å ¬é: 2010å¹´5æ30æ¥16æ40åé WASForum Conference 2010ãOpenIDã®ã話ã®å¾ã¯ãæ¼ä¼ã¿ãæãã§åå¾ã®ã»ãã·ã§ã³ã§ããåå¾ã®ä¸çºç®ã¯ãHASHã³ã³ãµã«ãã£ã³ã°ã®å¾³ä¸¸æµ©ããã«ãããã±ã¼ã¿ã¤2.0ãéãã¦ãã¾ã£ããã³ãã©ã®ç®±ããå®ã¯ãã®ã»ãã·ã§ã³ãäºåã«ãæªå ¬è¡¨ã®ãã¿2件ãçºè¡¨ãã (twitter.com)ãã¨å®£è¨ããã¦ãã¾ãããæªå ¬è¡¨ã®èå¼±æ§ãè¤æ°å ¬éãããã®ã§ã¯ãªããâ¦â¦ã¨ãæå¾ ã¨ä¸å®ãé«ã¾ãã¾ãã åãµã¼ãã¹ã®ãããããã°ã¤ã³æ©è½ã¯ã¦ãª â¦â¦ ããããããã°ã¤ã³ãããã©ã¤ãã㢠â¦â¦ ãã¯ã¤ãã¯ãã°ã¤ã³ãããmixi â¦â¦ ããããããã°ã¤ã³ããããã©ã¦ã¶ä¸å½å¿ â¦â¦ ãªãã¨ãããããããã°ã¤ã³ãã®ã¿ããããæ½ã?Twitter â¦â¦ ãããããã°ã¤ã³ããããã®ãµã¼ãã¹ã¯ã端æ«ã3å°ããã°3å°ã¨ããããããã°ã¤ã³ã§ããããã«é å¼µã£ã¦ãããRemem
WASï¼Web Application Securityï¼ãã©ã¼ã©ã ã®ã«ã³ãã¡ã¬ã³ã¹ã«åå ãã¦ããã ãã®ã«ã³ãã¡ã¬ã³ã¹ã¯ãæ¯å¹´ãé常ã«å 容ãæ¿ããã¾ããï¼æ¨å¹´åº¦ã«å¼ãç¶ãï¼åæã®éå¬ã§ãããã¨ã¨ãèªè²»ã§åå ã§ããã¬ãã«ã®åå è²»ç¨ã§ãããã¨ãããä¼ç¤¾ã§ãã»ãã¥ãªãã£ãé¢é£ã®ããã·ã§ã³ãä¸ãããã¦ããªã人ã§ãåå ãããã*1ã ã¡ã¤ã³ãã¼ã¯ã¼ãã¯ãæºå¸¯ï¼ç¹ã«ããããããã°ã¤ã³ï¼ãã¨ãOpenIDãã ã£ãã¨æãããç°ãªããµã¼ãã¹éã§ãã¦ã¼ã¶ãã©ãèå¥ããã©ã®ããã«ã¦ã¼ã¶ã®æ å ±ãéåä¿¡ããããã«ã¤ãã¦ãä¸çã®ã¤ã³ã¿ã¼ãããã大ããåãã¦ãããæ¥æ¬ã®ã¤ã³ã¿ã¼ããããæ¹åã誤ããªãããã«ããããããããã¡ãã»ã¼ã¸ãåãåã£ãã ä¸åå è ã¨ãã¦ãå¾®åãªããè²¢ç®ããªãã¦ã¯ãã¨æãã®ã ãããå¾®åããã¦ãã¨ããããèªåã®ã¾ããããï¼ã¹ãã«ã¯ãã¤ãã¼ã¹ã§èº«ã«ã¤ãã¦ããããããããªãããããªãï¼ã 以ä¸ãåã»ã
* ã²ã¼ãã¦ã§ã¤ã¯ãã«ãã¦ã¼ã¶ã¼ã対象ãªã®ã§ãæèãæèããPinningã¯ä¸å¯è½ã§ããã¤ãã¯IPã¢ãã¬ã¹ãæ¸ãæããã°ãªããªã
