ããã«ã¡ã¯ãã¤ã³ãã©ãã¼ã ããã¯ãªã¼ãã®æ«»äºã§ãã ä»åã¯Dockerã¨firewalldã使ã£ã¦å é¨ãããã¯ã¼ã¯ã¸ã®ã¢ã¯ã»ã¹ãå¶éããSSRFæ»æãé²ãæ¹æ³ã«ã¤ãã¦ç´¹ä»ãã¾ãã SSRFæ»æã¨ã¯ SSRFï¼Server Side Request Forgeryï¼æ»æã¯Webã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ããæ»æã®ä¸ç¨®ã§ãå ¬éããããµã¼ãã¼ãçµç±ãã¦å ¬éããã¦ããªãå é¨ãããã¯ã¼ã¯ã®ãµã¼ãã¼ã«ã¢ã¯ã»ã¹ããææ³ã§ãã SSRFã®æ¦ç¥å³ å ·ä½ä¾ ä¾ãã°ä»¥ä¸ã®ããã«å¤é¨ããæå®ãããURLã«curlã§ãªã¯ã¨ã¹ããè¡ãããã®çµæãåºåããããã°ã©ã ãããã¨ãã¾ãï¼ãã®ããã°ã©ã ã«ã¯XSSèå¼±æ§ãå«ã¾ãã¦ãã¾ããä»åã¯å²æãã¾ãï¼ã <?php $ch = curl_init(); curl_setopt_array($ch, [ CURLOPT_URL => 'http://' . $_REQUEST['u
{{#tags}}- {{label}}
{{/tags}}