DoSï¼Denial of Serviceï¼æ»æã¨ã¯ãæªæãæã¤è ããæ¨çã¨ãããµã¼ãã®ãµã¼ãã¹ãåæ¢ã«è¿½ãè¾¼ããããªæ»æãããã¾ããé常ã¯ãµã¼ãã«å¯¾ãã¦çæéã«é常ã«å¤ãã®ãªã¯ã¨ã¹ããéãã¤ãããããµã¼ãã½ããã¦ã§ã¢ã®ãã°ãçã£ã¦æ»æãããã®ãå¤ãã®ã§ãããXML ãã¼ã¿ãåä¿¡ãã¦å¦çãããµã¼ãã¹ã§ã¯ããã£ã 1 åã®éä¿¡ã§ãµã¼ãã¹è½åã®ä½ä¸ããããã¯ãµã¼ãã¹åæ¢ã«è¿½ãè¾¼ã¾ããå¯è½æ§ãããã¾ããä»åã¯ãã®ç¹ãæ¤è¨¼ãã対çãèãã¾ãããã ã¿ãªããã¯ããã©ã¦ã¶ã»ã¯ã©ãã·ã£ã¼ãã¨ããè¨èããèãã«ãªã£ããã¨ãããã§ããããï¼ãã©ã¦ã¶ã§Web ãã¼ã¸ãéããæã«ãã©ã¦ã¶ãããªã¼ãºãããããã·ã¹ãã ããªã½ã¼ã¹ä¸è¶³ã«ãã¦åä½ä¸è½ã«ããããããªå±éºãªWeb ãã¼ã¸ã®ãã¨ã§ããå¿åæ²ç¤ºæ¿ãªã©ã§ããããããããããã«ãã©ã¦ã¶ã»ã¯ã©ãã·ã£ã¼ã¸ã®ãªã³ã¯ãæ¸ãè¾¼ã¾ããå ´åãããã® ã§ããªã³ã¯ãä¸ç¨æã«ã¯ãªãã¯
ãXMLããã»ãã¥ãªãã£ãã¨ããåèªã§Webæ¤ç´¢ããã¨ãå¤ããããããã®ã¯XMLãã¸ã¿ã«ç½²åãXMLæå·ãªã©ã説æããWebãã¼ã¸ã§ãã æ¬æ¥ã®æ¥è¨ã§ã¯ãããã¨ã¯ã¡ãã£ã¨éããã¼ãï¼XXEã¨å¼ã°ããæ»æï¼ã«ã¤ãã¦æ¸ãã¾ãã èå¼±ãªã³ã¼ãã¨æ»ææ¹æ³ ãã£ããèå¼±æ§ããããµã³ãã«ããã°ã©ã ã§ãã import java.io.*; import javax.servlet.*; import javax.servlet.http.*; import org.w3c.dom.*; import org.apache.xerces.parsers.*; import org.xml.sax.*; public class Test1 extends HttpServlet { public void service(HttpServletRequest request, HttpServletRe
ãã®ãã©ã¦ã¶ã¼ã¯ãµãã¼ããããªããªãã¾ããã Microsoft Edge ã«ã¢ããã°ã¬ã¼ãããã¨ãææ°ã®æ©è½ãã»ãã¥ãªãã£æ´æ°ããã°ã©ã ãããã³ãã¯ãã«ã« ãµãã¼ããå©ç¨ã§ãã¾ãã XML ãµã¼ãã¹æå¦æ»æã¨é²å¾¡ç Bryan Sullivan ãµã¼ãã¹æå¦ (DoS) æ»æã¯ãWeb ãµã¤ãã«å¯¾ããæ»æã®ä¸ã§ãæãå¤ããããã種é¡ã®æ»æã® 1 ã¤ã§ããDoS æ»æã¯ãå°ãªãã¨ã 1992 