
ãã®ã¨ã³ããªã§ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã«ããããã°ã¢ã¦ãæ©è½ã«é¢é£ãã¦ããã®ç®çã¨å®ç¾æ¹æ³ã«ã¤ãã¦èª¬æãã¾ãã è°è«ã®åæ ãã®ã¨ã³ããªã§ã¯ãèªè¨¼æ¹å¼ã¨ãã¦ããããããã©ã¼ã èªè¨¼ãåæã¨ãã¦ãã¾ãããã©ã¼ã èªè¨¼ã¯ä¿ãªè¨ãæ¹ããããã¾ããããHTMLãã©ã¼ã ã§IDã¨ãã¹ã¯ã¼ãã®å ¥åãã©ã¼ã ãä½æãããã®å ¥åå¤ãã¢ããªã±ã¼ã·ã§ã³å´ã§æ¤è¨¼ããèªè¨¼æ¹å¼ã®ãã¨ã§ããIDã¨ãã¹ã¯ã¼ãã®å ¥åã¯æåã®1åã§ãã¾ããããããé常ã¯Cookieãç¨ãã¦èªè¨¼ç¶æ ãä¿æãã¾ãããã°ã¢ã¦ãæ©è½ã¨ã¯ãä¿æãããèªè¨¼ç¶æ ãç ´æ£ãã¦ãèªè¨¼ãã¦ããªãç¶æ ã«æ»ããã¨ã§ãã Cookieãç¨ããèªè¨¼ç¶æ ä¿æ åè¿°ã®ããã«ãèªè¨¼ç¶æ ã®ä¿æã«ã¯Cookieãç¨ãããã¨ãä¸è¬çã§ãããCookieã« auth=1 ã¨ããuserid=tokumaru ãªã©ã®ããã«ããã°ã¤ã³ç¶æ ãããã®ã¾ã¾ãCookieã«ä¿æããã¨èå¼±æ§ã«ãªãã¾ã
ãµã¼ãã¼ã¯ã¹CEOããã°ã大ç³èµäººä¹å©ã®ãé²ãã¤ãããããªè©±ãã¯ã ãã¯ã¦ãªããã°ãã¸ç§»è¡è´ãã¾ããã æ§ããã°è¨äºã®URLãããè¶ãã®çæ§ã¯èªåã§æ°ããã°ã¸è»¢éããã¾ãã 転éãããªãå ´åãæãå ¥ãã¾ããä¸è¨URLãã移åããé¡ãè´ãã¾ãã æ°URLï¼https://ceo.serverworks.co.jp/ å¼ãç¶ãã大ç³èµäººä¹å©ã®ãé²ãã¤ãããããªè©±ããå®ãããé¡ããããã¾ãã
ç±³Yahoo!ã¯ç¾å°æé2012å¹´3æ29æ¥ãå人æ å ±ç®¡çæ段ãDo Not Trackããåå¤ã¾ã§ã«å ¨é¢å°å ¥ããã¨çºè¡¨ãããå社ã®ä¸çãããã¯ã¼ã¯å ¨ä½ã«ããã£ã¦Do Not Trackãããã¼ãå©ç¨å¯è½ã«ãããå°å ¥å¯¾è±¡ã«ã¯ãå社åä¸ã®ãªã³ã©ã¤ã³åºåãªã¼ã¯ã·ã§ã³äºæ¥Right Mediaã¨ã¿ã¼ã²ããåãªã³ã©ã¤ã³åºåæè¡ã®interclickãå«ã¾ããã Do Not Trackã¯ã¤ã³ã¿ã¼ãããã¦ã¼ã¶ã¼ããªã³ã©ã¤ã³è¡åã®è¿½è·¡ãæå¦ã§ããããã«ããããã®æ段ãç±³é£é¦åå¼å§å¡ä¼ï¼FTCï¼ã¯ãã©ã¤ãã·ã¼ä¿è·ã®æ çµã¿ææ¡ã«åæ段ã®æ¡ç¨ãçãè¾¼ãã§ããã3æ26æ¥ã«çºè¡¨ããæçµå ±åæ¸ã§ã¯ã2012å¹´æ«ã¾ã§ã«å¹æçã§ä½¿ããããDo Not Trackãªãã·ã§ã³ãæ¶è²»è ã«æä¾ã§ããããã«ãªãã¨ç¢ºä¿¡ãã¦ãããã¨ã®è¦è§£ã示ããï¼é¢é£è¨äºï¼FTCããã©ã¤ãã·ã¼ä¿è·ã®å ±åæ¸ããã¼ã¿ããã¼ã«ã¼åãæ³æ´åãªã©è¿½å ï¼ã
