#LTé§å 29ã§ã®çºè¡¨ã¹ã©ã¤ã
æè¿ãç§ã¯ãã»ãã·ã§ã³ãã¼ã¯ã³ããcookieã®ä»£ããã« Web Storage (sessionStorage/localStorage)ã«ä¿åããã®ã¯å®å ¨ã§ããï¼ãã¨ãããã¨ãå°ãããã¾ããããã®ãã¨ã«ã¤ãã¦Googleã§æ¤ç´¢ããã¨ãããæ¤ç´¢çµæã®ä¸ä½ã®ã»ã¨ãã©ããWeb storageã¯cookieã«æ¯ã¹ã¦ããªãã»ãã¥ãªãã£ãå¼±ããã»ãã·ã§ã³ãã¼ã¯ã³ã«ã¯ä¸åãã§ãããã¨æè¨ãã¦ãã¾ãããéææ§ã®ãããç§ã¯ãã®éã®çµè«ã«è³ã£ãçè«çæ ¹æ ãå ¬ã«æ¸ããã¨ã«ãã¾ããã Web Storageã«é¢ããè°è«ã®ä¸æ ¸ã¨ãã¦è¨ãããã®ã¯ããWeb Storageã¯secureãã©ã°ãHttpOnlyãã©ã°ã¨ãã£ãcookieç¹æã®æ©è½ããµãã¼ããã¦ããªããããæ»æè ã容æã«çã¿åããã¨ãå¯è½ãã¨ãããã®ã§ããpathå±æ§ã«ã¤ãã¦ãè¨åããã¾ããç§ã¯ããããã®æ©è½ããããã«ã¤ãã¦èª¿ã¹ã¦ã¿ã¾ãããããã¦ã
ãã¸ã¿ã«å¸æ°æ¨©å£ä½ã®é»åããã³ãã£ã¢è²¡å£ï¼EFFï¼ã¯11æ20æ¥ï¼ç¾å°æéï¼ãç±³ITä¼æ¥å¤§æã®ãµã¼ãã¹ã®æå·åç¶æ³ãä¸è¦§ã§ãããªã¹ããå ¬éããã ç±³å½å®¶å®å ¨ä¿éå±ï¼NSAï¼ã«ãã大æITä¼æ¥ã®ã¦ã¼ã¶ã¼ãã¼ã¿ã¸ã®ç¡æã¢ã¯ã»ã¹ãå ±ããããä¸ãä¼æ¥ãã¦ã¼ã¶ã¼ãå®ãããã«ã©ã®ãããªå¯¾çãã¨ã£ã¦ãããã確èªãããã¨ãç®çã ãªã¹ãã®é ç®ã¯ãå·¦ãããã¼ã¿ã»ã³ã¿ã¼éã®ãªã³ã¯ãHTTPSã®ãµãã¼ããHTTP Strict Transport Securityï¼HSTSï¼ã®ãµãã¼ããforward secrecyï¼PFSã¨ãå¼ã°ããï¼ã®æ¡ç¨ãSTARTTLSã®ãµãã¼ãã ç¾æç¹ã§ãã¹ã¦å¯¾å¿ãã¦ããã®ã¯GoogleãDropboxãDropboxã®ç«¶åã®SpiderOakãããã¼ããã³ãISPã®Sonic.netã®4社ã®ã¿ãVerizonã¨AT&Tã¨ããç±³éä¿¡ãã£ãªã¢1ä½ã¨2ä½ã¯ãããã対å¿ç¶æ³ãæããã«ãã¦
Webã¢ããªã±ã¼ã·ã§ã³ã«ããã¦JSONãç¨ãã¦ãã©ã¦ã¶ - ãµã¼ãéã§ãã¼ã¿ã®ããåããè¡ããã¨ã¯ãã¯ãæ®éã®ãã¨ã§ããããã®ã¨ãJSONå ã«ç¬¬ä¸è ã«æ¼ãã¦ã¯å°ãæ©å¯æ å ±ãå«ã¾ããå ´åã¯ãå¿ ã X-Content-Type-Options: nosniff ã¬ã¹ãã³ã¹ããããã¤ããããã«ãã¾ããã(ãããæ©å¯æ å ±ãã©ããã«é¢ããããå ¨ã¦ã®ã³ã³ãã³ãã«ã¤ããã»ãããããé¢é£:X-Content-Type-Options: nosniff ã¤ãããªããã¤ã¯æ»ãã°ããã®ã«! - èã£ã±æ¥è¨)ã ä¾ãã°ãæ©å¯æ å ±ãå«ã以ä¸ã®ãããªJSONé åãè¿ããªã½ã¼ã¹(http://example.jp/target.json)ããã£ãã¨ãã¾ãã [ "secret", "data", "is", "here" ] æ»æè ã¯ç½ ãã¼ã¸ãä½æãã以ä¸ã®ããã«JSONé åãvbscriptã¨ãã¦èªã¿è¾¼ã¿ã¾ãããã¡ã