å¹´ã®è¨é²ã«ã¯æ¢ã«æ®ã£ã¦ãããSQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ (1998 å¹´ã«çºè¦ããã¾ãã)ãã¯ãã¹ãµã¤ã ã¹ã¯ãªããã£ã³ã° (JavaScript ãçºæãããã®ã¯ 1995 å¹´ã«ãªã£ã¦ããã§ã)ãããã³ã¯ãã¹ãµã¤ã ãªã¯ã¨ã¹ã ãã©ã¼ã¸ã§ãª (CSRF (ã¯ãã¹ãµã¤ã ãªã¯ã¨ã¹ã ãã©ã¼ã¸ã§ãª) æ»æã¯ä¸è¬ã«ã»ãã·ã§ã³ Cookie ãå¿ è¦ã¨ãã¾ãããCookie ãä¸ã«åºãã®ã¯ 1994 å¹´ã«ãªã£ã¦ã
TAKAGI, Hiromitsu @TakagiHiromitsu ãå°æ¹å ¬å ±å£ä½ã«ãããæ å ±ã·ã¹ãã ã»ãã¥ãªãã£è¦æ±ä»æ§ã¢ãã«ãã©ã³ï¼Webã¢ããªã±ã¼ã·ã§ã³ï¼ãhttp://t.co/giM0AzYb ãWebã¢ããªã±ã¼ã·ã§ã³ãå°å ¥ããã«ããã£ã¦ãã·ã¹ãã ã®èå¼±æ§ããªãããå®å ¨ã«éç¨ããããã«å¿ è¦ãªè¦æ±ä»æ§äºé ãåãã¾ã¨ããç¹è¨ä»æ§æ¸ã®ä¾ã§ãã 2012-10-22 15:00:03 TAKAGI, Hiromitsu @TakagiHiromitsu LASDECãWebã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£è¦æ±ä»æ§çæ¤è¨å§å¡ä¼ãã«åç»ããé·å¹´ã®æ¸æ¡ã§ãã£ãã»ãã¥ã¢ãªçºæ³¨ä»æ§ã®ä¸ã¤ã®å¨ãæ¹ã示ãã¾ããã ãå°æ¹å ¬å ±å£ä½ã«ãããæ å ±ã·ã¹ãã ã»ãã¥ãªãã£è¦æ±ä»æ§ã¢ãã«ãã©ã³ï¼Webã¢ããªã±ã¼ã·ã§ã³ï¼ãhttp://t.co/giM0AzYb 2012-10-22 19:46:01 TAKAGI,
横æµå¸ã®ãã¼ã ãã¼ã¸ï¼ï¼¨ï¼°ï¼ã«è è¿«æãæ¸ãè¾¼ã¾ããäºä»¶ã«çµ¡ã¿ãåå¸ã®ï¼¨ï¼°ã®å¼±ç¹ãæªç¨ãããå¯è½æ§ããããã¨ãããå¸ã¯ï¼¨ï¼°ã®ããã°ã©ã ãä¿®æ£ãã¦ã»ãã¥ãªãã£ã¼å¯¾çãå¼·åããæ¹éãåºããã ãã®äºä»¶ãå·¡ã£ã¦ã¯ãæ治大å¦çã ã£ãå°å¹´ï¼ï¼ï¼ï¼ãçè¦ã«é®æããããã®å¾ãä¿è·è¦³å¯å¦åã¨ãªã£ããããããä»æä¸æ¬ããçç¯äººããåä¹ã人ç©ããæ±äº¬é½å ã®å¼è·å£«ãªã©ã«å±ããç¯è¡å£°æã¨ã¿ãããã¡ã¼ã«ã«ãç¯äººããç¥ãå¾ãªãç¯è¡äºåã®å ¨æãæ¸ããã¦ãããã¨ãªã©ãããçè¦ã¯å°å¹´ä»¥å¤ã®ç¬¬ä¸è