å æ¥å§ã¾ã£ã LAWSON Wi-Fi ãå©ç¨ããããã«å¿ è¦ãªãã¼ã½ã³ã¢ããªã®å©ç¨è¦ç´ãã¨ãã§ããªãã£ã件ã ã¢ããªå©ç¨ä¸ã¯èª°ã®èªçæ¥ãé»è©±çªå·ãç¥ããã¦ã¯ãããªãããç¥ããã¨ãã¦ããããªãï¼ Pontaã«ã¼ãã解ç´ãããã¨ãã¦ããã¼ã½ã³ã¢ããªã®è¦ç´ã§éä¼åºæ¥ç¡ãï¼è©°ãã ï¼ ã4/10 22:10ã ç¶ããèªã
ããã¡ãéè¡ã®ã¹ã¯ã¬ã¼ãã¼ãæ¸ãã«å½ããããã¹ã¯ã¼ãã¨åè¨èãããããªãã£ãã®ã§åæåããé¡ãããã åæåããé¡ãããã®ã«ãçªå£ã®ãå§ããã«ãåéç¥ã§ããï¼ãã¨ãè¨ãããããã£ã¨è¨ãééãã ããã¨æã£ã¦ãããæ¬å½ã«ãã¹ã¯ã¼ããå¹³æã§å±ããã ãã¹ã¯ã¼ããå¿ããã®ã§éµééç¥ããé¡ãããã åã®ãã¹ã¯ã¼ãå°åããèåç´ãå±ãããï¼¼(^o^)ï¼ ããç´ããããªãã¯è¦ãã¦ããã£ããã£ããå¿ãããã¹ã¯ã¼ããå°åããã¦éµéããã¦ããã ãã¸ã§ãã³å¼ããããã å¿ãããã¹ã¯ã¼ããéããã¦ãããã (ãã¹ã¯ã¼ããå°åããã¦å±ããã) (æ証çªå·ãå°åããã¦å±ããã ) ãããã«ããã¯ãã³å¼ããããã ããæ å ±å¦çã»ã³ã¿ã®ãã¤ããæä½æ¥ã§å°ãã¦ããã§ãããã»ã»ã» ããããç´å¤±ãããã¹ã¯ã¼ããå¹³æã§ãã®ã¾ã¾å±ãã¾ããããåçºè¡ãããªãã¦ã以åã®ãã®ããã®ã¾ã¾ã éµéã§éããããããã ãã¹ã¯ã¼ããå¹³æã§ä¿æ
In some of the feedback I have gotten on the openID Connect spec, the statement is made that Connect is too complicated. That OAuth 2.0 is all you need to do authentication. Many point to Identity Pro⦠è±èªèªã¿ãããªãã¨ãã人ã®ããã«ç°¡åã«è§£èª¬ããã¨â¦ OAuth 2.0 ã® implicit flow ã使ã£ã¦ãèªè¨¼ãããããã¨ããã¨ãã¨ã£ã¦ã大ããªç©´ãéãã¾ãã ã«ããï¼ãã¼ã¹ãã¢ã¿ãã¯ãå¯è½ã ããã§ãã OAuth èªè¨¼ï¼ã¯ãå³ï¼ã®ãããªæµãã«ãªãã¾ãã å³ï¼ OAuth èªè¨¼ï¼ã®æµã ä¸è¦ãåé¡ãªãããã«è¦ãã¾ããããããããã¯ãã¹ã¦ã®ãµã¤ãããè¯ããµã¤ãããªãã°ã§ãã Site_A
ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãª (cross-site request forgery) ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã®ä¸ã¤[1]ãããã¯ãããå©ç¨ããæ»æãç¥ç§°ã¯CSRFï¼ã·ã¼ãµã¼ã (sea-surf) ã¨èªã¾ããäºããã[2][3]ï¼ãã¾ãã¯XSRFããªã¯ã¨ã¹ãå¼·è¦[4]ãã»ãã·ã§ã³ã©ã¤ãã£ã³ã° (session riding[3]) ã¨ãå¼ã°ããã1990年代ã¯ã¤ã¡ã¿ã°æ»æã¨ãå¼ã°ãã¦ãã[è¦åºå ¸]ãèå¼±æ§ãããªã¼åã«åé¡ããCWEã§ã¯CSRFããã¼ã¿èªè¨¼ã®ä¸ååãªæ¤è¨¼ (CWE-345) ã«ããèå¼±æ§ã®ã²ã¨ã¤ã¨ãã¦åé¡ãã¦ãã (CWE-352)[5]ã ãªãCSRFã®æ£å¼å称ã¯ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° (XSS) ã¨ä¼¼ã¦ããããXSSã¯ä¸é©åãªå ¥åç¢ºèª (CWE-20) ã«ããã¤ã³ã¸ã§ã¯ã·ã§ã³ (CWE-74) ã®ã²ã¨ã¤ã¨ãã¦åé¡ããã¦ãã[5]ãå ¨ãç°ãªã種é¡ã®
ãå®è·µDNS - DNSSECæ代ã®DNSã®è¨å®ã¨éç¨ -ãã®ç®æ¬ãé ãã¾ããã ãããã¨ããããã¾ãã ç§ã¯DNSã®ãã¨ãè¯ãããããªãã¦ãåå¼·ããããã¨æãã¤ã¤è²ã 調ã¹ã¦ã¯ããã®ã§ãããDNSã®æ å ±ãã¾ã¨ã¾ã£ã¦è¿°ã¹ããã¦ããæ¸ç±ãçºè¦ã§ããã«å°ã£ã¦ããã¨ããã ã£ãã®ã§ãé常ã«åèã«ãªãã¾ããã ããã¾ã§ãé称ãããã¿æ¬ãã¨å¼ã°ãã¦ããDNS & BINDãæã詳ããDNSæ¬ã ã£ãã¨æãã®ã§ãããããã¿æ¬ã¯BINDã®æ¬ã§ãã£ã¦ãDNSã®æ¬ã§ã¯ããã¾ããã§ããã ããããæå³ã§ããå®è·µDNSãã¯ãæè¡ã¨ãã¦ã®DNSã«é¢ãã¦ããããªæ¸ãã¦ããè¯æ¸ã ã¨æãã¾ãã 豪è¯ãªå·çé£ ãå®è·µDNSãã¯ãDNSãDNSSECã«é¢ãã¦æ¥æ¬å½å ã§èãå¾ãæé«ã¬ãã«ã®å·çé£ã«ãã£ã¦å·çããã¦ããã¨æãã¾ããã èè ã¯3åã¨ãã.jpãã®JPãã¡ã¤ã³åã®ç»é²ç®¡çæ¥åã¨DNSã®éç¨ãè¡ã£ã¦ããæ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ã
