ã¯ã¦ãªããã°ã®ãã«ãã§ã
ã¯ã¦ãªããã°ã®ãã«ãã§ã
UTF-7 ã使ã£ã¦ã¹ã¯ãªãããè¨è¿° +ADw-SCRIPT+AD4-alert(\'XSS\');+ADw-+AC8-SCRIPT+AD4- IE ã¯ãæåã¨ã³ã³ã¼ãã£ã³ã°ãä¸æ㧠UTF-7 ã£ã½ãæååãããã°ãèªåå¤å¥ã§ UTF-7 ã¨ãªãã
æçµæ´æ°æ¥: Wednesday, 29-Nov-2006 02:46:05 JST Webãã° CSRF (Cross Site Request Forgeries) DoS (ãµã¼ãã¹æå¦) ãµãã¿ã¤ãº ãªã¬ãªã¬è¨¼ææ¸ Cookie Monster SQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ HTTP Response Splitting (ã¬ã¹ãã³ã¹åå²) HTTPã®ãã¼ã¸ã®ãã¬ã¼ã ã«HTTPSã®ãã¼ã¸ã表示 ãããã¡ãªã¼ãã¼ããã¼ ãã£ãã·ã³ã° Forceful Browsing (å¼·å¶ãã©ã¦ãº) ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° ã¼ããã¤(0day)æ»æ ãã£ã¬ã¯ããªãã©ãã¼ãµã« ã»ãã·ã§ã³ãã¤ã¸ã£ã㯠権éææ ¼ OS ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ ãªã¼ãã³ãããã· Webãã° ï¼¼ãã__ããï¼ ï¼¿ãï¼ï½ï¼ã_ãã¼ã³ã¼ã³ |ã| ï¼ ãï½Â´ã ï¼¼ ('A`
Wizard Bibleã¯2018å¹´4æ22æ¥24æã«ééãã¾ããã æ稿è ãèªè ã®çæ§ãããã¾ã§ã®éæ¬å½ã«ãããã¨ããããã¾ããã ã2021å¹´6æ27æ¥æ´æ°ã Wizard Bibleã®è¨ç«ããééã¾ã§ã«è³ãéç¨ã詳細ã«è¿°ã¹ãæ¬ãåºããã¨ã«ãªãã¾ããã ãWizard Bibleäºä»¶ããèãããµã¤ãã¼ã»ãã¥ãªãã£ãå·çããã¸ã§ã¯ã èå³ã®ããæ¹ã¯æ¯éèªãã§ã¿ã¦ãã ããã Security Akademeiaã«æ»ã
æ å ±ãå®ããæªæ¥ãåµé ãããã¤ãªãã¢ã¨ãã¦ã®ä¿¡é ¼ã¨èªä¿¡ã§ããã£ã¨å 㸠æé«å³°ã®ã»ãã¥ãªãã£ãµã¼ãã¹ã¨ãITãã¼ã¿ã«ã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¾ãã ãã£ã¨ç¥ã
Googleã®ä¸è¬æ¤ç´¢ã§ãã社å¤ç§æ å ±ã®å ¥ã£ãExcelãæ¤ç´¢ãããããããåºã¦ãã(åè ã å ¬éWebãµã¼ãããæ©å¯æ å ±ãå¼ãåºããGoogleãããã³ã°ãã®è å¨ã¨ããã®å¯¾ç)ã¨ãã£ã話ãããããã¤ãæè¿ã¯Google Calendarã§æããã«å ¬éæ å ±ãããªãããããªäººã®äºå®ãæ¤ç´¢ã§ããã¨ããææã話é¡ã«ãªã£ãã ã¨ãããã¨ã§ãæ¨æ¥ãªãªã¼ã¹ãããGoogleã³ã¼ãæ¤ç´¢ã§ãããã£ããè²ã ãªãã¤ãã¤ãææãã kottke.org ã§ã¯ä»¥ä¸ã®ãããªæ¤ç´¢ä¾ã å§ç¸®ã¢ããªã±ã¼ã·ã§ã³ã®æå·çæé¨åã®ã½ã¼ã¹ ãã¹ã¯ã¼ããåãè¾¼ãã ããã°ã·ã¹ãã ã®ã½ã¼ã¹ ãããã¡ã¼ãªã¼ãã¼ããã¼èå¼±æ§ããããããªã½ã¼ã¹ å ¬éãããã¹ãã§ãªããã¨æ¸ãã¦ããã½ã¼ã¹ æç´ã£ãããç½µã£ããã馬鹿ã«ãããã¨ããã³ã¡ã³ã æåããã°ã©ãã¼ã®ååã§ã®æ¤ç´¢ ã¾ããPHPã®ã»ãã¥ãªãã£ã¨ããã°ãã®äººã® Chris Shiflett
