ããã ã.com
HTML5 ã¯ãWHATWG ããã³ W3C ã HTML4 ã«ä»£ãã次ä¸ä»£ã® HTML ã¨ãã¦çå®ãé²ãã¦ããä»æ§ã§ãããHTML5 ããã³ãã®å¨è¾ºæè¡ã®å©ç¨ã«ãããWeb ãµã¤ãé²è¦§è (以ä¸ãã¦ã¼ã¶) ã®ãã©ã¦ã¶å ã§ã®ãã¼ã¿æ ¼ç´ãã¯ã©ã¤ã¢ã³ãã¨ãµã¼ãéã§ã®åæ¹åéä¿¡ãä½ç½®æ å ±ã®åå¾ãªã©ãå¾æ¥ã® HTML4 ãããæè»ãã¤å©ä¾¿æ§ã®é«ã Web ãµã¤ãã®æ§ç¯ãå¯è½ã¨ãªã£ã¦ãã¾ããå©ä¾¿æ§ãåä¸ããä¸æ¹ã§ããããã®æ°æè¡ãæ»æè ã«æªç¨ãããéã«ã¦ã¼ã¶ãåããå½±é¿ã«é¢ãã¦ãååã«æ¤è¨¼ãå¨ç¥ãããã¦ããã¨ã¯è¨ãããã»ãã¥ãªãã£å¯¾çããããªãã¾ã¾æ®åãé²ããã¨ãå±æ§ããã¦ãã¾ãã JPCERT/CCã§ã¯ãHTML5 ãå©ç¨ããå®å ¨ãª Web ã¢ããªã±ã¼ã·ã§ã³éçºã®ããã®æè¡æ¸ãã¬ã¤ãã©ã¤ã³ã®ãã¼ã¹ã¨ãªãä½ç³»çãªè³æã®æä¾ãç®çã¨ãã¦ãæ¸å¿µãããã»ãã¥ãªãã£åé¡ãæ½åºããä¸ã§æ¤è¨ãå ãããããã®åé¡
ã¨ãã¨ãMacã«ãã¦ã¤ã«ã¹ã®è å¨ãæ¼ãå¯ãã¦ããã®ãã»ã»ã» Macçãã®ãã«ã¦ã§ã¢ã55ä¸å°ä»¥ä¸ã®Macã«ææããJavaã®èå¼±æ§çªãæå£ã§çå¨ - ITmedia ãã¥ã¼ã¹ ãã®ä»¶ã®å¯¾çã¯ä»¥ä¸ãåãããããã§ãã 60ä¸å°ä»¥ä¸ãææãã¦ããããã¤ã®æ¨é¦¬ãFlashbackãã«ææãã¦ããã調ã¹ãæ¹æ³ | Macã®ææ¸ã説ææ¸ ã¨ãæ¥ããç§ããã§ãã¯ãã¦å¤§ä¸å¤«ã ã£ãã®ã確èªãã¾ãããã¨ããããããã¨ä¸å®å¿ã ã§ããã®ä»¶ã«ã¤ãã¦ã¨Macã®ã»ãã¥ãªãã£ã«ã¤ãã¦èª¿ã¹ãã¡ã¢ã ãã®ãFlashbackãã«é¢ãã詳細ã¯ä¸è¨è¨äºããããªã³ã¯ããã¦ã以ä¸ã詳ããã§ãã ã¨ãã»ãã¥ã¢ããã° : ï¼Macï¼Flashbackã¯ãããï¼ ãFlashbackãã®ååã®ç±æ¥ããLionããæ¨æºã§ã¤ã³ã¹ãã¼ã«ãããªããªã£ãJavaã®èå¼±æ§ãå©ç¨ããããã¤ã®æ¨é¦¬ã£ã¦ãã¨ã§ãä½ã¨ãè¤éãªæ°æã¡ã«ãªãããã§(^^;;