ãé¢ä¸ããªãã£ããäºä»¶ã®æ¤è¨¼ãå§ãã¦ããã ç¯è¡å£°æã¨ã¿ãããã¡ã¼ã«ã«ã¯ãé²è¦§ãããã¦ã§ããµã¤ãããä¸æ£ãªå½ä»¤ãéã£ã¦ãã½ã³ã³ãæä½ãããã¯ãã¹ãµã¤ãã»ãªã¯ã¨ã¹ãã»ãã©ã¼ã¸ã§ãªï¼ï¼£ï¼³ï¼²ï¼¦ï¼ãã¨å¼ã°ããæ»æãä»æããã¨æ¸ããã¦ããã å¸ï¼©ï¼´æ´»ç¨æ¨é²èª²ã«ããã¨ãæªç¨ãããã®ã¯å¸åºè´ç¸è«èª²ã®ç®¡çããå¸ã®ï¼¨ï¼°å ã«ããæ稿æ¬ãå¸æ°ããã®ææ¡ãã
ã¢ã¸ã¢æ大ã®æ ¼å®èªç©ºä¼ç¤¾ï¼ï¼¬ï¼£ï¼£ï¼ã°ã«ã¼ããã¨ã¢ã¢ã¸ã¢ãã®ãã¼ã ãã¼ã¸ï¼ï¼¨ï¼°ï¼ä¸ã§ãäºç´çªå·ãå ¥åããã ãã§ä»äººã®é»è©±çªå·ãã¯ã¬ã¸ããã«ã¼ãçªå·ã®ä¸é¨ãªã©å人æ å ±ãè¦ãããé²è¦§ãã人ãåæã«äºç´å¤æ´ãã§ããç¶æ ã«ãªã£ã¦ãããã¨ãåãã£ãã ï¼ï¼æ¥ååï¼ï¼æãããé¢æ±å¨ä½ã®ç·æ§ä¼ç¤¾å¡ï¼ï¼ï¼ï¼ãHPã«èª¤ã£ã¦å¥ã®äºç´çªå·ãå ¥åããã¨ãï¼ï¼æ³ã®ãã¬ã¼ã·ã¢äººã®æ°åã¨çå¹´ææ¥ãé»è©±çªå·ãã¡ã¼ã«ã¢ãã¬ã¹ãã¯ã¬ã¸ããã«ã¼ãçªå·ã®ä¸ï¼æ¡ãªã©ã表示ããããäºç´ãããã¬ã¼ã·ã¢å½å ç·ã®æä¹æ¥ã便åã座å¸çªå·ãåããããå¤æ´ããã¯ãªãã¯ããã°å¤æ´å¯è½ãªç¶æ ã ã£ãã åæ§ã«éãäºç´çªå·ãå ¥åããã ãã§ãåæ¥åå¾ï¼ï¼æåæç¹ã§ãã¬ã¼ã·ã¢ï¼ï¼äººãã¤ã³ããã·ã¢ï¼ï¼äººãæ¥æ¬ï¼äººãªã©ãå°ãªãã¨ãï¼ï¼äººåã®å人æ å ±ãé²è¦§ã§ãããæ¥æ¬èªç©ºãå ¨æ¥ç©ºã«ããã¨äºç´æ å ±ç §ä¼ã«ã¯ä»ã«æ°åãæä¹æ¥ã便åã®å ¥åãå¿ è¦ã§ãäºç´çªå·ã ãå ¥åãã¦
ã¹ã¯ã¦ã§ã¢ã»ã¨ããã¯ã¹ã¯10æ16æ¥ãå社ãéå¶ãããªã³ã©ã¤ã³ã·ã§ããã³ã°ãµã¼ãã¹ãã¹ã¯ã¦ã§ã¢ã»ã¨ããã¯ã¹ ãªãã£ã·ã£ã«ã°ããºãªã³ã©ã¤ã³ã·ã§ãããã«ã¤ãã¦ãä¸æ£ã¢ã¯ã»ã¹ã«ããå人æ å ±ãçªåããã形跡ã確èªãåã·ã§ããã³ã°ãµã¼ãã¹ãçµäºãããã¨ãçºè¡¨ããã å社ã¯9æ13æ¥ã®æç¹ã§ä¸æ£ã¢ã¯ã»ã¹ã®å¯è½æ§ããã£ããã¨ãåç¥ããã®å¾ã®å社ãªãã³ã«å¤é¨èª¿æ»æ©é¢ã«ãã調æ»ã®çµæãå½è©²ãµã¼ãã¼ã«æ ¼ç´ããã¦ããããµã¤ãä¸ã§ç»é²ãã¦ããå人æ å ±ã®ãæ°åããä½æããé»è©±çªå·ããæ§å¥ããçå¹´ææ¥ããã¡ã¼ã«ã¢ãã¬ã¹ããçªåããã形跡ã確èªããã¨ã®ãã¨ããªããè³¼å ¥ã«ãããå ¥åãããã¯ã¬ã¸ããã«ã¼ãçªå·ã«ã¤ãã¦ã¯ãä¸æ£ã¢ã¯ã»ã¹ãå¯è½ãªç¶æ ã§ãã£ããã¨ã¯ç¢ºèªããã¦ããããçªåããã形跡ã¯ç¢ºèªããã¦ããªãã å½è©²ãµã¼ãã¼ã¯ãå社ã®ãã£ã©ã¯ã¿ã¼ã°ããºè²©å£²ã®ã¿ã«ä½¿ç¨ãã¦ããå°ç¨ãµã¼ãã¼ã§ãããæ¥åå§è¨å ã管çãå社ã®ãã®ä»ã®
æ å ±ãå®ããæªæ¥ãåµé ãããã¤ãªãã¢ã¨ãã¦ã®ä¿¡é ¼ã¨èªä¿¡ã§ããã£ã¨å 㸠æé«å³°ã®ã»ãã¥ãªãã£ãµã¼ãã¹ã¨ãITãã¼ã¿ã«ã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¾ãã ãã£ã¨ç¥ã
å¤ã¨ãããã¨ã§ãæã話ããã¾ãã Webã¢ããªã±ã¼ã·ã§ã³éçºè ã®çãããèãã¦ä¸ããã æéããªã人ããä»ã®äººã«åé¡ã説æããã¨ããªã©ã«ã¯ç°¡æ½ã«ã¾ã¨ããçãã©ããã ããã¯2011å¹´12æ27æ¥ã«Appleã«å ±åããSafariã®åé¡ã§ããAppleããã¯ä¿®æ£ããäºå®ã¯ãªãã¨ããåçãè²°ã£ã¦ãã¾ãããã2012å¹´7æ25æ¥ã«ãªãªã¼ã¹ãããMacã®Safari 6ã®ã¢ããã¤ã¶ãªã«ããã¨ã©ããMacã®Safari 6ã§ã¯ä¿®æ£ãããããã§ãã About the security content of Safari 6 http://support.apple.com/kb/HT5400 WebKit Available for: OS X Lion v10.7.4, OS X Lion Server v10.7.4 Impact: Visiting a maliciously crafted
å ¬é: 2012å¹´7æ9æ¥3æ5åé ãããªã話ãâ¦â¦ãCOOKPADã®ãä¼ãåã«ããå ¥åããã¿ã³ã¯ç´ æ´ããã (blog.tokumaru.org)ãã é常ããã¹ã¯ã¼ãå ¥åæ¬ã§ã¯ãå ¥åä¸ã®ãã¹ã¯ã¼ãããã¹ã¯ããã¦èªããªãããã«ãªã£ã¦ãã¾ãããããããã¹ã¯ããªãæ¹ãè¯ãã®ã§ã¯ãªããã¨ãã説ãããã¾ãããã£ã¨åã«ããã¹ã¯ã¼ããé ãã®ããããã?ãã¨ãã話ã§ã触ãã¾ããããã¤ã³ãã»ãã¼ã«ã»ã³ãããã¹ã¯ã¼ããé ãã®ããããã (www.usability.gr.jp)ãã¨ãã主張ããã¦ãã¾ãã ãã¹ã¯ã¼ãå ¥åãé£ãããªãã¨ãã¦ã¼ã¶ã¼ã¯ããå ¥åãããããã¹ã¯ã¼ããå©ç¨ãããã¨ããã§ããããå®éãã±ã¼ã¿ã¤ã§ã¯è¤éãªãã¹ã¯ã¼ããå ¥ããã®ã大å¤é¢åãªãããã¦ã¼ã¶ã¼ã¯æ°åã®ã¿ã®çããã¹ã¯ã¼ãã好ãå¾åãããã¾ãããã¹ã¯ã¼ãå ¥åãããã«ããã¨ãã¦ã¼ã¶ã¼ã¯å¼±ããã¹ã¯ã¼ãã使ãããã«ãªããéã«å®å ¨æ§ãæãªãã