ãã¼ãã©ã£ãã話ãã°ããããªãæ£ç´ã«ããããã®ã¨ããããæ¸ãã®ãå ¬å¹³ã§ãããããããªããããTwitter ã§ã¦ãªãããã¦ã人ã¯ãããã¨ãããã¼ããªã«ããªããããå¥³è£ ã女ã£ã½ãè¨åããã¦ãªããã©ãå¿ã¯å¥³ã¨ããããä¼¼åãããããã°å¥³ã®åã®æ ¼å¥½ãããããããã²ã¼ã ã®ãã£ã©ãã¢ãã¿ã¼ã¯å¿ ã女æ§ã«ãããã§ããããã«ãã¨è¨ã£ãã»ããæ£ããããªã ãã§ãã¡ãã£ã¨åã«ã¦ã§ãæ¥çã®èª¿æ»ã¨å¥½å¥å¿ã§ã¢ãã²ã¼ã«å ¥ä¼ãã¾ãããããã¹ãã¼ããã©ã³çã§ãï¼ç§ã®ææ端æ«ã¯ iPhone 3Gï¼ããã®éããã¨ã§ã¢ãã¿ã¼ã¯èªç±ã«çãæ¿ããããã¨æã£ã¦ãæ§å¥ã®æ¬ã¯ãç·æ§ãã«ããããããæ¸ç±ä¸ãç·æ§ã ãããããããã¢ãã¿ã¼ããããã¦ããã¨æã£ãããç·æ§å½¢åºå®ã§å¥³æ§å½¢ã«ã§ããªããããã ãã§ããããããªãããå¥ã¢ã«ã¦ã³ãä½ããã¨æã£ã¦ãå¥ã®ã¡ã¢ãã§ã¢ã«ã¦ã³ãä½ã£ããããã§ç«ã¡å¡ããã®ããæºå¸¯é»è©±çªå·èªè¨¼ããæºå¸¯é»è©±çªå·ãå ¥åãã¦
2011å¹´10æ05æ¥22:30 ã«ãã´ãªæ¸è©/ç»è©/åè©iTech ããã§æä½é! - æ¸è© - ä½ç³»çã«å¦ã¶ å®å ¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹ ã½ãããã³ã¯ã¯ãªã¨ã¤ãã£ãåä¿æ§ããç®æ¬å¾¡ç¤¼ã ä½ç³»çã«å¦ã¶ å®å ¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹ èå¼±æ§ãçã¾ããåçã¨å¯¾çã®å®è·µ 徳丸浩 [é»åç@bookpub.jp] ååº2011.02.24; 2011.10.05 é»åçã¸ã®ãªã³ã¯ã追å ããããæ¬ãå¾ ã£ã¦ãããWebå¶ä½ã«é¢ããå ¨ã¦ã®äººãå¿ æºã ã¨åæã«è¨ã£ã¦ããããã®ã¯ãå®å ¨ãªWebã¢ããªã±ã¼ã·ã§ã³ãä½ãã«ããã£ã¦ãæ¬æ¸ã®å 容ã¯ããã¾ã§å¿ è¦æ¡ä»¶ã§ãã£ã¦å åæ¡ä»¶ã§ã¯ãªãã¨ãããã¨ãåççã«ã ãªããã ããªãã®Webãµã¤ãã§ä½ãåºæ¥ã¦ã¯ãªããªããã¯ãããªãã«ãã決ããããªãããã ã æ¬æ¸ãä½ç³»çã«å¦ã¶ å®å ¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹ãã¯ãå¯é¡ã«ãèå¼±æ§ãçã¾ããåçã¨å¯¾ç
ãããã®VPS ã£ã¦ããã©ã«ãã§ã¯ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã®è¨å®ä½ãããã¦ãªãã¨ããè¨äºãã¿ã¦é©æãããã¨ãããèããã Ubuntu 10.04 LTS ãåã¤ã³ã¹ãã¼ã«ãããããã©ã£ã¡ã«ãã¦ãåæç¶æ ã ãªã ã¨ãããã確ãããã $ sudo iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination ãªã¦ããããã©ã«ãã¯ç©ºãªã®ãâ¦â¦ iptables ã®è¨å®ããã©ããããªã¼ã©ããããããªã¼ãã¨æã£ã¦ããããã©ãã Ubuntu ã§ã¯ ufw ã¨ãã
