LinuxãUNIXç³»OSã«ããã¦ãä¸è¬ã¦ã¼ã¶ã¼ãä¸æ£ã«ç¹æ¨©ãå¾ããã¨ãã§ãããStack Guard Page Circumventionãã¨å¼ã°ããæ»æææ³ãçºè¦ãããï¼Red Hat Customer Portalï¼ãLinuxã«ã¼ãã«ãglibcãsudoãªã©ã®èå¼±æ§ãå©ç¨ãããã®ã§ãå¹ åºãå½±é¿ãåºãããã ã ãã¼ã¹ã¨ãªã£ã¦ããã®ã¯ãã¹ã¿ãã¯é åã«å¤éã®ã¡ã¢ãªå²ãå½ã¦ã¨ãã¼ã¿æ¸ãè¾¼ã¿ãè¡ã£ã¦ã¹ã¿ãã¯é åã溢ãããããã¨ã§ããã¼ãé åã®ãã¼ã¿ãä¸æ£ã«æ¸ãæãããããã¨ãããã¨ããåé¡ãRed Hatã«ããã¨ãé¢é£ããèå¼±æ§ã¯CVE-2017-1000364ï¼Linuxã«ã¼ãã«ã®stack guard pageã®èå¼±æ§ï¼ãCVE-2017-1000366ï¼glibcã§LD_LIBRARY_PATHã®å¤ã«ç´°å·¥ããããã¨ã§ãã¼ã/ã¹ã¿ãã¯ã®å¤ãæä½ã§ããèå¼±æ§ï¼ãCVE-2017-1000
å¤é¨ããç°¡åã«HTTP_PROXYã¨ããç°å¢å¤æ°ãã»ããã§ãããµã¼ãééä¿¡ãå¤é¨ãµã¤ãã¨é£æºãã¦ããå ´åã«å½±é¿ããããããããªãèå¼±æ§ã§ãã(HTTPoxy. CVE-2016-5385) PHPã®å ´åã¯php-fpm, mod_php, Guzzle4以ä¸ãããã¤ãã®ã©ã¤ãã©ãªã§å½±é¿ããã¾ãã 対å¿æ¹æ³ã¯ç°¡åã§ãã Apacheå´ã§å¯¾å¿ããå ´åã¯ãmod_headerã使ããç¶æ³ã§ããã°ãconfãã¡ã¤ã«ã«ä¸è¨ã®1è¡ã追å ã RequestHeader unset Proxy FastCGIã®å ´åã¯ä¸è¨ã®1è¡ã追å ã fastcgi_param HTTP_PROXY ""; Guzzleã¯6.2.1ã§å¯¾å¿ãããããã§ãã Release 6.2.1 release · guzzle/guzzle · GitHub ã³ããããã°ãè¦ãã¨ãCLIã®æã®ã¿ãgetenv('HTTP_PROXY
404 NOT FOUND æå®ããããã¼ã¸ãè¦ã¤ããã¾ããã æ²è¼ããä¸å®ã®æ¥æ°ãçµéããè¨äºã¯ã é 信社ã¨ã®å¥ç´ã«åºã¥ãåé¤ãããå ´åããããã¾ãã ï¼ãã®å ´åãä¸å®æéçµéå¾ã¯è¨äºãè¦ããã¨ãåºæ¥ã¾ãããï¼ ãã以å¤ã®ã±ã¼ã¹ã«ã¤ãã¦ã¯ããææ°ã§ãã 以ä¸ã®ããããã®æ¹æ³ã§ãã¼ã¸ããæ¢ããã ããã ãã©ã¦ã¶ã®åèªã¿è¾¼ã¿ãè¡ã å ¥åããURLï¼ãã¼ã¸ã¢ãã¬ã¹ï¼ã«ã¿ã¤ããã¹ããªãã確èªãã ãã©ã¦ã¶ã®ãæ»ãããã¿ã³ãæ¼ãã¦åç»é¢ããããç´ã