ã304 Not Modified ã¤ã³ã¿ã¼ãããã®ã´ã¼ã«ãã³ã¿ã¤ã ã¨ãµã¤ãã®æ´æ°æéããèªãã§ã ã21:00ã24:00 ããããã¤ã³ã¿ã¼ãããã®ã´ã¼ã«ãã³ã¿ã¤ã ãã¨ããäºãªã®ã ããã ãã¾ãªãæ°ã¯ãã®ã´ã¼ã«ãã³ã¿ã¤ã ãé¿ãã¦æ´æ°ãããã¦ããããã ããç§ã®æ´æ°ã¯ãã®æé帯ã«ãã£ã¡ãå ¥ã£ã¦ãããªã ã¤ã³ã¿ã¼ãããã£ã¦çµå±ã¯èªã¿é£ã°ãã®æåã«ãªã£ã¦ãã¾ããã¡ãªãã§ããä»ã®ããã°ãæ´æ°ãããä¸ã§èªåãæ´æ°ããããä¾ãã°10åã®ä¸ã®1åã«ãªã£ã¦ãã¾ããã§ããããããä»ã®ãµã¤ããæ´æ°ãããªãæéã®ä¸ãªãã2åã®ä¸ã®1åã«ãªãã¨æããã§ãããããªã£ãããå¾è ã®æ¹ãèªåã®è¨äºããã£ããèªãã§ããããã¨æãã¾ãããï¼ ç¢ºãã«ããã ãç§ãããã¯åãã£ã¦ãããã ãããããå¤ãã®äººã«èªãã§è²°ãããã¨æã£ã¦ããããã´ã¼ã«ãã³ã¿ã¤ã ã«æ´æ°ããã®ã¯é¿ããæ¹ãããã ãããã ããæ°ãè¨ããã¦ããããã«ä¼ç¤¾å¤ãããã¦ãã
ã»ããã¼ç³ãè¾¼ã¿ãã©ã¼ã ãã¹ãã ã®è¸ã¿å°ï¼ï¼æéåã®Webã¢ããªã»ã®ã¼ã®æ¹é è¨ç»ï¼1ï¼ï¼1/4 ãã¼ã¸ï¼ æ7æããã¤ããã30åæ©ãèµ·ãããæéåã27æ³ã®ç§ã ä»æ¥ã¯ãæéåãããã¦å¸æãã¦ããWebæ å½ã¸é å±æ¿ãã«ãªãæ¥ãæéåã®ä¼ç¤¾ã§ã¯åµç«è¨å¿µæ¥ã®ä»æ¥ãæ©ã«ãWebã«åãå ¥ããããã®æ°ãããã¼ã ãçºè¶³ããã®ã ã 足åãã軽ããæéåã¯ä¼ç¤¾ã¸åºç¤¾ãããã¾ã ããWebæ å½ã«ãªããã¨ãããã¨ä»¥å¤ãå ·ä½çãªãã¨ã¯ä¸åç¥ãããã¦ããªãããã¨ã¦ããããããã¦ããã ãã®ä¼ç¤¾ã§ã¯ã人äºçºä»¤ãããã¨ãã¯1人ãã¤ç¤¾é·å®¤ã«å¼ã°ãããæéåãèªå¸ã§ãããããã¦ããã¨ãä¸çªã«å£°ãæãã£ãã 社é·ããæéåãå ¥ããªããã æéåã¯2å¹´ã»ã©åã«ãã®ä¼ç¤¾ã¸è»¢è·ãã¦ãããåè·ã§ã¯ãç°¡åãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½æãFlashä½æãªã©ã®ã³ã¼ãã£ã³ã°ãä¸å¿ã®Webãã¶ã¤ã³ã®ä»äºããã¦ãããWebãã¶ã¤ã³ã®ä»äºãå¸æ
â ä¸æ¥ä¸å¹¼å ãã¡ã®æ åãä¸ç¹å®å¤æ°ã«å ¬è¡éä¿¡ãã¦ããä¿è²æ åã©ãå®ãIT ââå¦æ ¡ã§é§ ã§è¡ã§, ææ¥ããããããã, 2005å¹´9æ28æ¥ ãããä¸ç¶ å¹¼ç¨åã§ã®ç¬é¡æºéï¼è·å ´ã§å®¶ã§è¦ªå®å¿ ï¼ç¥ï¼ããããã·ã¹ãã ã§ã¯ãä¿è·è ãã«ã¯å°ç¨ãã¹ã¯ã¼ããé å¸ãã¦æ åãè¦ãããããã«ãããã権éã®ãªãé¨å¤è ã«ã¯æ åãè¦ããªãã®ãæ®éã ãããããåä¿è²æã¯ãä¿è²æã«èå³ãæã£ã¦ã»ãããã¨ãä¸è¬ã«ãæ åãå ¬éãã¦ããããã£ã¨ããåã©ãã®å®å ¨ãå®ããããã«ã¡ã©ã®ãºã¼ã ã¢ããã¯ã§ããªãããã«ãã¦ãããä¿è·è ã§ããªãéããæ åã§åã©ãã®è¦åãã¯ã§ããªãã ã¨ããè¨äºããã£ããã西èä¿è²æãã§æ¤ç´¢ãã¦ã¿ãã¨è¦ã¤ãã£ãã 社ä¼ç¦ç¥æ³äºº 西èä¿è²æ ã©ã¤ãæ å ãããã«ã誰ã§ãã©ã¤ãæ åãè¦ãããããã«ãªã£ã¦ãããä»è¦ãã¨ããããã¼ã«ããåºã女å ãã¡ãå ¨è£¸ã«ãªã£ã¦çæ¿ãã¦ããæ§åãæ ã£ã¦ããã ãæ åã§åã©ãã®
â [ruby] XSS - 表示系ãã©ã¡ã¼ã¿ã«åå¨ããç²ç¹ : Rubyã®å ´å Ruby+ERBã 㨠<a href="http://example.com/test.cgi?id=<%= id %>">hoge</a> ã¿ãããªæ¸ãæ¹ã¯å±éºã§ã <a href="http://example.com/test.cgi?id=<%=u id %>">hoge</a> ã®ããã«ãããã£ã¦ãã¨ã§ããã®ããªï¼ Ruby+ERBã§CGIãæ¸ãã¨ãã¯ã åºæ¬çã«ã<%= str %>ã§ã¯ãªã <%=h str %> ã使ãã a hrefã®URLã®ä¸ã«åãè¾¼ãã¨ã㯠<%=u str%>ã使ãã ã©ããã¦ãstrã®ä¸ã§HTMLã¿ã°ã使ãããã¨ãã ãã<%= str %> (ã¨ã¹ã±ã¼ããªã)ã使ãã ã¨ããæãã§ãã£ã¦ã¾ãã ãã©ãã¯ããã¯ããã¦ããè¨äºã«ããããã©ããã¡ãã¡ ãç¡å®³åããå¿ è¦ããã
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®æéã§ãï¼ XSSã¨ããã¨â¦ï¼ ã¾ã£ããã«æãã¤ãã®ããå ¥åãã¼ã¿éä¿¡ â 確èªè¡¨ç¤ºã®é¨åã§ã®ç¡å®³åæ¼ãã§ãããï¼ ãã¨ãã°ãããªæãã®ãã©ã¼ã ããåãåã£ããã©ã¡ã¼ã¿ãã 確èªã¨ãã¦è¡¨ç¤ºãããã¼ã¸ã¨ãï¼ (å ¥å) <form action="register.cgi" method="post"> ã¿ã¤ãã«ï¼<input type="text" name="title"> â ãã¼ãã¯ã¾ã¡ã¡ããï¼ããå ¥å æ¬æï¼<input type="text" name="body"> â ãããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert(1)</script>ããå ¥å </form> (確èª) <p>ãã®å 容ã§ç»é²ãã¦ããï¼</p> <p> ã¿ã¤ãã«ï¼ ã¼ãã¯ã¾ã¡ã¡ããï¼<br> æ¬æï¼ ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert
第1å Ajaxæè¡ã®ç®ã«è¦ããªãéä¿¡å 容ãã®ããã¦ã¿ããã§ã¯ãAjaxã®æè¡èæ¯ã解説ãã¾ãããä»åã¯ããã»ãã¥ãªãã£ãã¨ãã観ç¹ã§Ajaxãè¦ã¦ããããã¨æãã¾ãã 2åç®ã®ä»åã¯ãé常ã«å¹ åºãã奥ãæ·±ããAjaxã®ç¹å¾´ã«æ½ãã»ãã¥ãªãã£ãªã¹ã¯ãããå®éã®ãµã³ãã«ã¢ããªã±ã¼ã·ã§ã³ã®éä¿¡ãããã¦ã¹ã®åããåç»ã§è¦ãªãããç解ãã¾ããããã¹ãã¤ã¦ã§ã¢ããã¼ãã¬ã¼ã¸ã®åºæ¬çãªå¯¾çã解説ãã¾ãã é常ã®Webã¢ããªã¨ç°ãªãAjaxã®ç¹å¾´ã«æ½ããªã¹ã¯ ãAjaxã®ã»ãã¥ãªãã£ãã¨ãããªããã£ã¦ãããAjaxã¨ã¯ãããåãªãWebãã©ã¦ã¶ã§åä½ããã¢ããªã±ã¼ã·ã§ã³ãªã®ã ãããããã¾ã§ã®Webã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã¨ãã¾ãå¤ãããªãã®ã§ã¯ï¼ãã¨äºæ³ãããæ¹ãå¤ãã§ãããã確ãã«ãWebã¢ããªã±ã¼ã·ã§ã³ã¨ãã¦æ³¨æãã¹ãã»ãã¥ãªãã£ã®ãã¤ã³ãã¯ãAjaxã«ããã¦ãå ±éãã¦å½ã¦ã¯ã¾ãã¨èãã¦åé¡ã
ãããã³ã° Wiki â ãããã³ã°ã®é¢é£ã®ããããã«ã¤ãã¦ã¾ã¨ãã¦ã¿ããã¨æã£ã¦ããwikiã§ããæªããã¨ã«ã¯ä½¿ããªãã§ãã ããï¼ãã¶ã使ããªãã¨æãã¾ããï¼ã å 容ã¯å°ããã¤å å®ããã¦ããããã¨æã£ã¦ãã¾ãããwikiã®ä½¿ãæ¹ã¯ãã¾ãããã£ã¦ããªãã®ã§äºæ ã§æ¶ããããããã¾ããã 硬ãã®ã§æä½ããã§ãã¾ããã«ãããã¨æãã¾ãã 誰ãç·¨éããªãã®ã§ç·¨éã§ããªãããã«æ»ãã¾ãããç·¨éããã人ã¯yamamoto at bogus.jpå®ã«ã¡ã¼ã«ããããblogã«ã§ãæ¸ãè¾¼ãããé»è©±ã§ããã¦ãã ãããã â
Please Sign In No account? Create new user.
iPhoneã®ä¸è¬ä¿®çåºã¯äºç´ãªãã§ãæ¥åºã§ããï¼ åºæ¬çã«ã¯é£ã³è¾¼ã¿ã§ä¿®çã«è¡ã£ã¦ãOK iPhoneãç½®ãã¦ããã½ãã¡ã«ãã£ããã¨è °ããã¦ãã¾ããããã«ãå²ã£ã¦ãã¾ã£ãããããªæã¯ã¹ããã®ä¸è¬ä¿®çåºã¸è¡ãã¾ããããç»é¢å²ãã¯ãã¹ãããã¿ãã¬ããã®æ éåå ã¨ãã¦é常ã«å¤ããã®ã§ããäºç´ãªãã§çªç¶ãåºã«è¡ã£ã¦ãå¹³æ°ãããã¨ãä¸å®ã«æãæ¹ã ãããã£ãããããããã¾ãããçµè«ã¨ãã¦ã¯ç¹ã«åé¡ã¯ãªããäºç´ãªãã§è¨ªåãã¦ãç»é¢å²ãã®ä¿®çã¯ãé¡ãã§ãã¾ãã ãã ãä»ã®ãµã¼ãã¹æ¥ã®ãåºåæ§ãäºç´ãªãã®å ´åããåºãæ··éãã¦ããã¨é çªå¾ ã¡ãããªããã°ãããªãã§ããç¹ã«ç¹çãã¦ããã¹ããä¿®çã®ãåºã ã¨ãè¡åãåºå ã§åºæ¥ã¦ãããäºç´ãªãã ã¨ãèªåã®é çªãå·¡ã£ã¦ããã¾ã§é·æéå¾ ããããå¯è½æ§ãããã¾ããå¹³æ¥ã®æãæ¼ãªãå©ç¨å®¢ãå°ãªãå ´åãå¤ããé£ã³è¾¼ã¿ã§ãæ¯è¼ã¹ã ã¼ãºã«ä¿®çãé ¼ãã¾ãã äºç´ã¯å ¥ããæ¹ãæçã«ã
2024å¹´2æ28æ¥ãã¢ã¤ãã£ã¡ãã£ã¢ã主å¬ããã»ããã¼ãITmedia Security Week 2024 å¬ãã«ããããã¯ã©ã¦ãã»ãã¥ãªãã£ãã¾ã¼ã³ã§ãå¤æ©å¤§å¦ ã«ã¼ã«å½¢ææ¦ç¥ç 究æ 客å¡ææ è¥¿å°¾ç´ å·±æ°ããæ»æè ã¯ããã«ãã¦ã¯ã©ã¦ããå ï¼ãï¼ã¨ãã®ããä»ç¥ãã¹ãæ»æã®ãã¬ã³ããã¨é¡ããè¬æ¼ã«ç»å£ããã以åã¯ã©ã³ãµã ã¦ã§ã¢ããã¼ãã¨ãã¦ãä¸çæ å¢ã«åããã¦è¬æ¼ããããä»åã¯âã¯ã©ã¦ãâã®ç¾ç¶ãã西尾æ°ã®è¦ç¹ã§èªãã»ãã·ã§ã³ã¨ãªã£ããï¼2024å¹´4æ5æ¥ï¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}