DNSãµã¼ãã¼ã®ä¸é©åãªè¨å®ã§ããããªã¼ãã³ãªã¾ã«ãã¼ãã¯ããDNS Reflector Attacksï¼DNSãªãã¬ã¯ã¿ã¼æ»æï¼ãã¨ããåæ£ãµã¼ãã¹ä¸è½ï¼DDoSï¼æ»æã«æªç¨ãããæãããããJPRSã§ã¯ããã¾ã§ãåæã§ã®æ å ±æä¾ã注æåèµ·ãè¡ã£ã¦ãã¦ãã¾ãã 2013å¹´3æãæµ·å¤ã§å¤§è¦æ¨¡ãªæ»æäºä¾ããããä¸é¨å°åã«ããã¦ã¤ã³ã¿ã¼ããããä¸æçã«å©ç¨ãã«ãããªããªã©ã®é害ãçºçãã¾ãããJPRSã§ã¯ããã®åé¡ã«é¢ããæè¡è§£èª¬ãDNSãµã¼ãã¼ã®é©åãªè¨å®æ¹æ³ã«ã¤ãã¦ãæ¹ãã¦ä»¥ä¸ã®éãã¾ã¨ããå ¬éãã¾ããã èªèº«ã®ç®¡çããDNSãµã¼ãã¼ããªã¼ãã³ãªã¾ã«ãã¼ã§ããã¨ãDDoSæ»æã®å 害è ãè¸ã¿å°ã¨ãªãæããããã¾ããDNSãµã¼ãã¼ç®¡çè ãé¢ä¿è ã®çãã¾ã¯ã確èªããé¡ããã¾ãã
åããã¦èªãã§ãã ããï¼Flashã¨ç¹å®ãã©ã¦ã¶ã®çµã¿åããã§cross originã§ã«ã¹ã¿ã ãããä»ä¸ãåºæ¥ã¦ãã¾ãåé¡ãæªã ã«ç´ã£ã¦ããªã話 (2014-02/07) XMLHttpRequestã使ããã¨ã§ãCookieããªãã¡ã©ãhiddenå ã®ãã¼ã¯ã³ã使ç¨ããã«ã·ã³ãã«ã«CSRF対çãè¡ãããPOSTããJavaScriptã¯ä»¥ä¸ã®éãã(2013/03/04:ã³ã¼ãä¸é¨ä¿®æ£) function post(){ var s = "mail=" + encodeURIComponent( document.getElementById("mail").value ) + "&msg=" + encodeURIComponent( document.getElementById("msg").value ); var xhr = new XMLHttpRequest(); xhr
æè¡è ã¨ãã¦ã®è¯å¿ã«å¾ã£ã¦ãã®è¨äºãæ¸ãã¾ãã俺ã¯ã»ãã¥ãªãã£ã¨ãã©ã¤ãã·ã¼ã®äººã§ã¯ãªããJavaScriptã¨UIã®äººã§ãããæ³å¾ã®åå¼·ã ã£ã¦èªåã®çæ´»ã¨æ¥åã«é¢ããã®ããç¯å²ã§ããããªãã ããããããå°ãªãã¨ãJavaScriptããã©ã¦ã¶ã絡ããããªé¨åã«ã¤ãã¦ã¯ã確å®ã«èªåã®ã»ããç解ãã¦ããã¨æã£ã¦ãããé«æ¨æµ©å ããããããããã¾ã«ééã£ããã¨ãæ¸ããããããããªãã¨ãæ¸ãã¦ããããã¦ããå¾ã ã«èª°ãææããªããªã£ã¦ããã¨æããããããªãã¨æ¸ãã¦ããã¨ãã¦ããéæè¡è ããè¦ãã¨ãã«ãå¤å°éæ¿ãªç©è¨ãã ãã©ããã®äººã¯å°é家ã ããè¨ã£ã¦ãããã¨ã¯æ£è«ãªã®ã ãããã¨ãããããã¯æè¡è ããè¦ãæã§ããå°éåéãéãã°ééã£ããã¨ãæ¸ããã¦ãã¦ãæ°ä»ããªãã¨ãããã¨ãããã ããã ããèªåã«ã¯åãããªããªã£ã¦ããã誰ã«ã§ãæ¤è¨¼ã§ãããããªäºå®é¢ä¿ã®ééãããããã¯ãæè¡çãªééããå«ã¾ãã¦ã
ããã¡ãã£ã¨ããºãããããªãããªãã Kampa! ã®äººã§ããä½ç°ãããè¦ã¤ãã¦æãã¦ããããã ãã©ã Facebook ã®ã¡ãã»ã¼ã¸ã¯å²ã¨ç°¡åã«ä»äººã«ãªããã¾ãã¦éããã¿ããã 以ä¸ããã¹ã¦éä¿¡è ã¨åä¿¡è ã®èªçºçãªååãå¾ã¦è©¦ãã¦ã¿ãçµæã§ãã èµ·ããã㨠Facebook ã§ã¯ã¦ã¼ã¶ã¼ã« @facebook.com ã®ã¡ã¼ã«ã¢ãã¬ã¹ãä¸ãããã¦ãã¾ãã å人ãã¼ã¸ã www.facebook.com/namaewo ã®äººãªã [email protected] ã¨ããå ·åã«ã ãã®ã¢ãã¬ã¹å®ã«ã¡ã¼ã«ãéãã¨ã ã¢ãã¬ã¹ã®ææè ã« Facebook ä¸ã®ã¡ãã»ã¼ã¸ã¨ãã¦å±ãã¾ããã ãã®æããã®ã¡ã¼ã«ã®éä¿¡å ã¡ã¼ã«ã¢ãã¬ã¹ã å¥ã® Facebook ã¦ã¼ã¶ã¼ã«ãã£ã¦ç»é²ããã¦ããã¢ãã¬ã¹ã§ãã£ãå ´å Facebook ã§ã¯ããã®ã¦ã¼ã¶ã¼ããéãããã¡ãã»ã¼ã¸ã¨ãã¦æ±ããã¾ãã é»å
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}