â»(2014/10/1 追è¨) èå¼±æ§ã®çªå·ã誤ã£ã¦ CVE-2014-6721 ã¨è¡¨è¨ãã¦ãã¾ã£ã¦ãã¾ãã æ£ãã㯠"CVE-2014-6271" ã§ã 失礼è´ãã¾ãã â»(2014/10/7 追è¨) 2014/10/7 14:00æç¹ã§ Shell Shock ã¸ã®ä¿®æ£ãããã¯6å å ¬éããã¦ãã¾ã æ¢ã«å¯¾å¿æ¸ã¿ã®ã·ã¹ãã ã§ããããã®æ¼ãããªãã注æãã¦ãã ãã ã·ã§ã«ã«èå¼±æ§ãè¦ã¤ãã£ããããã§ã ãã®ã³ãã³ããå®è¡ããã¨èå¼±æ§ããããã¼ã¸ã§ã³ãã®ãã§ãã¯ãã§ããããã§ã $ env x='() { :;}; echo vulnerable' bash -c "echo this is a test" 以ä¸ã®ããã«è¡¨ç¤ºããããã¢ã¦ãã§ã vulnerable this is a test ã©ãããããã®ã³ãã³ããæ£å¸¸ã«å®è¡ã§ããã¨ããã®ããã®èå¼±æ§ã®æ£ä½ãããã echo vuln
SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ããªãæåã«ãªãã¾ãããããªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ã¾ã ãã¾ãèããªãã®ã§ãã¾ã¨ãã¦ããã¾ãã Dependency Injectionï¼DIï¼ã¨ã¯é¢ä¿ããã¾ããã ãªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³èå¼±æ§ã¨ã¯ï¼ SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãå¤é¨ããSQLæãæ³¨å ¥ããæ»æã§ããã®ã¨åãããã«ããªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ã¯å¤é¨ãããªãã¸ã§ã¯ããæ³¨å ¥ããæ»æã§ãã å¤é¨ãããªãã¸ã§ã¯ããæ³¨å ¥ã§ããã°ããã®ãªãã¸ã§ã¯ãã®æ©è½ã«ãããã¾ãã¾ãªæ»æãã§ããå¯è½æ§ãããã¾ããææªã®å ´åãä»»æã®ã³ã¼ããå®è¡ã§ããèå¼±æ§ã«ãªãã¾ãã PHPã®å ´åããã®æ»æãå¯è½ãªã®ã¯ãunserialize()é¢æ°ãæªç¨ã§ããå ´åã§ãã æ»æã®æ¹æ³ unserialize()é¢æ°ã«å¤é¨ããä»»æã®ãã¼ã¿ã渡ãã³ã¼ãããã£ãå ´åãæ»æè ã¯èªç±ã«ã·ãªã¢ã©ã¤ãºããããã¼ã¿ãéä¿¡ãããã¨ã§ãçæããããªãã¸ã§
