Developers Summit 2023 10-A-4 ãããã³ãã¨ã³ãéçºã®ããã®ã»ãã¥ãªãã£å ¥éãã®çºè¡¨è³æã§ãã https://event.shoeisha.jp/devsumi/20230209/session/4176/ ãHTTPSåããCORSããXSSããèå¼±ãªã©ã¤ãã©ãªã®â¦
Developers Summit 2023 10-A-4 ãããã³ãã¨ã³ãéçºã®ããã®ã»ãã¥ãªãã£å ¥éãã®çºè¡¨è³æã§ãã https://event.shoeisha.jp/devsumi/20230209/session/4176/ ãHTTPSåããCORSããXSSããèå¼±ãªã©ã¤ãã©ãªã®â¦
ãªã³ã¯ Yahoo!ãã¥ã¼ã¹ ä»äººã®å¯¿å¸ã«ããã³ä¹ãã¤ã¿ãºã©...ã¯ã¾å¯¿å¸ã被害å±æåºã¸ æ稿åç»ãçä¸âå 害è è¬ç½ªãå³æ£å¯¾å¿ï¼J-CASTãã¥ã¼ã¹ï¼ - Yahoo!ãã¥ã¼ã¹ ä»ã®å®¢ã注æãã寿å¸ã«ã¬ã¼ã³ä¸ã§ããã³ãä¹ãããã¨ãã£ãããããè¡çºã®åç»ãSNSä¸ã«æ稿ããã大æå転寿å¸ãã§ã¼ã³ãã¯ã¾å¯¿å¸ãã¯ãè¦å¯ã«è¿ã被害å±ãåºããã¨ã2023å¹´1æ23æ¥ã®åæã«æããã« 285 users 1013
LIFULL ã«æ°åå ¥ç¤¾ãããããã4å¹´ç®ã«ãªããã©ãã§ãã æ®æ®µã¯ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã¨ãã¦ãã»ãã¥ãªãã£/ãã¹ãèªååã«é¢ããæ¨é²ãæ¯æ´ãªã©ãä¸å¿ã«åãçµãã§ãã¾ãã 15æ¥ç®ã®è¨äº ã§ã¯ Dastardly ã GitHub ä¸ã§åããã¦ãã¾ããããä»åã¯ãã¼ã«ã«ï¼WSL2ï¼ä¸ã§åããã¦ã¿ããã¨æãã¾ãã What is Dastardly? Dastardly ã¯ãç¡æã§å©ç¨ã§ãã CI/CD ãã¤ãã©ã¤ã³ç¨ã® Web ã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£è¨ºæãã¼ã«ã§ãã éçºå 㯠Burp Suite ã§ããªãã¿ã® PortSwigger ã§ãéè¦ãª7ã¤ã®èå¼±æ§ã«é¢ãã¦10å以å ã§è¦ã¤ãããã¨ãã§ãã¾ãã Cross-site scripting (XSS) (reflected) Cross-origin resource sharing (CORS) issues Vulnerab
PlayStation 5(PS5)ã¯ã2020å¹´ã®ç»å ´ããè¨äºä½ææç¹ã¾ã§å ¥æå°é£ãªç¶æ ãç¶ãè¶ äººæ°ã²ã¼ã æ©ã§ãããããªPS5ã¯å¤ãã®ããã«ã¼ã«ãã£ã¦ãããã³ã°ã試ã¿ããã¦ããã2021å¹´11æ8æ¥ã«ã¯ãã·ã¹ãã ã®ãããã³ã°ã«æåãããã¨ããããã«ã¼ãç¸æ¬¡ãã§ç»å ´ãã¾ããã PS5 Kernel Exploit? TheFloW showcases Debug Settings menu on retail console, no plan to release. - Wololo.net https://wololo.net/2021/11/08/ps5-kernel-exploit-theflow-showcases-debug-settings-menu-on-retail-console-no-plan-to-release/ PS5 Exploit: Fail0verflow