ä»æ¥WASForumã¨ããã¤ãã³ãã«åå ãã¦ãã¾ããã ç¾å¨ã®ã¤ã³ã¿ã¼ãããã®ã»ãã¥ãªãã£ã¼ã«ã¤ãã¦ã®ã話ããä½äººãã®æ¹ããã¬ã¼ã³ãã¦ãã ããã¾ããã å¦çã®èº«åã¨ãã¦ã¯â¦ã¨ã¦ãé£ããã£ãã®ã§ãããå¦çã®å ã«ãèªåã®ç¥ããªãç¯å²ããããããããã¨ãä½æãã¦ãã§ããã ããèªèåºæ¥ã¦ããä¸çãåºããå¿ è¦ãæããã¨æãã®ã§é å¼µãã¾ããã¾ããå°ãã§ãç¥èãå ¥ãã¦ç½®ãå¿ è¦ãããã¨æãã¾ãã ã¤ãã³ãã§ä¸çªããã£ããã¨ã¯â¦ ãããããã°ã¤ã³ã¯æ» 亡ãã¹ã ãããããã°ã¤ã³ã¯ã²ã©ãã¿ããã§ãã⦠æºå¸¯é»è©±åãã®ãµã¤ãã«ããããã»ãã¥ãªãã£å¯¾çãPCã¨åãã¬ãã«ã§èããæ¹ãããã¨ã®ãã¨ã§ãã ãã¨ã¯ãã©ã®ãããªæ»æããããã®ãã¨è¨ã話ã§ãJavaScriptãã©ã®ããã«ãã¦å®è¡ããããã¨è¨ããã¨ãã話ãããããã¾ãããããããæå¤ã«é¢ç½ãã£ãã§ãããã®æãã®æã使ã£ã¦ãçµã¿è¾¼ãã§ããã¨è¨ãããªãã¨ãããâ¦
WASForumã«åå ãã¦ãããé¢ç½ãã£ãããªãã¨ãªãç¥ã£ã¦ãããã¼ã¯ã¼ããã¡ããã¨èª¬æãã¦ããã£ã¦ä½ç½®ã¥ããã¯ã£ãããããã¨ãã§ããããä»ã®æµè¡ãã¯ã©ã®ããããªã®ããç¥ããã¨ãã§ãããããã°ã©ã ã¯ãã¡ããTwitterã®#wasfã¿ã°ã使ã£ã¦ããããããããã«é¢ããã¤ã¶ããã¯Togetterï¼WASForumã¾ã¨ãã«ã¾ã¨ãããã¦ããã çµå§ãé«æ¨ããããã¿ã«ãªã£ã¦ããã®ã¯é¢ç½ãã£ããããã¦ãé«æ¨ããããããé æ ®ãªãå©ç¨ãã¦ãã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ã®å®ä¾ãâ¦ããã®ãããã©ã¼ã©ã ã§ãããè¬æ¼è ã®ã¿ãªãã¾ãéå¬è ã®ã¿ãªãã¾ããã¤ãããã¾ã§ããã éæããï¼ãªã¼ããã³ã°ã»ãã·ã§ã³ -ãWebãµã¤ããå®å ¨ã«ä½¿ãç§æã¨ã¦ã¼ã¶ãç´é¢ããï¼ã¤ã®å±éºã ã¡ããã¨ãããæ°å³ã®ãªã¼ããã³ã°ã»ãã·ã§ã³ã ã£ãã æ¾å²¡ããï¼å½æ°ã®ããã®ã¦ã§ããµã¤ããéå¶ããIDèªè¨¼ã®èå°è£ Yahoo Japanã«ãããIDèªè¨¼å¨
æ¨æ¥ãASForum Conference 2010ãéå¬ããã¾ãããæºå¸¯é»è©±ã«é¢ãã話ãèãããã«åå ãã¾ããããæ¥æ¬ã®æºå¸¯é»è©±ã®ã»ãã¥ãªãã£ã¯ã²ã©ãã§ããã ç§ã¯ããããããã°ã¤ã³ãæ§ã ãªãµã¤ããå®è£ ãã ããé ããããããªãµã¤ãã§PCããã®ãªã¯ã¨ã¹ããæºå¸¯ã«å¤æ´ãã¦ãããããã°ã¤ã³ãå¯è½ãã©ãããè¡ã£ã¦ã¿ãã¨ãããããªãã®ãµã¤ãã§ãã°ã¤ã³ã§ãã¾ããã以æ¥ããããããã°ã¤ã³ã¯çµ¶å¯¾ã«å©ç¨ãã¾ããã§ãããä»æãã°ããµã¤ãã«é©åãªã¢ããã¤ã¹ãè¡ãã°ããã£ãã¨åçãã¦ãã¾ãã