WEBç³»ã®æ å ±ã»ãã¥ãªãã£é¢é£ã®å¦ç¿ã¡ã¢ã§ããã¡ã¢ãªã®ã§ä»æ å ±ã®ãã¤ã³ã¿ã ããã¨ãã®åæ¯ãªè¨äºãããã¾ãã â»2020.9 注è¨:æ¬ããã°ã®è§£èª¬è¨äºã¯å 容ãå¤ããªã£ã¦ããã¾ããOWASP ZAPãªã©ã®ã½ããã¦ã§ã¢ã®è§£èª¬ã¯ç¾è¡ãã¼ã¸ã§ã³ã®ä»æ§ããä¹é¢ãã¦ããå¯è½æ§ãããã¾ãã EC-CUBEã§èå¼±æ§ãè¦ã¤ããããmixiã®èå¼±æ§å ±åå¶åº¦ã§ææãæããããããããããã©ããã£ã¦èå¼±æ§ãè¦ã¤ãã¦ããã§ããï¼ãã¨ãã質åãããããã¨ãææãããä¸å¿æé ã¯èª¬æããã®ã§ããããã¤ãå£é ã§ç´°ããã¯èª¬æã§ããªãã¦ç³ã訳ãªãã®ã§ãèªåã®ããæ¹ãã¾ã¨ãã¦ãã®ããã°ã«ã¢ãããã¦ããã¾ãã æ¨æºçãªèå¼±æ§æ¤æ»ã®ããæ¹ãã説æãã¦ããªãã®ã§ãèå¼±æ§æ¤æ»ã®ããæ¹ãæ¢ã«ææ¡ãã¦ãã人ãèªãã§ãå¾ããã®ã¯å°ãªãã®ã§ã¯ãªããã¨æãã¾ããä»åã¯èå¼±æ§æ¤æ»ã«èå³ããããä½ãã©ãããããããåãããªããããªåå¿è åãã³ã³ãã³ãã§
ãã®èå¼±æ§ãæªç¨ããã¨ãã¢ããªã®ã³ã¼ããæ¹ããããæ£è¦ã®ã¢ããªããã«ã¦ã§ã¢ã«å¤ãããã¨ãã§ãã¦ãã¾ãã¨ããã ã¢ãã¤ã«ã»ãã¥ãªãã£æ°èä¼æ¥ã®ç±³Bluebox Securityã¯7æ3æ¥ãAndroidã®ã»ãã¥ãªãã£ã¢ãã«ã«èå¼±æ§ãè¦ã¤ãã£ãã¨çºè¡¨ãããæ£è¦ã®ã¢ããªã±ã¼ã·ã§ã³ããã«ã¦ã§ã¢ã«æ¹ãããããæããããã¨ããã99ï¼ ã®ç«¯æ«ãå½±é¿ãåããã¨ãã¦ããã å社ã®ããã°ã«ããã¨ãå ¨ã¦ã®Androidã¢ããªã«ã¯ããã®ã¢ããªãæ£è¦ã®ãã®ã§ãããã¨ã確èªããããã«æå·åç½²åã使ããã¦ããã ããããä»åè¦ã¤ãã£ãèå¼±æ§ãæªç¨ããã¨ããã®æå·åç½²åãç ´ããã¨ãªãAndroidã¢ããªã±ã¼ã·ã§ã³ããã±ã¼ã¸ï¼APKï¼ã®ã³ã¼ããæ¹ããããæ£è¦ã®ã¢ããªããã«ã¦ã§ã¢ã«å¤ãããã¨ãã§ãã¦ãã¾ãã¨ããããããããã®æ¹ããã¯ã¢ããªã¹ãã¢ã«ãã端æ«ã«ããã¨ã³ãã¦ã¼ã¶ã¼ã«ãæ°ã¥ããããã¨ã¯ãªãã¨ãã¦ããã ã¢ããªã®ç¨®é¡ã«
æ¢ã«æ»æã³ã¼ããåºåããã»ãã¥ãªãã£å°é家ã¯IEã®ã¦ã¼ã¶ã¼ã«å¯¾ããMicrosoftããã®åé¡ã«å¯¾å¦ããã¾ã§ã®éãChromeãFirefoxãªã©å¥ã®Webãã©ã¦ã¶ã«åãæ¿ãããã¨ãå§ãã¦ããã ç±³Microsoftã®Internet Explorerï¼IEï¼ã«ãã¾ãæ°ããªæªè§£æ±ºã®èå¼±æ§ãå ±åããããIE 7ã¨8ãæ¨çã¨ããæ»æãæ¢ã«çºçãã¦ãããããã ãç±³SANS Internet Storm Centerãã»ãã¥ãªãã£ä¼æ¥å社ã9æ17æ¥ã«ä¸æã«ä¼ããã IEã®èå¼±æ§ãæªç¨ããã³ã¼ãã¯ãå ã«çºè¦ããJavaã®èå¼±æ§ï¼Oracleã8æ30æ¥ã«å¯¾å¦æ¸ã¿ï¼ã«ã¤ãã¦èª¿ã¹ã¦ããç 究è ã14æ¥ã«çºè¦ããææ°ã®ããããå½ã¦ãWindows XP SP3ä¸ã§æªç¨ã§ãããã¨ã確èªããã ãã®èå¼±æ§ã¯IE 7ï¼8ï¼9ã«åå¨ããç´°å·¥ãæ½ããWebãµã¤ããã¦ã¼ã¶ã¼ãè¦ãã ãã§è¢«å®³ã«éãå¯è½æ§ãããã¨ãããM