HTML5 Security Cheatsheetã¯HTML5ã®ã»ãã¥ãªãã£ã«é¢ãããã¼ãã·ã¼ãã§ããåé¡ç¹ã¨å¯¾è±¡Webãã©ã¦ã¶ã対å¦æ³ãä¸è¦§ã«ãªã£ã¦ãã¾ãã HTML5 Security Cheatsheetã¯HTML5ã«ãããã»ãã¥ãªãã£ãã¼ã«ã«ãªãããåé¡ç¹ãã³ã¼ããéãã¦åºãã¦ãããã¨ããããã¸ã§ã¯ãã§ããWebããã°ã©ãå¿ è¦ã¨è¨ããã§ãããã ããããã¼ã¸ã§ããæ§ã ãªé ç®ã並ãã§ãã¾ãã å·¦å´ã¯åã»ãã¥ãªãã£ãã§ãã¯ãã¹ãé ç®ã§ã対象ã«ãªãWebãã©ã¦ã¶ã¨ãã®ãã¼ã¸ã§ã³ã並ãã§ãã¾ããåé¡ç¹ã®æ示ã¨ã¨ãã«ããã®åé¿çã«ã¤ãã¦ãæ¸ããã¦ãã¾ãã®ã§ã¨ã¦ãåèã«ãªãã¾ãã ã¾ã æ¥æ¬èªåããã¦ããªãé¨åãããã¾ãã ã»ã¼å ¨ã¦ã®Webãã©ã¦ã¶ã対象ã«ãªãé¨åãããããã§ãã é ç®ã¯é常ã«å¤ãã§ãããã»ãã¥ãªãã£ãéè¦ããããã«ããã§ãã¯ãã¦ããã¹ãã§ãã HTML5ã§ã¯ããã¾ããIE6ãªã©
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ Webããã°ã©ãã³ã°ãã¦ã¾ããï¼ ãããPHPã¯ã»ãã¥ãªãã£ããã¡ãã¨ãè¨ããã¦ãããã ã§ãããã£ã¦ãã¹ã¤ã«PHPãæªãããããªãã¦ã ãã¶ããã»ãã¥ãªãã£ã¨ãããã¾ã ããããããªã人ãå¤ãã ããªããããªãããªã ããã°ã£ã¦åå¼·ãããã¨æã£ã¦ãããªãã ãé£ããçå±ã並ãã§ãããããããâ¦ã ãªã®ã§ä»æ¥ã¯ãã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦ã ãããã ããã£ã¨ãã°ãããã¨å®å ¨ã«ãªãããã£ã¦ãã¨ããåå¿è ããã«ã大éæã«æ¸ãã¦ã¿ã¾ãï¼ çå±ãããããªãã¦ããæåã¯ã³ããã§ãã ãªã«ããããªãããããã£ãã»ãããã£ã¨ãã·ã«ãªãï¼ 1. XSS対ç åçãªãã®ã表示ããã¨ããå ¨é¨ã¨ã¹ã±ã¼ãããã°okã§ãï¼ (NG) ããªãã®åå㯠<?= $name ?> ã§ããï¼ â (OK) ããªãã®åå㯠<?= htmlspecialchars($name, ENT_QUOTES) ?>
ãã¾ãããªãããGoogle+ ãå©ç¨ããä¸ã§æ³¨æãã¦ãããæ¹ããããªã¼ã¨ãã¯ãæã£ã¦ãããã¨ã«ã¤ãã¦ã¾ã¨ãã¦ã¿ã¾ããããã¼ã¨ãã¢ã©ã«ã¨ãã£ã話ã§ã¯ãªããèªåã®èº«ãå®ãããã®æ³¨æç¹ã§ããããã³ãã§è¨ããªããæ§æªèª¬ã«åºã¥ãï¼ãã§ãã âï¼ï¼"ä¸è¬å ¬é"ã¨"éå®å ¬é"ã«ã¤ã㦠"ä¸è¬å ¬é"ã§æ稿ããã¨ãå³åº§ã« Google ã« Index ãããå ¨ä¸çã®èª°ããè¦ãããç¶æ ã«ãªãã¾ããä¸è¬å ¬é以å¤ï¼"ããªãã®ãµã¼ã¯ã«"ã"åã ã¡ã®åã ã¡ãµã¼ã¯ã«"ãªã©ï¼ã¯å ¨ã¦"éå®å ¬é"ã§ããä¸è¬å ¬éã¨éå®å ¬éã¯å¤§éãã ã¨ãããã¨ãã¾ãèªèãã¦ããã¾ãããã âï¼ï¼"éå®å ¬é"ã®ç¯å²ã«ã¤ã㦠ãã¹ãã®"éå®å ¬é"ã¨æ¸ãã¦ããæãã¯ãªãã¯ããã¨ããã®æ稿ã誰ã«å ¬éããã¦ããããå¤ãããã«ãªã£ã¦ãã¾ãããã ããå®å ¨ã«èª°ããç¹å®ã§ããã®ã¯20人ãããã¾ã§ã§ããã以ä¸ã«ãªãã¨äººæ°ããå¤ãã¾ããã âï¼ï¼"éå®å ¬é"ã®åå ±
ä»ãã³ã³ãã¥ã¼ã¿ã¯ä¸äººä¸å°ã®æ代ãå人æ å ±ã®å®åº«ã§ããããããä»äººã«ç¡æã§ä½¿ãããã®ã¯é¿ãããã§ããããã³ã³ãã¥ã¼ã¿ã«ãã°ã¤ã³ããããã®ãã¹ã¯ã¼ããè¨å®ãããããPreyããªã©ã®ã¢ããªãã¤ã³ã¹ãã¼ã«ãã¦ããã®ãåºæ¬çãªæ段ã§ããã誰ãã«èªåã®ã³ã³ãã¥ã¼ã¿ã使ãããçãããããªããã³ã³ãã¥ã¼ã¿ã«ãã«ãã¤ã³ããããã°ããã§ãã¯ããã®ãä¸æ³ã§ãã Image remixed from an original by CREATISTA . â Windowsï¼ã¤ãã³ããã¥ã¼ã¢ããã§ãã¯ããæ¹æ³ Windowsã§ã¯ããã¤ãã³ããã¥ã¼ã¢ã¼ãã¨å¼ã°ããããã°ã©ã ãéãã¨ãæè¿ã®ã³ã³ãã¥ã¼ã¿ã®ä½¿ç¨å±¥æ´ããããã¾ããæé ã¯æ¬¡ã®ã¨ããã ã¹ã¿ã¼ãã¡ãã¥ã¼ã®æ¤ç´¢ããã¯ã¹ã«ãEvent Viewerãã¨å ¥åããEnterãã¼ããããã å·¦ãµã¤ããã¼ã®ãWindows ãã°ããããã«ã¯ãªãã¯ãããã·ã¹ãã ããã¯ãªãã¯
7. ã¦ã§ãã¢ããªã®å ¥åãå¦çãåºåå ¥åºåã¦ã§ããµã¼ãã¦ã§ãã¢ããª(PHP ãªã©)å¤é¨ API ãµã¼ã(Facebook API ã決æ¸ä¼ç¤¾ãªã©)å ¥åºåå¦çå ¥åºåãã¼ã¿ãã¼ã¹ãµã¼ã(MySQL ãªã©)ã¦ã§ããã©ã¦ã¶ 10. ã¦ã§ããµã¼ãã¼ãéããã¦ã§ããã©ã¦ã¶ããã®å ¥åã®ä»æ§ãèãããPHP ã«å ¥ã£ã¦ããå¤ã¯ä½ããç¥ãå¯å¤é·ã®ãã¤ãå (æååã§ã¯ãªãï¼ï¼)GET ãã©ã¡ã¼ã¿POST ãã©ã¡ã¼ã¿ã¢ãããã¼ããã¡ã¤ã«ãªã¯ã¨ã¹ãããã (Cookie