æè¿ã®ã¢ãã³ãªWebãã©ã¦ã¶ããµãã¼ããã¦ãããã»ãã¥ãªãã£ã«é¢é£ããã㪠X- ãªHTTPã¬ã¹ãã³ã¹ããããã¾ã¨ãã¦ã¿ã¾ããããã以å¤ã«ããã£ããæãã¦ãã ããã X-XSS-Protection 0:XSSãã£ã«ã¿ãç¡å¹ã«ããã 1:XSSãã£ã«ã¿ãæå¹ã«ããã XSSãã£ã«ã¿ãæå¹ã«ãããã¨ã§ã¨ã³ãã¦ã¼ã¶ãXSSã®è¢«å®³ã«ããå¯è½æ§ãä½æ¸ããããã¾ãã«èª¤æ¤ç¥ãããã¨ã§ç»é¢ã®è¡¨ç¤ºãä¹±ãããã¨ããããIE8+ãSafariãChrome(å¤å) ã§æå¹ãIEã§ã¯ãX-XSS-Protection: 1; mode=blockãã¨ããæå®ãå¯è½ã 2008/7/2 - IE8 Security Part IV: The XSS FilterBug 27312 â [XSSAuditor] Add support for header X-XSS-Protection X-Content-Ty
ç¥ç° å¤§ä» @kanda_daisuke ã¿ãªãã¾ããã¯ãããããã¾ããè¨äºãæ¸ãã¾ããææ¥æ°èã®ç¥ç°ã¨ç³ãã¾ããä»åã®ä»¶ã§ã¯ããã¤ãã¿ã¼ãããã°ãªã©ãããä¸ã®æ å ±ãããããåèã«ããã¦ããã ãã¾ãããã¾ãã¯ã礼ãç³ãä¸ãã¾ãã #librahack 2010-08-21 08:50:36 ç¥ç° å¤§ä» @kanda_daisuke ãã®ä»¶ã§ã¯ããããï¼ãæéã«ããã£ã¦åæãç¶ãã¦ãã¾ããï¼æ¯æ¥ãã®åé¡ã ãã«å°å¾ãã¦ããããã§ã¯ããã¾ãããï¼ãè¨äºã«æ¸ããã¦ãããã¨ã¯ã»ãã®ã¨ãã»ã³ã¹ã«éãããã¾ãåºç¯å²ãªæ°èèªè ãæ³å®ãã¦ãããããããããã¨è¡¨ç¾ãã丸ãã¦ãããã¾ãã #librahack 2010-08-21 08:53:14
æ¬è³æã¯ãJVNã§å ¬è¡¨ãããJVN#79314822ï¼ãTomcatãã«ããããªã¯ã¨ã¹ãå¦çã«é¢ããèå¼±æ§ãã«ã¤ãã¦è§£èª¬ãããã®ã§ãã ãApache Tomcatãï¼ä»¥ä¸ ãTomcatãï¼ã¯ããµã¼ãä¸ã§ Java ã¢ããªã±ã¼ã·ã§ã³ãåä½ãããããã®ã½ããã¦ã§ã¢ã§ããJava ãµã¼ãã¬ããä»æ§ã¨ JavaServer Pages ä»æ§ã®ãªãã¡ã¬ã³ã¹å®è£ ã¨ãªã£ã¦ãã¾ãã ãTomcatãã«ã¯ãã¦ã§ããµã¼ãã¨é£åããæ©è½ãããã¾ããAJP (Apache JServ Protocol) 1.3 ã¯é£åã®ããã®ãããã³ã«ã®ä¸ã¤ã§ãAJP 1.3 Connector (org.apache.ajp.tomcat4.Ajp13Connector) 㯠AJP 1.3 ã使ç¨ããã³ãã¯ã¿ã®ä¸ã¤ã§ãããã®ã³ãã¯ã¿ã使ç¨ããå ´åããTomcatãã¯ã¦ã§ããµã¼ããã AJP 1.3 ãªã¯ã¨ã¹ããåãåãã
