ä¸ã®ä¸ã«ã¯ãã¾ãã¾ãªã¿ã¤ãã®ã¨ã³ã¸ãã¢ããã¾ããæµè¡ã«åããã¦æ¬¡ã ã¨æ°ããããã°ã©ãã³ã°è¨èªããã¬ã¼ã ã¯ã¼ã¯ãç¿å¾ãã人ãããã°ãç¹å®ã®æè¡ã«é·ãæºããå°éæ§ãé«ãã人ãããã§ãããã å¾è ã®ã¿ã¤ãã®ä»£è¡¨æ ¼ã¨è¨ããä¸äººããJavaã®ã¹ãã·ã£ãªã¹ãã¨ãã¦ç¥ãããLINE Fukuokaæ ªå¼ä¼ç¤¾ã®ããã ãªãã(@kis)ããã å½¼ã¯20年以ä¸ã«ãããããã®è¨èªã¨åãåãã¹ãã«ãçªãè©°ãã¦ãã¾ããã æè¿ã§ã¯ãæ¸ç±ãããã«ãªãJava*ããå·çãããªã©ãJavaã®èªç¥æ¡å¤§ã»æ®åã®ããã®æ´»åãè¡ã£ã¦ãã¾ãã ããã ããã¯ãJavaã¸ã®èå³ãé·ãç¶ããçç±ã¨ãã¦ãæè¡ã³ãã¥ããã£ã®åå¨ã大ããå½±é¿ãã¦ãããã¨èªãã¾ãã ä»åã¯ããã ããã«ãæè¡ã³ãã¥ããã£ã«é¢é£ããã¨ãã½ã¼ãã¨ã¨ãã«ããã£ãªã¢ãæ¯ãè¿ã£ã¦ããã ãã¾ããã *â¦æè¡è©è«ç¤¾ãã2022.3.19åºçãããã ãªãããããå±±æ¬è£ä»ãããæå±±
ãã¨ã³ã¸ãã¢ã¨ãã¦ä»ãããæªçã ã£ãããã¯ãããã«éãæ¸ãããã»ãããã¨æãããã³ã¼ããæ¸ãããã«æ°æã¡ãåããã¡ã§ãããã§ãã大äºãªã®ã¯ãã¼ã ã¨ãã¦éç¨ããããã³ã¼ããæ¸ãããã©ããããã®ããã«ã誰ãè¦ã¦ãããèªã¿è§£ããã³ã¼ããæèãã¦æ¸ãããã«ãªãã¾ããã ãã¨ã¯ãµã¦ã£ã¶ã¼ãºãã§æ´»èºããâã¦ã£ã¶ã¼ãºâãã¡ãç´¹ä»ããã¹ãã¼ãªã¼ã ä»åã¯ã¢ãã¤ã«ã°ã«ã¼ãã®ãªã¼ãã¼ãåããCoty Saxmanãããç»å ´ãã¾ãããã²ã¼ã ãä½ããããã¨ããä¸å¿ã§ã¨ã³ã¸ãã¢ã¨ãªããITæ¥çã¸é£ã³è¾¼ãã éå¹´ãä»å¥®éãã¦ããã®ã¯ãã¡ã³ãã¼ãæ´»èºã§ããç°å¢ã¥ãããã§ããã â¾ï¸ ãããã£ã¼ã« Coty Saxman Rochester Institute of Technologyã«ã¦ãã²ã¼ã ãã¶ã¤ã³ã¨å²å¦ãå°æ»ãå¨å¦ä¸ã«æ¥æ¬ã¸çå¦ããä¸æºå¤§å¦ã¸ãæ°è¦äºæ¥æ¨é²æ¯æ´ã¹ã¿ã¼ãã¢ããæ¯æ´ã»ã¤ã³ãã¥ãã¼ã·ã§ã³äºæ¥æ¦ç¥ã³ã³ãµ
Notice 2019å¹´11æãããLINE Security Bug Bounty Programã®ãã©ãããã©ã¼ã ã¯HackerOneã¸ã¨ç§»è¡ãã¾ããã ææ°ã®æ å ±ã¯HackerOneã®ããã°ã©ã ãã¼ã¸ä¸ã§æ²è¼ããã¦ãã¾ãã 以ä¸ã®å 容ã¯ããã©ãããã©ã¼ã 移è¡åã®ãã®ã¨ãªãã¾ãã 1. Hall of fame LINE Security Bug Bounty Program (2016/6/2ãã) ã«ããã¦ãçºè¦ã»å ±åããã ããå 容ã å¼ç¤¾ã«ãã審æ»ã«ãã£ã¦ã該å½ã®èå¼±æ§ã§ããã¨èªå®ãããæ¹ã ããHall of fameãã«æ²ç¤ºãããã¾ãã No Profile Name Vulnerability