ã¾ãã2007å¹´ããæºå¸¯é»è©±ã®ã»ãã¥ãªãã£ã«å¯¾ãã¦å°ããããéã¯ãï½¢è¿ãå°æ¥ãJavaScriptãæºå¸¯ã§å©ç¨ã§ããããã«ãªãã®ã§ï½£æºå¸¯ãµã¤ãã«å¯¾ãã¦PCããã¢ã¯ã»ã¹ããé常ã®ãµã¤ãã¨åçã®ã»ãã¥ãªãã£å¯¾çãè¡ãã¹ãã¨è¨ã£ã¦ãã¾ããããï½¢ç¾ç¶ã¯ã»ã»ã»ã»ã»ã»ï½£ã¨ãã£ã¦é¿ãããããã¨ãã»ã¨ãã©ã§ãããä»åã®ã«ã³ãã¡ã¬ã³ã¹ãåã
ãã¼ã:ã¦ã§ããµã¤ãã®ãã¦ã¼ã¶ãã¨ãIDãã«ããããæåäºä¾ã¨é½å¸ä¼èª¬ WASForumã¯ããWASForum Conference 2010ããã2010/5/22åææ¥ã«ãã³ã¯ã¨ãã¼ã«ï¼åå·é§ 港åå£å´å¾æ©5åï¼ã§éå¬ãã¾ãã ãã¦ã¼ã¶ããæ±ãã¦ã§ããµã¤ãã®é¢ä¿è ã¯å ¨å¡éåï¼ï¼ ä»åã®ãã¼ãã¯ãã¦ã§ããµã¤ãã®ãã¦ã¼ã¶ãã¨ãIDãã«ããããäºæã¨ãªãã¾ãããiPhone, Android, ã±ã¼ã¿ã¤ãªã©ãã¦ã¼ã¶ãåãæ±ãã¦ã§ãã®ç°å¢ã¯å¤§ããå¤åãã¦ãã¾ããOpenID, OAuth, Facebook Connect, Windows Live ID,⦠AuthN(èªè¨¼)ã¨AuthZ(èªå¯)ã®æ±ºå®æã¯ä½ã§ãããããID/ãã¹ã¯ã¼ãæ¹å¼ã®æ¬¡ã¨ã¯ï¼ä¸æ¥ã§ã¿ã£ã¡ãæ±ãã¾ãã éå¬æ¦è¦ æ¥æï¼ 2010å¹´5æ22æ¥åææ¥ 10æã18æ å ´æï¼ã³ã¯ã¨ãã¼ã« (ã¢ã¯ã»ã¹)ï¼åå·æ¸¯åå£ï¼ åå è²»ç¨ï¼
ã¦ã§ããµã¤ãã®ãã¦ã¼ã¶ãã¨ãIDãã«ããããæåäºä¾ã¨é½å¸ä¼èª¬ ãAuthNï¼Authenticationï¼èªè¨¼ï¼ãã¨ãAuthZï¼Authorizationï¼èªå¯ï¼ããæ¬ã ä»åã®ãã¼ãã¯ãã¦ã§ããµã¤ããã¨ãã¾ãã¨ã³ã·ã¹ãã ã«é¢ããäºæãæ±ãã¾ããç¹ã«ããã¦ã¼ã¶ãã¨ãIDããåãæ±ãã¦ã§ããµã¤ãã«é¢ããæ¹ã ã«ã¯æ¯éãè¶ãé ãããã¨æãã¾ããèªè¨¼æ¹å¼ãå ±éåºç¤ã¯ããããã®ç¹å¾´ã¨ãã¾ã課é¡ãããã¾ããããããäºæã横æçã«ã¿ã£ã¡ãæ±ãä¸æ¥ã§ããITæè¡è ã®ã¿ãªãããä¼ç»ããã¶ã¤ã³ã«é¢ããæ¹ã ãã¾ãã¤ã³ã¿ã¼ããããµã¼ãã¹ã®ã¢ã¯ãã£ããªã¦ã¼ã¶ãè²´éãªæ å ±ãåéã§ããæ©ä¼ã¨ãªããã¨ã§ãããã