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼ã¯ã Cè¨èªã§ä½æãããã½ã¼ã¹ã³ã¼ãã«èå¼±æ§ãåå¨ããªããã©ãããæ¤æ»ãããã¼ã«ãiCodeCheckerããå ¬éãã¾ãããç¡åã§å©ç¨ã§ãã¾ãã iCodeCheckerã¯ãã½ã¼ã¹ã³ã¼ãã®èå¼±æ§ãåå¨ããç®æãæ¤åºããä¿®æ£ä¾ãèå¼±æ§ãæªç¨ãããå ´åã®è å¨ã«ã¤ãã¦ã®ã¬ãã¼ããåºåãããã¼ã«ããã¬ã¹ãªãªã¼ã¹ããå¼ç¨ãã¾ãã æ¬ãã¼ã«ã¯ãèå¼±æ§ãã½ã¼ã¹ã³ã¼ãæ¤æ»æè¡ãå¦ç¿ãããå¦çãéçºè ã対象ã«ãå©ç¨è èªèº«ãä½æããã½ã¼ã¹ã³ã¼ãï¼Cè¨èªï¼ãæ¤æ»ãããã¨ã§ãã¾ãã æ¬ãã¼ã«ã§ã¯ãã½ã¼ã¹ã³ã¼ãã®èå¼±æ§ãåå¨ããç®æãæ¤åºããä¿®æ£ä¾ãèå¼±æ§ãæªç¨ãããå ´åã®è å¨ã«ã¤ãã¦è§£æããã¬ãã¼ããåºåãã¾ããå©ç¨è ã¯æ¬ãã¼ã«ãéãã¦ãèå¼±æ§ãå¦ç¿ããã¨ã¨ãã«ãã½ã¼ã¹ã³ã¼ãã»ãã¥ãªãã£æ¤æ»æè¡ã®æå¹çãªæ´»ç¨æ¹æ³ãç¿å¾ãããã¨ãã§ãã¾ãã é å¸å½¢å¼ã¯ãVMã¤ã¡ã¼ã¸ãããã±ã¼ã¸
PHPã«æ°ããªèå¼±æ§ãè¦ã¤ãã£ã¦ãCGIã¢ã¼ãã§åä½ããPHPã®å ´åã³ãã³ãã©ã¤ã³å¼æ°ãHTTPçµç±ã§æ¸¡ãã¦ãã¾ãããã-sãªãã·ã§ã³ã渡ãã¨PHPã®ã½ã¼ã¹ã³ã¼ãã丸è¦ãã«ãªãã¨ããã®ã話é¡ã«ãªã£ã¦ã¾ãã(-sãªãã·ã§ã³ã¯htmlã§ã·ã³ã¿ãã¯ã¹ãã¤ã©ã¤ãã¾ã§ãã¦ããã¦ã³ã¼ããè¦ããããªã) ããã§Facebookã«åãã¦ããã試ãã¦ã¿ãã¨ã»ã»ã» https://www.facebook.com/?-s ãããªæ å ±ãï¼ï¼ <?php include_once 'https://www.facebook.com/careers/department?dept=engineering&req=a2KA0000000Lt8LMAS'; ãã®URLã«ã¢ã¯ã»ã¹ããã¨ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®æ±äººæ å ±ãã¼ã¸ã«è¡ãã¾ã :) ããããã¼