ããã°ã©ã æ å ± 1. ããã°ã©ã ã®ç®ç æ¬ããã°ã©ã ã¯ãã³ãã¥ãã±ã¼ã·ã§ã³ã¢ããªãLINEãåã³WEBãµã¤ãã«åå¨ããèå¼±æ§ãæ©æã«çºè¦ããã¦ã¼ã¶ã¼ã«ãããå®å ¨ãªãµã¼ãã¹ãæä¾ãããã¨ãç®çã§ãã 2. ããã°ã©ã ã®è©³ç´°ã«ã¤ã㦠2019å¹´10æãããLY Corporationã¯Hackeroneã¨ãããã©ãããã©ã¼ã ä¸ã§LINE Security Bug Bounty Programï¼ä»¥ä¸ãæ¬ããã°ã©ã ãã¨ããï¼ãéå¶ãã¦ããã¾ããã¤ãã¾ãã¦ã¯ãèå¼±æ§ã®å ±åã¯ãã¡ãã®ãã©ã¼ã ããå©ç¨ãã ããã ã¾ããHackeroneããå©ç¨ã«ãªããªãå ´åããæ¬ããã°ã©ã ã¨ã¯é¢ä¿ã®ãªããã°ã®å ±åç㯠dl_bugreport@linecorp.com ã¸ã®ã¡ã¼ã«ã«ã¦åãä»ãã¦ããã¾ãã ãã ããèå¼±æ§å ±åãã©ã¼ã 以å¤ããã®å ±åã¯ãååã¨ãã¦å ±å¥¨éã®å¯¾è±¡å¤ã¨ãªãã¾ãã®ã§ã注æãã ããã 3. å©ç¨è¦ç´
LINEã¯å¯¾è©±ã¢ããªä¸ã§éã¹ãã¹ãã¼ããã©ã³ï¼ã¹ããï¼åãã²ã¼ã 8ã¿ã¤ãã«ããã¹ã¦åæ¢ããç´1ã«æã®æ¹ä¿®ä½æ¥ãå§ããã9æã«éå§ããã°ããã®ãµã¼ãã¹ãé·æéåæ¢ããã®ã¯ç°ä¾ã ãç±³ã¢ããã«ã®ã¢ããªé ä¿¡ãµã¼ãã¹ãã¢ããã¹ãã¢ãã®å¯©æ»ã§åé¡ãèµ·ãããã¨ãåå ã®ããããLINEã¯èªç¤¾ã®ã¦ã¼ã¶ã¼åãã«æ°ããªã²ã¼ã å¸å ´ãä½ãçãã ã£ãããåºã°ãªããããããæ ¼å¥½ã ããé¢é£è¨äºãLINEå ã²ã¼ã ãã¢ã³ããã¤ãçãä¸é¨åéï¼11æ7æ¥ï¼
LINEã¯13æ¥ã京é½å¸å ã«æ°ããªéçºæ ç¹ãéãããéçºæ ç¹ã¯æ±äº¬é½ãç¦å²¡å¸ã«ç¶ã3ã«æç®ã京é½ã®ãã©ã³ãåãçããã¦å½å å¤ã®åªç§ãªæè¡è ãéããçããããã3å¹´å¾ã«ã100人ä½å¶ãç®æãã人工ç¥è½ï¼AIï¼ãä¸å¿ã«å 端æè¡ãåãå ¥ãããµã¼ãã¹éçºãé²ããã京é½å¸å ã§è¨è ä¼è¦ããåºæ²¢å社é·ã¯ãã¤ã³ã¿ã¼ãããä¼æ¥ã¯äººæã競äºåã®æºæ³ã¨ãªããæè¡è ã®è½åãææ§ããµã¼ãã¹éçºãå·¦å³ãããã¨å¼·èª¿ããã
大å¦çã»å¤§å¦é¢çã®å°±è·æ´»åã§å¦çå´ã®ã売ãæå¸å ´ããç¶ããªããç¹ã«ITï¼æ å ±æè¡ï¼äººæã®äºå¥ªæ¦ãç½ç±ãã¦ããããªãã§ãLINEã¯ã1ã«æã§40ä¸åãã®å ±é ¬ãæ¯æããã¨ã³ã¸ãã¢å°±æ¥ã³ã¼ã¹ãã¨ããã¤ã³ã¿ã¼ã³ã·ãããæ¡ç¨è©¦é¨ãä½åº¦ã§ãåããããããªãã£ã¬ã³ã¸å¶åº¦ãã®å°å ¥ã§æ³¨ç®ãéãã¦ãããå·è¡å½¹å¡ã¨ãã¦äººäºãæ å½ããè½åç´è²´æ°ã«ã¤ã³ã¿ã¼ã³ã®çããæ¡ç¨ã®æ¹éãèããã ââ1ã«æã§å ±é ¬40ä¸åã®ã¤ã³ã¿ã¼ã³ãå§ããçãã¯ã