ãªã©)å®éã®å¦çã«æ¸¡ãã¹ãå¤ã¯ä½ããèããæååãããã¤ãåãï¼æåã³ã¼ãã¯ä½ãï¼(ã¦ã§ããµã¼ãã¼ã§ãã¤ãåãå¦çãããã¨ã£ã¦ãã¾ããªãã®ã§ã PHP ã§ã¯åºæ¬çã«æåã³ã¼ãã®ããªãã¼ã·ã§ã³ã¯å¿ è¦ã ã¨æã£ã¦è¯ã)é·ãã¯ã©ããï¼ã©ãããææ³ãæ§é ãæã¤ãã¼ã¿ï¼å ¥åãããå¤ãå®éã®å¦çã«æ¸¡ãã¹ãå¤ãã©ããã確èªãããã¨ããããªãã¼ã·ã§ã³ãã¨ãã 11
CWE is a Software Assurance strategic initiative sponsored by the National Cyber Security Division of the U.S. Department of Homeland Security. CWE - 2010 CWE/SANS Top 25 Most Dangerous Programming Errorsã«ããã¦èå¼±æ§ã®åå ã¨ãªãå±éºãªããã°ã©ãã³ã°ã¨ã©ã¼25ãçºè¡¨ããããéçºè ã«ã»ãã¥ãªãã£åé¡ã®åå ã¨ãªãããã°ã©ãã³ã°ã«é¢ãã注æãä¿ããå®éã«ã½ããã¦ã§ã¢ãåä½ããåã®æ®µéã§åé¡ãçºè¦ã対å¦ã§ããããã«ãããã¨ãç®æãããã®ã2009å¹´ã«çºè¡¨ããããªã¹ãã®æ´æ°çã«ããããå 容ã®å¤ããæ´æ°ããã¦ããã2009å¹´çã使ã£ã¦ããå ´åã«ã¯ãä»åçºè¡¨ããã2010å¹´çãå度æ¤è¨ãã価å¤ãããã
ã¿ã¤ãã«ã¯åºæ¥ãã°é¢é£ããæ¹ã«èªãã§æ¬²ããã£ãã®ã§ã軽ãé£ãéã«ãã¾ããããã¿ã¾ããã:*) æè¿ã¯ããã®ãã¦ã£ãããã¼ï¼Twitterï¼ã§ãããããââã£ãã¼ãã¿ãããªãµã¼ãã¹ãã°ãã°ãç»å ´ãã¦ã¾ããï¼ ãããã§ã¾ãã¾ããã¤ãã¿ã¼ãé¢ç½ãæãã«ãªã£ã¦ã¦ãããæµãã§ããï¼ ã§ã・・・ã¡ãã£ã¨æ°ã«ãªããã¨ã・・・ æè¿ãããããã°ã©ãã«ã¯é ¼ããªãï¼ç°¡åããã°ã©ãã³ã°ï¼ãã ã¨ã・・・ ãPHPã§èª°ã§ãç°¡åWebãµã¼ãã¹ä½æï¼ãã ã¨ã・・・ ã¯ã¦ãªããã¯ãã¼ã¯ã®ãããã³ããªã§è¦ããã¾ããã・・・ ããã°ã©ãã³ã°ãã人ãå¢ããã®ã¯ç´ æµã§ãï¼ã¬ããï½¥ããã°ã©ãã³ã°ãªãï¼ ãªãã§ããã©ï½¥ï½¥ï½¥ ã¡ããã¨ã»ãã¥ãªãã£ã®ãã¨èãã¦ã¾ãã・・・ï¼ï¼ ãã»ãã¥ãªãã£å¯¾çã¨ãé£ãããé¢åããã¼ãã俺ã®é©å½ã«ä½ã£ããµã¼ãã¹ã¨ãã©ããªã£ã¦ãã¤ã¤ãï½ï½ã ãããã§ããããã§ãï¼ å¥ã«ããæã£ã¦ããªãã©ãã§ããããã§ãï¼