ãã®ã¨ã³ããªã§ã¯ãããPHPã®å ¥éæ¸ãé¡æã¨ãã¦ãAjaxã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã«ã¤ãã¦æ¤è¨ãã¾ããå ¨3åã¨ãªãäºå®ã§ãã ãã®ã¨ã³ããªãæ¸ãããã£ãã twitterããã¿ã¬ã³ããã¡ããã ããã¦ãä½ããªããåºç¤ããå¦ã¶PHPã«ããWebã¢ããªã±ã¼ã·ã§ã³å ¥éXAMPP/jQuery/HTML5ã§ä½ãã¤ãããã®Weã¨ããæ¬ãèªã¿ã¾ãããææã¯ä»¥ä¸ã®éãã§ãã ã¿ã¬ã³ãæ°ã®ä¸»å¼µã®ããã«ãæ¬æ¸ã¯ã»ãã¥ãªãã£ãä¸åèæ ®ãã¦ããªã 主ãªèå¼±æ§ã¯ãXSSãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãä»»æã®ãµã¼ãã¼ãµã¤ãã»ã¹ã¯ãªããå®è¡ï¼ã¢ãããã¼ãçµç±ï¼ãã¡ã¼ã«ãããã¤ã³ã¸ã§ã¯ã·ã§ã³ç èå¼±æ§ä»¥åã®åé¡ã¨ãã¦ãµã³ãã«ã¹ã¯ãªããã®å質ãä½ãããããã°ããªãã¨åããªãã¹ã¯ãªãããå¤æ°ãã£ã ä¸è¨ã«é¢é£ãã¦ãæµç¨å ã®ã½ã¼ã¹ããããã°ç¨ã®alertãªã©ãã³ã¡ã³ãã¨ãã¦æ®ã£ã¦ãã¦çã ãã ä»æãã®æ°´æºã¯ãªããã¼ã¨æãã¾ããã以å
Microsoftã®èå¼±æ§ç 究ï¼Microsoft Vulnerability Researchï¼MSVRï¼ãã¼ã ã¯ã2010å¹´7æ以æ¥åè¨38社ã®ãã³ãã¼ã«å½±é¿ãåã¼ã109種é¡ã®ã½ããã¦ã§ã¢èå¼±æ§ãç¹å®ãã¦ããã Microsoftã®ç 究è ã¯ãAppleã¨Googleãå«ããµã¼ããã¼ãã£ã¼ã®ãã³ãã¼ã®è£½åã«ãããã»ãã¥ãªãã£èå¼±æ§ãå¯ãã«çºè¦ãã修復ã«åã貸ãã¦ããã 8æã ãã§ããMSVRãã¼ã ã¯ãWordPressãã¨Appleã®ãSafariããã©ã¦ã¶ã®ææ¸ã®èå¼±æ§ã«ã¤ãã¦ãã¢ããã¤ã¶ãªããªãªã¼ã¹ãã¦ããã7æã«ã¯Googleã®ãPicasaãã¨Facebookã®ã»ãã¥ãªãã£èå¼±æ§ãçºè¦ããã修復ãããã 2008å¹´ã«ãã¼ã³ããããMSVRããã°ã©ã ã«ãã£ã¦ãMicrosoftã®ç 究è ã¯ãµã¼ããã¼ãã£ã¼è£½ã½ããã¦ã§ã¢ã®ã³ã¼ããç£æ»ãããããã®åé¡ãå ¬éããã¦ãã¾ãåã«ä¿®å¾©ã§ããã
æ¨æ¥ã®ããã°ã¨ã³ããªãPHP5.3.7ã®crypté¢æ°ã«è´å½çãªèå¼±æ§(Bug #55439)ãã«ã¦ãcrypté¢æ°ã®é大ãªèå¼±æ§ã«ã¤ãã¦å ±åãã¾ãããèå¼±æ§ã®åºæ¹ãè¿å¹´ã¾ãã«è¦ãã»ã©ã®ãã®ã ã£ãã®ã§ãtwitterããã¯ããªã©ãè¦ã¦ãããã©ããã¦ãããªã£ããã¨ããçåãå¤æ°ç®ã«ãã¾ããã