2008/09/26 ã»ãã¥ãªãã£å°é家ã "Clickjacking" ãè¦å heise Securityã«ããã¨ãOWASPä¼è° (Open Web Application Security Project) ã§ãRobert "RSnake" Hansenã¨Jeremiah Grossman 両æ°ã¯å¤ãã®Webãã©ã¦ã¶ãWebãµã¤ããæã¤é大ãªã»ãã¥ãªãã£ã®æ¬ é¥ã«é¢ããçºè¡¨ãè¡ãäºå®ã ã£ãããæ¥é½ãã£ã³ã»ã«ã«ãªã£ãããã ãå ¬ã«ããåã«ãã³ãã¼ã«è¦åãéããã¨ã«ãªã£ãã¨ã®ãã¨(Grossmanæ°ã®ããã°)ããã®é大ãªæ¬ é¥ã¨ããã®ã¯ã¦ã¼ã¶ãæå³ããªããµã¤ãã«èªå°ãããããã®å½ãªã³ã¯ã§ãã¦ã¼ã¶ã®ã¯ãªãã¯ãä¹ã£åã(ãã¤ã¸ã£ãã¯)ã¨ããããã"Clickjacking" ã¨å¼ã°ãããå½ãªã³ã¯ã¯JavaScriptãIFRAMEãªã©ã使ã£ã¦ä½ããããããã©ã¦ã¶ã®åé¡(æ¬ é¥)ã¨èãã¦ããã ãã
{{#tags}}- {{label}}
{{/tags}}