UTF-7 ã使ã£ã¦ã¹ã¯ãªãããè¨è¿° +ADw-SCRIPT+AD4-alert(\'XSS\');+ADw-+AC8-SCRIPT+AD4- IE ã¯ãæåã¨ã³ã³ã¼ãã£ã³ã°ãä¸æ㧠UTF-7 ã£ã½ãæååãããã°ãèªåå¤å¥ã§ UTF-7 ã¨ãªãã
UTF-7 ã使ã£ã¦ã¹ã¯ãªãããè¨è¿° +ADw-SCRIPT+AD4-alert(\'XSS\');+ADw-+AC8-SCRIPT+AD4- IE ã¯ãæåã¨ã³ã³ã¼ãã£ã³ã°ãä¸æ㧠UTF-7 ã£ã½ãæååãããã°ãèªåå¤å¥ã§ UTF-7 ã¨ãªãã
2006å¹´12æ02æ¥04:30 ã«ãã´ãªLightweight Languages Error Messageã«ãããæãã·ã³ãã«ãªXSSåé¿æ³ 404 Blog Not Found:perl+javascript - ã¯ã¦ãã¨ç縮URLã®Mashupã®ãã°ãã£ãã¯ã¹ã æè¡ã¡ã¢å¸³ - dankogaiããã®ã¢ããªã®XSS ã¨ã©ã¼ã¡ãã»ã¼ã¸ãåºåããã¨ãã« HTMLã¨ã¹ã±ã¼ããããã¦ãªãã£ãã è¦è½ã¨ãã¨ããã ã£ããããããå ´åã¯ãTBãªããCommentãªã©ãå è¨äºããç´æ¥è¦ããå½¢ã§å ±åãã¦æ¬²ããã ããããtext/htmlã¨ãã¦è§£éããã¦ããã®ã¯ããããã¨æã£ã¦headerãè¦ããã % HEAD 'http://u.dan.co.jp/r.cgi/<script>alert('easy%20xss');</script>' 500 Internal Server Error Co
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®æéã§ãï¼ XSSã¨ããã¨â¦ï¼ ã¾ã£ããã«æãã¤ãã®ããå ¥åãã¼ã¿éä¿¡ â 確èªè¡¨ç¤ºã®é¨åã§ã®ç¡å®³åæ¼ãã§ãããï¼ ãã¨ãã°ãããªæãã®ãã©ã¼ã ããåãåã£ããã©ã¡ã¼ã¿ãã 確èªã¨ãã¦è¡¨ç¤ºãããã¼ã¸ã¨ãï¼ (å ¥å) <form action="register.cgi" method="post"> ã¿ã¤ãã«ï¼<input type="text" name="title"> â ãã¼ãã¯ã¾ã¡ã¡ããï¼ããå ¥å æ¬æï¼<input type="text" name="body"> â ãããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert(1)</script>ããå ¥å </form> (確èª) <p>ãã®å 容ã§ç»é²ãã¦ããï¼</p> <p> ã¿ã¤ãã«ï¼ ã¼ãã¯ã¾ã¡ã¡ããï¼<br> æ¬æï¼ ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert
ãªã¼ãã³ã½ã¼ã¹ã®eã©ã¼ãã³ã°CMSã¢ããªã±ã¼ã·ã§ã³ãATutorãããã³ãACollabãã«ããã¦ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«é¢ããèå¼±æ§ãçºè¦ãããã æ å ±å¦çæ¨é²æ©æ§ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼IPAï¼ããã³JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼JPCERT/CCï¼ã¯7æ5æ¥ãèå¼±æ§æ å ±ãµã¤ãJP Vendor Status Notesï¼JVNï¼ã«ããã¦ããªã¼ãã³ã½ã¼ã¹ã®eã©ã¼ãã³ã°ã¢ããªã±ã¼ã·ã§ã³ãATutorããªã©ã«èå¼±æ§ããããã¨ãæããã«ããããã®èå¼±æ§ãçªãããã¨ãæ å ±æ¼ããããªããã¾ãã許ãã¦ãã¾ãå±éºæ§ãããã èå¼±æ§ãçºè¦ãããã®ã¯ãeã©ã¼ãã³ã°ç¨ã®CMSï¼ã³ã³ãã³ã管çã·ã¹ãã ï¼ATutorããã³ATutorã®ã¢ããªã³ã¨ãã¦åä½ããã³ã©ãã¬ã¼ã·ã§ã³ã½ãããACollabãã ATutorã§ã¯ã1.5.2以åã®ãã¼ã¸ã§ã³ã«ããã¦ãã¯ãã¹
ã»ãã¥ãªãã£çµç¹ã®ç±³SANS Instituteãªã©ã¯ç¾å°æé6æ12æ¥ï¼ç±³Yahoo!ãæä¾ããWebã¡ã¼ã«ã»ãµã¼ãã¹ã®èå¼±æ§ï¼ã»ãã¥ãªãã£ã»ãã¼ã«ï¼ãçªãã¦ææãåºããã¦ã¤ã«ã¹ãåºåã£ã¦ããã¨ãã¦æ³¨æãå¼ã³ããããã¡ã¼ã«æ¬æãèªããã¨ããã ãã§ææãï¼ã¢ãã¬ã¹ã»ãªã¹ãã®æ å ±ãçã¾ããã¨ã¨ãã«ã¦ã¤ã«ã¹ã»ã¡ã¼ã«ãéä¿¡ããããããYahoo!ã§ã¯ç¾å¨å¯¾å¦ä¸ã§ããã¨ãã¦ããã Yahoo!ã®Webã¡ã¼ã«ã»ãµã¼ãã¹ï¼Yahoo!ã¡ã¼ã«ï¼ã«ã¯ï¼ã¡ã¼ã«ã«ç´°å·¥ãæ½ããã¦ããã¨ï¼ã¡ã¼ã«æ¬æãéãã ãã§ï¼æ·»ä»ãããHTMLãã¡ã¤ã«ãåæã«éãã¦ãã¾ãèå¼±æ§ãè¦ã¤ãã£ããHTMLãã¡ã¤ã«ã«ã¹ã¯ãªããï¼JavaScriptï¼ãå«ã¾ãã¦ããå ´åã«ã¯ï¼ãã®ã¹ã¯ãªãããåæã«å®è¡ããã¦ãã¾ããä»åã®ã¦ã¤ã«ã¹ã¯ãã®èå¼±æ§ãæªç¨ãããã®ã§ï¼HTMLãã¡ã¤ã«ã«å«ã¾ããã¹ã¯ãªãããã¦ã¤ã«ã¹ã®å®ä½ã§ããããªãï¼ä»åã®èå¼±æ§ã¯
ãYahoo!ã¡ã¼ã«ã®ã¦ã¤ã«ã¹ãæªç¨ããã®ã¯ãXSSèå¼±æ§ãï¼ãµã¤ã管çè ã¯æ³¨æãã---å°é家ãè¦å ããYahoo!ã¡ã¼ã«ããçã£ãã¦ã¤ã«ã¹ã¯ï¼åãµã¤ãã®ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ï¼XSSï¼èå¼±æ§ãæªç¨ãããåæ§ã®èå¼±æ§ã¯å¤ãã®Webãµã¤ãã«åå¨ããããã®ã¦ã¤ã«ã¹ã®ã½ã¼ã¹ã»ã³ã¼ããåºåã£ã¦ããã®ã§ï¼ä»å¾ï¼åæ§ã®æ»æãé »çºããå¯è½æ§ã¯é«ããWebãµã¤ãã®ç®¡çè ãéçºè ã¯ååã«æ³¨æããå¿ è¦ãããã---ã京ã»ã©ã³ãã¥ãã±ã¼ã·ã§ã³ã·ã¹ãã ã®ã»ãã¥ãªãã£äºæ¥é¨ å¯äºæ¥é¨é·ã§ãã徳丸浩æ°ã¯6æ15æ¥ï¼ITproã®åæã«å¯¾ãã¦è¦åããã Yahoo!ã¡ã¼ã«ã®ã¦ã¤ã«ã¹ã¯âåç´â 6æ12æ¥ããã«ç¢ºèªããã¦ãYamannerããªã©ã¨åä»ããããã¦ã¤ã«ã¹ã¯ï¼ç±³Yahoo!ãæä¾ããã¡ã¼ã«ã»ãµã¼ãã¹ãYahoo! Mailï¼Yahoo!ã¡ã¼ã«ï¼ãã§ææãåºããï¼é¢é£è¨äºï¼Yahoo!ã¡ã¼ã«ã®èå¼±æ§ãçª