大å¤ãç¡æ²æ±°ãã¦ããã¾ããããã2å¹´ã®æ²é»ãæã¡ç ´ããWASForumã¯2010å¹´5æ22æ¥ã«ãã³ã¯ã¨ãã¼ã«ï¼åå·ï¼ã«ã¦çµæ¥ã®ã«ã³ãã¡ã¬ã³ã¹ãéå¬ãããã¨ã«ãããã¾ããã å°ãªããã¬ãã£ã¹ã«ãã·ã§ã³ãéããä½ã¶æãã®ä¼ç»ã®æéãçµã¦ãä»åã®ãã¼ãã¯ã¦ã§ããµã¤ãã§ãã¦ã¼ã¶ãããIDããåãæ±ãæ¹ã ãã¹ã¦ã®ããã«å¿ è¦ãªæ å ±ãã·ã§ã¢ãããã¨ã«ãã¾ããã ãã¼ãã¯ä»¥ä¸ã®ããã«ãªã£ã¦ãã¾ãã ã¦ã§ããµã¤ãã®ãã¦ã¼ã¶ãã¨ãIDãã«ããããæåäºä¾ã¨é½å¸ä¼èª¬ï¿½ãAuthNï¼Authenticationï¼èªè¨¼ï¼ãã¨ãAuthZï¼Authorizationï¼èªå¯ï¼ããæ¬ã ããã°ã©ã ã®è©³ç´°ã¯è¿æ¥ä¸ã«å ¬éãã¾ãããåå10æããå¤æ¹ã¾ã§ããã®å½æ°çãµã¤ããOpenIDãã±ã¼ã¿ã¤2.0ãOAuthãWindows Live IDã Web2.0ãµã¤ãã®é£æºã«é¢ä¿ãããã¨ã横æçã«æ±ããã¾ãã ã¦ã§ããµã¤ãã®ã»ã
bakera.jp > æ°´ç¡æã°ããã®ãã³æ¥è¨ > WASForum Conference 2008: Webã»ãã¥ãªãã£ã®ãã«ãã©ã¯ãã£ã¹ â æãè¾¼ã¿ã«ããã½ããã¦ã§ã¢ã¨ã©ã¼ããªãã¨ããã
1æ¥ç®ã®æå¾ã®ã»ãã·ã§ã³ã¯ããã«ãã£ã¹ã«ãã·ã§ã³ããã¾ãç¶²ç¾ çã«ã¡ã¢ã§ãã¦ããªãã®ã§ãããã¨ãã®ä¸é¨ã®ã¿ã®æç²ã¨ããæãã«ãªã£ã¦ãã¾ãã â»å®ã¯PCã®ããããªããã³ãã§ã¡ã¢åæ°ãã»ã¼ããããããã»ã¨ãã©ã¡ã¢ãã¦ãã¾ããã§ããâ¦â¦ãorz ã¡ãªã¿ã«ãããªã¹ãã¯ããµã¤ãªã¹ãã¯ããã¸ã¼ã®å±±å´éä¹æ°ããµã¦ã³ããã¦ã¹ã®ä¸å³¶å°å½¦ç¤¾é·ãã©ã¤ããããçå½ä¿éºã®ä¸å·é彦æ°ãå¥è¯å 端ç§å¦æè¡å¤§å¦é¢å¤§å¦ã®éæéåºæ°ãããã¦ããªãã¿ãç£ç·ç ã®é«æ¨æµ©å æ°ã以ä¸ã®ã¡ã¢ã§ã¯çºè¨è åã®æ¬ç§°ã¯ç¥ããã¦ããã ãã¦ãã¾ãã Webãæ´»ç¨ãããã¸ãã¹ã§ã®å¿æ§ãã¨ã¯?ä¸å³¶ãä¸ããã®è¨èãåããããããè¡æ¿ãããã»ãã¥ãªãã£å¤§äºã§ãããã¨è¨ããã¡ãã£ããããã ãã é«æ¨ä»ã¾ã§2åãããåºã¦ã¯ããã®ã§ããâ¦â¦ã 2001å¹´ã«XSSã®åé¡ãçµç£çã®å¯©è°å®ã«èª¬æããã¨ãããããã¯ã¯ã¼ã ã®ããã«åºããã®ã?ãã¨èããããåºãããªãããªãã¨æ
æ¢ã«è²ã ãªæ¹ãç´¹ä»ããã ãã¦ãã¾ããããWASForum Conference 2008ã®7/5 Developers DAY - äºä»¶ã¯ç¾å ´ã§èµ·ãã£ã¦ããâ¦â¦ã»ãã¥ãªãã£ã©ã¤ããµã¤ã¯ã«ã¨ãã«ãã©ã¯ãã£ã¹ã«ã¦ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çåèãã®ã¿ã¤ãã«ã§è¬æ¼ããã¦ããã ããã¨ã«ãªãã¾ããã7æ5æ¥åææ¥ãæ±é座æäºéä¿¡ãã¼ã«ã§ãã