æ·±å¤ã®é§è»å ´ããããã£ã¨åºã¦ããè»ã è»ãçã¿åºãããç¬éãã¨ãããé²ç¯ã«ã¡ã©ã®æ åã§ãã ãéµã¯æå ã«ããã®ã«ãè»ããªããªã£ã¦ããã ãã¾ãããããäºä»¶ããå ¨å½ã§ç¸æ¬¡ãã§ãã¾ãã ãã£ããè»ã¯ã©ããã£ã¦çã¾ããã®ãã äºä»¶ã®ã«ã®ãæ¡ããããç¹æ®ãªæ©å¨ãããå ¨å½ã§åãã¦é¢è¥¿ã§æ¼åããã¾ããã ï¼ç¥æ¸æ¾éå± è¨è åæ¨é§¿å¤ªï¼ ä»å¹´7æãåèçã®ä¸å¤è»è²©å£²åºããé«ç´ãããã³ãçã¾ãã¾ããã é§è»å ´ã«å±ç¤ºãã¦ããè»ã«ã¯ãéµããã¡ãã¨ããã¦ãã¾ããã éµãçã¾ãã形跡ã¯ããã¾ããã ã§ã¯ãè»ã¯ã©ããã£ã¦çã¾ããã®ãã åºã®é²ç¯ã«ã¡ã©ã«ã¯ããã®ä¸é£ã®ç¯è¡ã®éç¨ãè¨é²ããã¦ãã¾ããã
YubiKey ã®ãããªæå·ããã¤ã¹ã®ä»£ããã«ã¹ããã使ã£ã¦ FIDO U2F (Universal 2nd Factor) ãå®ç¾ã§ãã製åãããã¨ããã®ã¯èãããã¨ããã£ããï¼å®ã¯ SSH ã®èªè¨¼ã git commit/tag æã® OpenPGP é»åç½²åãè³ããããããããã Go 製ã§ãã«ããã©ãããã©ã¼ã 対å¿ã ã£ã¦ãã å ·ä½çãªä½¿ãæ¹ã«ã¤ãã¦ã¯ä¸ã®è¨äºãè¦ã¦ããã ããããï¼ä»çµã¿ãã¤ãã¤ãåãããªããã ããã以ä¸ã®ã·ã¼ã±ã³ã¹å³ã§ã ãããåã£ã¦ãï¼ krssh 㨠ssh ã®é¢ä¿ããã¼ã krssh ãå ¨é¨ãè©ä»£ãããã¦ãã£ã¦ãã¨ãªã®ã ãããï¼ ããã§åã£ã¦ããã¨ããåæã§è©±ãé²ãããã©ï¼ãã¤ã³ãã¯ã¹ããã¯åãªãéµã¹ãã¢ã§ã¯ãªãç½²åã¢ããªã±ã¼ã·ã§ã³ãå ¼ãã¦ããã¨ããç¹ã ããã Git commit/tag æã® OpenPGP é»åç½²åãä¼¼ããããªæããããï¼å¤åã krgpg
Amazon Web Services ããã° AWSç°å¢ã«ã»ãã¥ã¢ãªãã¼ã¹ã©ã¤ã³ãæä¾ãããã³ãã¬ã¼ããBaseline Environment on AWSãã®ãç´¹ä» ã¿ãªããããã«ã¡ã¯ãã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ãã®å¤§æã§ãã ãã®ããã°ã§ã¯ãç§ãã¡AWS Japanã®ã½ãªã¥ã¼ã·ã§ã³ã¢ã¼ããã¯ãã AWS Samples ã«å ¬éãã¦ãã ãBaseline Environment on AWSï¼BLEAï¼ãã«ã¤ãã¦è©³ãããç´¹ä»ãã¾ãã ããã¯AWSã®ã»ãã¥ãªãã£ã®ãã¹ããã©ã¯ãã£ã¹ãå®è£ ããç°å¢ããè¿ éã«å®ç¾ããããã®ãã³ãã¬ã¼ãã§ãã ã»ãã¥ãªãã£ãµã¼ãã¹ã ãã§ãªããããå©ç¨ãããã¢ããªã±ã¼ã·ã§ã³ã®å®è£ ãµã³ãã«ãå«ãã§ãã¾ããããã«ãã£ã¦åºæ¬çãªã»ãã¥ãªãã£ãå®ç¾ããç¶æ ãã¹ã¿ã¼ãå°ç¹ã¨ãã¦ã·ã¹ãã æ§ç¯ãéå§ã§ãã¾ãããã®ãã³ãã¬ã¼ãã¯åä¸ã®ã¢ã«ã¦ã³ãã§ããã¾ã AWS Contro
