å
ã®æ¥è¨(XSSã¯ãã©ã¦ã¶ä¸ã§ã¹ã¯ãªãããåããCSRFã¯ãµã¼ãã¼ä¸ã§ã¹ã¯ãªãããåã - ockeghem(徳丸浩)ã®æ¥è¨)ã¯ãä»è¾¼ãã ãã¿ãããã£ã¦å¤ãã®æ¹ã«èªãã§ããã ãããç´°ããå
容ã«ã¤ãã¦ã¯ãé æ´ããæ¹å¤ãåçããããããã®ãã¼ãã«å¯¾ãã¦å¤ãã®é¢å¿ãéãããã¨ãã§ããã®ã¯è¯ãã£ãã¨æããä»åããæãå¤ãåãå¤ãã¦ãXSSã¨CSRFã®éãã説æããããã¨ãããã¨ã§ãä»åã¯ã¯ã¤ãºä»ç«ã¦ã«ãã¦ã¿ãã ã¨ãã£ã¦ããé常ã«ç°¡åãªã¯ã¤ãºã ã èªè¨¼ãå¿
è¦ã¨ããä¼å¡å¶ãµã¤ãmaitter.comã§ãå人æ
å ±ãå
¥åããç»é¢ããããå
¸åçãªãå
¥å(A)-確èª(B)-ç»é²(C)ã¨ããç»é¢é·ç§»ï¼ä¸å³ï¼ãæ³å®ããå ´åã XSSãçºçããããç»é¢ãä¸ã¤ããã CSRFãçºçããããç»é¢ãä¸ã¤ããã ã¨ãããã®ã (å
¥åç»é¢ã¯åæå
¥åã®ã¿æ³å®)ãã¨ã©ã¼æã®æåãªã©ã¯æå®ããã¦ããªãã®ã§æ³å®ããªããã®ã¨ããã 解
{{#tags}}- {{label}}
{{/tags}}