é«æ¨æµ©å æ°ã®ããã°ã§ã¯ã ä»ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®å¯¾çæ¹æ³ã¯åºãç解ããã¦ããã¯ãã®ããã«ãæãã¾ãããã©ããããã§ããªãããã§ãããã¾ã ã«ããµãã¿ã¤ãºãçãªå¯¾çãæããæ¤æ»æ¥è ãã³ã³ãµã«æ¥è ãããããã§ããã°ãã°ããããã£ãæ¥è ãã¯ã¦ãªããã¯ãã¼ã¯ã§è¡ç¥ãã«ããããã¦ããäºä¾ãæ£è¦ãããã¨ããã§ããblog ã§ãSQLã®ã¨ã¹ã±ã¼ãåèãã¨ãã£ãã¨ã³ããªãæ¸ããã¦ãã徳丸ããã«ããã®ãããã®ãã¨ã«ã¤ãã¦çµè«ãåºãã¦ããã ãã¾ãã ã¨ã®ã³ã¡ã³ããããã ãã¦ã
ãã¸ãã¹ç¤¾ä¼ãè¡ãããã®å ±åããã¸ã§ã¯ããHardening Project(åå:ãã¼ããã³ã°ããã¸ã§ã¯ã)ã¯2012å¹´ããéå¶å©ã®ã³ãã¥ããã£ã«ããå£ä½ã¨ãã¦æ´»åãã¦ãã¾ãã
2008å¹´3æ11æ¥ï¼ä¸ç¹å®å¤æ°ã®Webãµã¤ãã«å¯¾ãã大è¦æ¨¡ãªSQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æãçºçãããæ¬æ»æã¯ã¿ã¼ã²ããã¨ãªãWebãµã¤ãã®ã½ã¼ã¹ã³ã¼ããæ¹ãããï¼æ»æè ãç¨æããä¸æ£ãªWebãµã¤ãã¸ã®ãªã³ã¯ãæ¿å ¥ãããã®ã§ãããã»ãã¥ãªãã£ãªãã¬ã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼SOCï¼ã§ãï¼2008å¹´3æ11æ¥ï½13æ¥ã®éã«ï¼ãã®SQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã試è¡ããéä¿¡ãå¤æ°æ¤ç¥ãããä»åã®æ»æã¯IISï¼Internet Information Servicesï¼ï¼Microsoft SQL Serverï¼ASPï¼Active Server Pagesï¼ãå©ç¨ããWebãµã¤ãã対象ã¨ãããã®ã ã£ãã 大è¦æ¨¡ãªSQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã¯3æå¾åãã4æå¾åã«ããã¦ã度ã çºçãã¦ããï¼ä¸ççãªè¢«å®³ã®çºçãå ±åããã¦ãã ãããããï¼æ»æã®æ¹æ³ããã³ãã®å¯¾è±¡ã¯3æ11æ¥ã«çºçãããã®ã¨åæ§ã§ããï¼å¼ãç¶ã注
ãã®ãã©ã¦ã¶ã¼ã¯ãµãã¼ããããªããªãã¾ããã Microsoft Edge ã«ã¢ããã°ã¬ã¼ãããã¨ãææ°ã®æ©è½ãã»ãã¥ãªãã£æ´æ°ããã°ã©ã ãããã³ãã¯ãã«ã« ãµãã¼ããå©ç¨ã§ãã¾ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}