Cookieï¼ã¯ããã¼ï¼ã¨ã¯ï¼Webã¢ã¯ã»ã¹ã®ã¨ãã«Webãµã¼ãã¼ãã¦ã¼ã¶ã¼ãèå¥ããããã«ä½¿ãæ¯è¼çå°ããªããã¹ãã»ãã¼ã¿ã®ãã¨ãç±³ãããã¹ã±ã¼ãã»ã³ãã¥ãã±ã¼ã·ã§ã³ãºãèªç¤¾ã®Webãã©ã¦ã¶/ãµã¼ãã¼ã»ã½ããã«å®è£ ããã®ãå§ã¾ãã ãWebãµã¼ãã¼å´ã§ã¦ã¼ã¶ã¼ãèå¥ãããã¨ãï¼Webãã¼ã¸ã®ãã¼ã¿ãéåä¿¡ããã®ã¨ãã£ããã«Cookieãããã¨ãããããã¾ãï¼Cookieãããã¨ãããããã¿ã®ãã¨ããCookieãã¨å¼ã¶ã Cookieã«ã¯ï¼ãããã¹ã±ã¼ããä½æããä»æ§ã®ã»ãã«RFC2965ãããããã ãï¼RFC2965ã¯ãã¾ã使ããã¦ããªããããã§ã¯ï¼ãããã¹ã±ã¼ãã®ä»æ§ã«ã¤ãã¦ç´¹ä»ããã ã¾ãï¼Cookieã®ä½¿ãæ¹ãè¦ã¦ããããä¾ãã°ï¼AãããããWebãµã¼ãã¼ã«ã¦ã¼ã¶ã¼ç»é²ããã¨ãï¼Webãµã¼ãã¼ã¯ãã®å¿çã¡ãã»ã¼ã¸ã«ç¸æãAããã ã¨ããããããªãã¼ã¿ãå«ã¾ããããã®èå¥ãã¼ã¿ãCoo
èè : éåº <anvil@jumperz.net> http://www.jumperz.net/ â ã¯ããã« ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè ã®ç«å ´ããè¦ãCSRF対çã«ã¤ãã¦ããã¾ãã¾ãªæ å ±ãå ¥ãä¹±ãã¦ãããçè ã2006å¹´3æã®æç¹ã«ããã¦å½å ã®ã¦ã§ããµ ã¤ããã³ã³ãã¥ã¼ã¿æ¸ç±ã»éèªãªã©ã§CSRF対çã«ã¤ãã¦æ¸ããã¦ããè¨äºã調ã¹ãçµæããã©ããã¹ããã¨ã«ããã®ã»ã¨ãã©ã誤ããå«ãã§ããããç¾å®ç ã«ã¯ä½¿ç¨ã§ããªãæ¹æ³ãç´¹ä»ããããã¦ãããããã§æ¬ç¨¿ã§ã¯ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè ã«ã¨ã£ã¦ã®æ¬å½ã«æ£ããCSRF対çã«ã¤ãã¦ã¾ã¨ãããã¨ã¨ã ããã¾ããæ¡ç¨ãã¹ãã§ãªãCSRF対çã¨ãã®çç±ãåããã¦ç´¹ä»ããã â ããããæ©è½ãã¿ã¼ã²ããã¨ãªããã ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã®æã¤å ¨ã¦ã®æ©è½ãCSRFæ»æã®å¯¾è±¡ã¨ãªããããã¾ããã®ãã¨ãèªèãã¦ããå¿ è¦ãããã Amaz
ã¤ã£ãã¿ã©ããæºè¼ã¿ããã§ããï½ï¼id:sonodamãµã¡ http://d.hatena.ne.jp/yama_r/20060304/1141407252 èå¼±æ§ãããã⦠- ç¡é¡ããã¥ã¡ã³ã æ¥æ¬ããã°åä¼ã®èå¼±æ§ã«ã¤ã㦠- ããããã¯ã¦ã æ¥æ¬ããã°åä¼ã®å¤±æ - å ¨è³èªç±å¸³ å¾ç¶"ãããã"Blogæ¥è¨:æ¥æ¬ããã°åä¼ã®ãç²æ«ãªã¹ã¿ã¼ã - livedoor Blogï¼ããã°ï¼ æ¥æ¬ããã°åä¼ - ç¸å´ã§ãè¶ ãã£ãããã£ã¦ããããããã«ã¯ã¦ãªããã¯ãã¼ã¯ã«ããã¨ãä¼å¡ã«é å¸ãã¦ããIDã¨ãã¹ã¯ã¼ãã¯ã©ãããå ¨å¡ã«å ±éã®ãã®ã§ãã£ããããããããã人ãã¡ããããã°ã®æ®åä¿é²ããããã®ããæ©ããå ¨é¨ãã¿ã§ãããã¨è¨ã£ã¦ã»ããã ã¦ããããããã»ã»ã»ï¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}