ãã¨ã³ã¸ãã¢å°±æ¥ã³ã¼ã¹ã§ã¯ç¤¾å ã®ã¨ã³ã¸ãã¢ã¨æºã並ã¹ã¦ãå é¨ã®ã½ã¼ã¹ã³ã¼ããè¦ãªããå®éã«ã·ã¹ãã ãã¤ãã£ãããã¾ããå¦ç1人ã«ãã¥ã¼ã¿ã¼ã®ç¤¾å¡ã1人ã¤ãã¦ãµãã¼ããã¾ããå¦çã1ã«æãææããã®ã§ãããã«è¦åãå ±é ¬ã¨ãã¦40ä¸åæ¯æãã¾ããããã¯å½ç¤¾ã®ã¨ã³ã¸ãã¢ã®å任給ã¨ã ãããåãã¬ãã«ã§ããã®ãããã妥å½ã ã¨å¤æãã¾ãããã¤ã³ã¿ã¼ã³ã«åå ããã«ã¯é¸èããããä¸å®ã¬ãã«ã®ãã
AIï¼äººå·¥ç¥è½ãªã©ãæå 端æè¡ã¸ã®å¯¾å¿ã§ï¼©ï¼´ã®åéã§ã人æä¸è¶³ãæ·±å»åããä¸ãéä¿¡ã¢ããªå¤§æã®ãLINEãã¯ã京é½å¸ã«éçºæ ç¹ãè¨ããå°æ¹ã§ã®äººæã®ç²å¾ãå¼·åããæ¹éãåºãã¾ããã ãLINEãã§ã¯ãå½å ã®ç¤¾å¡ã®ï¼åã®ï¼ã«å½ãããããï¼ï¼ï¼äººã®æè¡è ããéä¿¡ã¢ããªã®ã»ãAIï¼äººå·¥ç¥è½ãæ´»ç¨ãããµã¼ãã¹ã®éçºãªã©ã«ããã£ã¦ãã¾ãã ããããæå 端æè¡ã¸ã®å¯¾å¿ãæ¥ãå½å å¤ã®ï¼©ï¼´å社ã«ããæè¡è ã®ç²å¾ç«¶äºãæ¿ãããªã£ã¦ãã¦ã人æã®ç¢ºä¿ãé£ãããªã£ã¦ãã¾ãããã®ããLINEã¯ã京é½ã«éçºæ ç¹ãè¨ãã¦ãå°å ã§åãããæåãæã¤é¢è¥¿å°æ¹ã®äººæã®æ¡ç¨ãå¼·åãããã¨ã«ãã¾ããã ãã®æ ç¹ã§ã¯ãæè¡ç³»ã®å¦çã®ã¤ã³ã¿ã¼ã³ã®åãå ¥ãã社å¡ã¨ã®äº¤æµã¤ãã³ããè¡ãè¨ç»ã§ãã ITæ¥çã§ã¯ããã¨ãã«å ¥ã£ã¦ãããªã¼ãã¼ã±ããã¢ããªã®ãã¡ã«ã«ãªãããã¼ã¿ã»ã³ã¿ã¼éå¶ã®ããããã¤ã³ã¿ã¼ãããããªã©ï¼ç¤¾ããç¦å²¡å¸ã«ç¸æ¬¡ãã§äº
By LINE Engineering | 2016.12.22 2021.01.08LINE Engineering Blog official account ãã®è¨äºã¯LINE Advent Calendar 2016ã®16è¨äºç®ã§ãã ããã«ã¡ã¯ãLINEã¨ã³ã¸ãã¢ã®æç²å¥äºã§ããæå±ã¯ãã»ãã¥ãªãã£å®¤ãã®ãApplication Security Teamãã¨ããã¨ããã§ã主ã«ãªãªã¼ã¹åã®Games/Appsã®è¨ºæãè¡ã£ã¦ãããããããä¸è¬çãªã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã§ããä»æ¥ã¯Unityã«é¢ããã»ãã¥ãªãã£è¦ç¹ã®å ¥éè¨äºãæ¸ãããã¨æãã¾ãã ã¯ããã« ãããããGames/Appsã®ã»ãã¥ãªãã£è¨ºæã£ã¦å ·ä½çã«ä½ãããã®ããã¨ãã話ã§ãããåºæ¬çã«ã¯ã¢ããªã®è§£æã¨ãéä¿¡ããã³ãã«ã®è§£æ/診æãã¡ã¤ã³ã«è¡ãã¾ãã ã¢ããªã®è§£æã«ã¯ããã¤ãã®ãã¼ã«ã使ãã®ã§ãããã¾ã.dexãåæ
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}