NRIã»ãã¥ã¢ãã¯ããã¸ã¼ãºãå®æ½ããä¼æ¥ã®ã»ãã¥ãªãã£åæ調æ»ãããWebã·ã¹ãã ãã»ãã¥ãªãã£ä¸ã®èå¼±ç¹ã«ãªã£ã¦ããå®æ ãåãã£ãã NRIã»ãã¥ã¢ãã¯ããã¸ã¼ãºã¯7æ5æ¥ã2012å¹´çã®ãä¼æ¥æ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£ã«é¢ããåæçµæãã®ã¬ãã¼ããçºè¡¨ãããå社ã®é¡§å®¢ä¼æ¥ã«ããã2011年度ã®ã»ãã¥ãªãã£ç¶æ³ãããWebã·ã¹ãã ã®å¯¾çãååã§ã¯ãªããã¨ãåãã£ãã ãã®åæã¯å社ã®æ å ±ã»ãã¥ãªãã£ãµã¼ãã¹ãå©ç¨ãã顧客ä¼æ¥ã®ãã¼ã¿ãåºã«ãããã®ã§ã2005年度ããæ¯å¹´å®æ½ãã¦ããã2011年度ã®åæãã以ä¸ã®3ã¤ã®åé¡ç¹ãæµ®ã彫ãã«ãªã£ãã¨ããã ã»ãã¥ãªãã£ç®¡çãç¾å°ä»»ãã«ãã¦ãããã¨ãå¤ãæµ·å¤æ ç¹Webãµã¤ãã®åæ°ã¯å±éºãªç¶æ ä¼æ¥ã®å ¬éWebã·ã¹ãã ã®3å²å¼·ããã¡ã¤ã¢ã¦ã©ã¼ã«ã§é²ããªãå±éºãªèå¼±æ§ã¸ã®å¯¾çãä¸åå ã½ã¼ã·ã£ã«ã¡ãã£ã¢ã®æ®åã«ããæ¨çåã¡ã¼ã«æ»æã®è å¨ãæ¡å¤§ãã¦ã
ãã¤ã¯ãã½ãã ã»ãã¥ãªãã£æ å ± MS12-023 - ç·æ¥ : Internet Explorer ç¨ã®ç´¯ç©çãªã»ãã¥ãªãã£æ´æ°ããã°ã©ã (2675157) http://technet.microsoft.com/ja-jp/security/bulletin/ms12-023 ãã®ã»ãã¥ãªãã£æ å ±ã«çµã¿è¾¼ã¾ãã¦ããå¤å±¤é²å¾¡ã«ã¤ãã¦ãã¤ã¯ãã½ããã¨ååãã¦ãã ãã£ã Masato Kinugawa æ° 2012å¹´4æã®Microsoftã®æä¾ã¢ãããã¼ãã«å«ã¾ãããMS12-023ã§ä¿®æ£ããããã®ä»¶ã«ã¤ãã¦æ¸ãã¾ãã Internet Explorer 9ã§ã¯ãæªæããè ã«èªå°ããã¦ã¢ãã¬ã¹ãã¼ã§ä¸æ¬æãªJavaScriptãå®è¡ãã¦ãã¾ããã¨(self-XSS)ãé²æ¢ããããã«ããjavascript:alert(1)ãããvbscript:alert(1)ãã®ãããªãã¹ã¯ãªããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}