ããã§ããã®ã¨ã³ããªã§ã¯ããã®èå¼±æ§ãã©ã®ããã«æ··å ¥ããã®ãã追ã£ã¦ã¿ããã¨æãã¾ãã PHPã®ã¬ãã¸ããªã®ãã°ãå ¬éããã¦ããã½ã¼ã¹ã®ç¶æ³ãããPHP5.3.7RC4ã¾ã§ãã®ãã°ã¯ãªããPHP5.3.7RC5ã§ãã®ãã°ãæ··å ¥ãã模æ§ã§ããRC5ã¯PHP5.3.7æå¾ã®Release Candidateã§ããããã¾ãã«æ£å¼ãªãªã¼ã¹ã®ç´åã§ãã°ãå ¥ã£ããã¨ã«ãªãã¾ãã ãã°ã®å ¥ãç´åã®ã½ã¼ã¹ã¯ãããã®é¢æ°php_md5_crypt_rããåç §ãããã¨ãã§ãã¾ãã以ä¸ã«ãããã¾ããªæµããå³ç¤ºãã¾ããã¾ãã¯ã
PHP5.3.7ã®crypté¢æ°ã«ã¯è´å½çãªèå¼±æ§ãããã¾ããææªã®ã±ã¼ã¹ã§ã¯ãä»»æã®ãã¹ã¯ã¼ãã§ãã°ã¤ã³ã§ãã¦ãã¾ãã¨ããäºæ ãçºçãã¾ãã該å½ããå©ç¨è ã¯ãè³æ¥ãå¾è¿°ããåé¿çãå®æ½ãããã¨ãæ¨å¥¨ãã¾ãã æ¦è¦ PHPã®crypté¢æ°ã¯ãã½ã«ãä»ãããã·ã¥å¤ãç°¡åã«æ±ãããã¨ãã§ãã¾ãï¼å ¬å¼ãªãã¡ã¬ã³ã¹ï¼ãcrypté¢æ°ã®ããã·ã¥ã¢ã«ã´ãªãºã ã¨ãã¦MD5ãæå®ããå ´åãã½ã«ãã®ã¿ãåºåãããããã·ã¥å¤ã空ã«ãªãã¾ããããã¯ãcrypté¢æ°ã®çµæãã½ã«ãã®ã¿ã«ä¾åãããã¹ã¯ã¼ãã«ã¯å½±é¿ãããªããã¨ãæå³ããcrypté¢æ°ãèªè¨¼ã«ç¨ãã¦ããå ´åãä»»æã®ãã¹ã¯ã¼ãã§ãã°ã¤ã³ã«æåããå¯è½æ§ãããã¾ãã å½±é¿ãåããã¢ããªã±ã¼ã·ã§ã³ crypté¢æ°ãç¨ããããã·ã¥ã¢ã«ã´ãªãºã ã¨ãã¦MD5ãæå®ãã¦ããã¢ããªã±ã¼ã·ã§ã³ã ç°å¢ã«ãä¾åãã¾ãããããã©ã«ããMD5ã®å ´åãããã¾ããçè ã®ãã¹ãç°å¢
æè¿åãçºè¦ããä¿®æ£ãããTwitterã®èå¼±æ§ã3ã¤ç´¹ä»ãã¾ãã 1.æ§Twitterã®æååå¦çã«çµ¡ãã XSS å»å¹´ã®å¤ãããã«ãTwitter Webä¸ã§ € ã ÿ ã®æååç §ãå«ã¾ãããã¤ã¼ããXMLHttpRequestã§èªã¿è¾¼ãã éã«è¡¨ç¤ºãä¹±ããã¨ããåé¡ã«æ°ä»ã*1ããã®æã¯ããã¯èå¼±æ§ã«ã¯ç¹ãããªãã ããã¨ããå¤æãããã®ã ãã©ãä»å¹´ã®4æã«ãªã£ã¦æ¹ãã¦èª¿ã¹ãã¨ãã貫éãã¾ããã 表示ãä¹±ããã¨ããã®ã¯ã€ ã ÿ ã®æååç §ãå«ã¾ãããã¤ã¼ããããã¨ãä¸é¨ã®æåã\XXXXã®å½¢å¼ã«åãããããã¤ã¼ãå¨è¾ºã®ã"ããã\"ãã«ãªã£ãããããã®ã ã£ãã®ã§ãããä»åã¯ã"ããã\"ãã«ãªãç¹ãèå¼±æ§ãçºçããã¦ãã¾ããã ãã®æ¡ä»¶ã§XSSããããã¨æã£ããããã¤ã¼ããç´°å·¥ãã¦URLã@ã#ãªã©ãªã¼ããªã³ã¯ãä½æãããé¨åã«ãã¾ããã¨ã¤ãã³