ä»æ¥ã¯ãWebæ å½è ã¨å¶ä½ä¼ç¤¾ãæä½éãã¦ãããªãã¨å¤§å¤ãªãã¨ã«ãªãå¯è½æ§ãããã»ãã¥ãªãã£å¯¾çã®è©±ã§ãã ããããã¦ãããªãã¨ãææªãããªãã®ãµã¤ãã«ã¦ã¤ã«ã¹ãä»è¾¼ã¾ãã¦å°ã£ããã¨ã«ãªã£ã¦ãã¾ãã¾ãã 2009å¹´5æã«ãWebæ¥çã«ççã«åºãã£ãã¦ã¤ã«ã¹ãããã¾ããé称ãGENOã¦ã¤ã«ã¹ãã¨ãããããã®ã§ããåã¾ã£ããã¨æã£ã¦ããã®ã§ãããæè¿ã§ãã¾ã æ®ã£ã¦ããããã§ãããç¥ãåãã®Webæ å½è ããã®ãã½ã³ã³ããã§ãã¯ããã¨å¯¾çãããã¦ããªãã£ãã®ã§ãä»æ´ã§ããæ¹ãã¦è§£èª¬ãã¦ããã¾ãã ã©ããªã¦ã¤ã«ã¹ï¼ ä½ãã¾ããã®ï¼ææãããã½ã³ã³ã§èªåã®ãµã¤ãã«FTPæ¥ç¶ããã¨ããã®ãµã¤ãã®HTMLã«ãã¦ã¤ã«ã¹ãæ¡æ£ããã³ã¼ããä»è¾¼ã¾ãã¾ãã ãããªãã¨ãããªãã®ãµã¤ãã«æ¥ã人ãã¦ã¤ã«ã¹ã«ææãã¦ãã¾ãã¾ãããGoogleæ¤ç´¢ã§ããã®ãµã¤ãã¯ã³ã³ãã¥ã¼ã¿ã«æ害ãä¸ããå¯è½æ§ãããã¾ããã¨è¡¨ç¤ºããã¦ã
å æ¥ãAmebaãªããCSRFã¨ããé常ã«ããã¥ã©ã¼ãªèå¼±æ§ãæ«é²ãããã¨æã£ãããããæ°æ¥ã¯ã»ãã³ãããã·ã§ããã³ã°ã§XSSã®èå¼±æ§ã¨ãIDæ¨æ¸¬ã«ããä»ã¦ã¼ã¶ã®å人æ å ±é²è¦§ã®åé¡ãçºçãã¦ããã¨ããåãæµãã¦ãã¾ãã ã¦ã¼ã¶ã®æ å ±ãé ãã£ã¦ãããªãããåºæ¬çãªã»ãã¥ãªãã£ã®å¯¾çãã§ãã¦ããªãã¨ããã®ã¯ãéè¡ã«ä¾ãããªãããéãé ãããã¨ããæã«ããéã¯é ããã¾ããã¡ããã¨ä¿ç®¡ãã¾ããã§ãè¦åã¯ãã¾ãããªãã®ã§çã¾ãããã¹ã¤ãã»ã³ãã¨è¨ããããããªãã®ã ã¨æãã è¦åã«ç©´ããã£ãã¨ããã®ã§ã¯ãªããã¾ã¨ãã«è¦åãã¦ã¾ããã§ãããã¨ããã®ã¯ãããã«ããããªããã¨ã§ãã ããã§ãéè¯WEBããã°ã©ãã§ããç§ãç¥ã£ã¦ããèå¼±æ§ãåæãã¦ã¿ãã ç§ã¯ããã°ã©ãã§ãã£ã¦ã»ãã¥ãªãã£ã®å°é家ã§ã¯ãªãã§ãããããä»å¹´ã®æ¥è¾ºããããã£ã¨å¤åãã®WEBããã°ã©ã ã¯çµãã§ã¾ããã ãã®äººéãç¥ã£ã¦ãããã®ã並ã¹
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}