HASHã³ã³ãµã«ãã£ã³ã°æ ªå¼ä¼ç¤¾ å ¬éæ¥:2009å¹´11æ24æ¥ è¿½è¨æ¥:2010å¹´1æ21æ¥ æ¦è¦ iã¢ã¼ããã©ã¦ã¶2.0ã®JavaScriptã¨DNS Rebinding(DNSãªãã¤ã³ãã£ã³ã°)åé¡ã®çµã¿åããã«ãããiã¢ã¼ãIDãå©ç¨ããèªè¨¼æ©è½ï¼ä»¥ä¸ãããããã°ã¤ã³ï¼ã«å¯¾ããä¸æ£ã¢ã¯ã»ã¹ãå¯è½ã¨ãªãå ´åããããã¨ã確èªããã®ã§å ±åãããå±éºåº¦ã®é«ãæ»æææ³ã§ããã®ã§ããµã¤ãéå¶è ã«ã¯è³æ¥ã®å¯¾çãæ¨å¥¨ããã èæ¯ æºå¸¯é»è©±ã®ãããããã°ã¤ã³ã¨ã¯ãã±ã¼ã¿ã¤ãã©ã¦ã¶ï¼ãã¨ãã°iã¢ã¼ããã©ã¦ã¶ï¼ã«ç¨æãããå¥ç´è åºæIDãå©ç¨ããç°¡æçãªèªè¨¼ã§ãããã¦ã¼ã¶ãIDããã¹ã¯ã¼ããå ¥åããªãã¦ãèªè¨¼ãå¯è½ã¨ãªããiã¢ã¼ãIDã¯ãNTTãã³ã¢ã®æä¾ããå¥ç´è åºæIDã®ä¸ç¨®ã§ãURLã«guid=ONã¨ããã¯ã¨ãªã¹ããªã³ã°ãå«ãããã¨ã«ããã端æ«åºæã®7æ¡ã®IDãWebãµã¼ãã«éåºããããç¾å¨ãiã¢
â ãWPA-TKIPã1åã§ç ´ããããã¯èª¤å ± å æãç¡ç·LANã®WPA-TKIPã1å以å ã«ç ´ãããã¨ããå ±éãããã話é¡ã¨ãªã£ãã ç¡ç·LANã®WPAããããæ°ç§ããæ°åç§ã§çªç ´ããæ°ããæ»ææ¹æ³ãç»å ´ãæ©æã«WPA2ã«ç§»è¡ããå¿ è¦ãã, Gigazine, 2009å¹´8æ5æ¥ ä»åã®æ¹æ³ã¯æ¨å¹´11æã«çºè¡¨ããããTews-Beckæ»æãï¼ç¥ï¼ãQoSå¶å¾¡ãå©ç¨ããæ©å¨ã«éå®ããããã®ã§ãããéµã®å°åºã«15åãã®æéãå¿ è¦ã§ãã£ãã®ã«å¯¾ãã¦ããããæ°ç§ããæ°åç§ã§å°åºãã¦ãã¾ããã¨ãã§ããã¨ãããã®ãï¼ç¥ï¼ ä»åçºè¡¨ãããæ¹æ³ã§ã¯ãTKIPã«ãããå®æçã«å¤æ´ãããéµã«ã¤ãã¦ãTKIPã®ãããã³ã«ã®æ°ããªèå¼±æ§ãå©ç¨ãã¦æ¥µãã¦çæéï¼æ°ç§ããæ°åç§ï¼ã§å°åºãããã®éµãå¹çããå©ç¨ããæ¹æ³ã¨ãã¦æ°ããªä¸éè æ»æãéçºããã¨ã®ãã¨ã ç¡ç·LANã»ãã¥ãªãã£ãWPAããããã1å以å ã§ç ´ãæ
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}