ã¤ã¿ãªã¢ã®ã»ãã¥ãªãã£ç 究è ããInternet Explorerãï¼IEï¼ã®èå¼±æ§ãçºè¦ããããããæªç¨ãããã¨ãPCããã¯ããã¼ãçã¿åºããããã¹ã¯ã¼ãã®ããã£ãã¦ã§ããµã¤ãã«ãã°ã¤ã³ãããããããããã¨ããã Rosario Valottaæ°ã¯ãcookiejackingãã¨ããã¨ã¯ã¹ããã¤ãã«ã¤ãã¦ããã¹ã¦ã®Windowsä¸ã®å ¨ãã¼ã¸ã§ã³ã®IEã«ã¼ããã¤æ»æã®èå¼±æ§ãè¦ã¤ãã£ã¦ãããã¦ã§ããµã¤ããåããã©ããªã¯ããã¼ãæ»æè ã«ãã¤ã¸ã£ãã¯ãããããããããã¨è¿°ã¹ã¦ããã Valottaæ°ã¯ãã®5æã«ããªã©ã³ãã®ã¢ã ã¹ãã«ãã ãã¹ã¤ã¹ã®ã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ã§ãã¢ãè¡ã£ããã¯ããã¼ãçã¿åºãã«ã¯ã¦ã¼ã¶ã¼ã«PCä¸ã§ãªãã¸ã§ã¯ãããã©ãã°ã¢ã³ããããããããå¿ è¦ããããã¨ãããèå¼±æ§ã®æªç¨ã«ã¯ã½ã¼ã·ã£ã«ã¨ã³ã¸ãã¢ãªã³ã°ãå°ãå¿ è¦ã ã¨åæ°ã¯èªãã¦ããã ãããReutersã®è¨äºã«ãã
以ä¸ã¯ãWEBããã°ã©ãã¼ç¨ã®WEBèå¼±æ§ã®åºç¤ç¥èã®ä¸è¦§ã§ãã WEBããã°ã©ãã¼ã®äººã¯ãããèªãã°WEBèå¼±æ§ã®åºç¤ããã¹ã¿ã¼ãã¦WEBããã°ã©ã ãæ¸ããã¨ãã§ããããã«ãªã£ã¦ããããã§ãã ã¾ããWEBèå¼±æ§ã®ç°¡æãªãã¡ã¬ã³ã¹ã¨ãã¦ãå°ãå©ç¨ã§ããããããã¾ããã WEBã¢ããªã±ã¼ã·ã§ã³ãéçºããã«ã¯ãéçºè¦ä»¶æ¸ãããã°ã©ã ä»æ§æ¸éãã«éçºããã°è¯ãã¨ããããã«ã¯ããã¾ããã ãããWEBèå¼±æ§ãçãæªæã®ã¦ã¼ã¶ã«ã対å¦ããªãã¨ãããªãã®ã§ãã ä»åãWEBã¢ããªã±ã¼ã·ã§ã³ãéçºã«ããã£ã¦ã®WEBèå¼±æ§ãã以ä¸ã®ä¸è¦§ã«ã¾ã¨ãã¦ã¿ã¾ããã ãã®ã¾ã¨ããWEBã¢ããªã±ã¼ã·ã§ã³éçºã®åèã«ãªãã°å¹¸ãã§ãã ã¤ã³ã¸ã§ã¯ã·ã§ã³ ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° ã»ãã·ã§ã³ã»ãã¤ã¸ã£ã㯠ã¢ã¯ã»ã¹å¶å¾¡ãèªå¯å¶å¾¡ã®æ¬ è½ ãã£ã¬ã¯ããªã»ãã©ãã¼ãµã«(Directory Traversal) CSRFï¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}