Amazon.comãå社å ã§ä½¿ããã¦ããå¾æ¥å¡åãã®ã»ãã¥ãªãã£ãªã³ã©ã¤ã³ãã¬ã¼ãã³ã°ãç¡åã§ä¸è¬å ¬éãæ¥æ¬èªçãæä¾ Amazon.comã¯ãããã¾ã§å社å ã§å¾æ¥å¡åãã«æä¾ãã¦ããã»ãã¥ãªãã£ã®ãªã³ã©ã¤ã³ãã¬ã¼ãã³ã°ã³ã¼ã¹ãç¡åã§ä¸è¬å ¬éãã¾ããã Starting today, we're making the same cybersecurity training used by Amazon employees available to businesses and individuals around the world at no cost. #CybersecurityAwarenessMonth https://t.co/h1EXJf6lrn â Amazon News (@amazonnews) October 26, 2021 ã»ãã¥ãªãã£ãã¬ã¼ãã³ã°ã¯ãCyber
ããã«ã¡ã¯ id:cohalz ã§ããã¯ã¦ãªããã°ã§ã¯2021å¹´4æã®å ¬å¼ããã°ã§ããã¹ã¦ã®ããã°ãHTTPSã«ä¸æ¬åãã¦ãããã¨ãæ¡å ãã¾ããã ⶠãHTTPSé ä¿¡ãã¸ã®åãæ¿ãã¨ãããã°ã®è¡¨ç¤ºã®ç¢ºèªããé¡ããããã¾ã ãã®æç¹ã§ã¾ã æ°ç¾ä¸ä»¶ã®HTTPã®ããã°ãæ®ã£ã¦ããç¶æ ã§ãããã2021å¹´8æã«ã¯ä¸è¨ã®æ¡å ã«è¿½è¨ããããã«ãå ¨ããã°ã§HTTPSåãå®äºã§ãã¾ããã å®äºã¾ã§ã«è¡ã£ã¦ãããã¨ããã®è¨äºã§æ¯ãè¿ã£ã¦ã¿ããã¨æãã¾ãã ã¯ã¦ãªããã°ã®HTTPSåã®ããã¾ã§ ã¯ã¦ãªããã°ã®HTTPSåã¯ã2017å¹´9æã«æåã®ãç¥ãããè¡ã£ã¦ã¹ã¿ã¼ããã¾ããã å½åã®äºå®ããæéããããã¾ãããã2018å¹´2æã«HTTPSé ä¿¡ã®æä¾ãéå§ãããã以éã«ä½æãããããã°ã¯æåããHTTPSã®ã¿ã§é ä¿¡ããã¦ãã¾ããã¾ãããã以åã«ä½æãããããã°ã§ããã¦ã¼ã¶å´ã§è¨å®ãå¤æ´ãããã¨ã§èªåã®ãã
[2021å¹´ç]AWSã»ãã¥ãªãã£å¯¾çå ¨é¨çã[åç´ããä¸ç´ã¾ã§] ã¨ããã¿ã¤ãã«ã§DevelopersIO 2021 Decadeã«ç»å£ãã¾ãã #devio2021 DevelopersIO 2021 Decadeã§ç»å£ããåç»ãè³æãæ²è¼ã解説ããã¦ãã¾ããAWSã®ã»ãã¥ãªãã£ã«ã¤ãã¦ç¶²ç¾ çã«æ±ã£ã¦ãã¾ããã¡ãã¼é·ãã®ã§ã注æãã ããã«ã¡ã¯ãè¼ç°ã§ãã ã¿ãªãããAWSã®ã»ãã¥ãªãã£å¯¾çãã¦ã¾ããï¼(æ¨æ¶ ã¤ãã«ãã£ã¦ã¾ããã¾ãããDevelopersIO 2021 Decadeï¼ç§ã¯ã[2021å¹´ç]AWSã»ãã¥ãªãã£å¯¾çå ¨é¨çã[åç´ããä¸ç´ã¾ã§]ãã¨ãããã¼ãã§ç»å£ãã¾ããã åç»ã¨è³æã¨è§£èª¬ããã®ããã°ã§ãã£ã¦ããã¾ãã åç» è³æ 解説 åç»ã¯ã¡ãã£ã±ãã§åã£ã¦ããã®ã§ã解説ã¯ä¸å¯§ãã«ãã£ã¦ããã¾ãã ã¿ã¤ãã«ä»ãã®èæ¯ ä»åä½åããããªã¼ã£ã¦æã£ã¦ããã2å¹´åã®Deve
ããã¯ãLet's Encryptãæ¯ãããã®äºäººã®ã«ã¼ãCA㨠OpenSSLã®ç©èªã§ããã DST Root CA X3 (2000-2021) ISRG Root X1 (2015-2035) ã2021å¹´1æã ISRG Root X1ããã¾ã¾ã§ä¸ç·ã«ãã£ã¦ããDST Root CA X3ããã®å¯¿å½ãéè¿ã»ã»ã»ãã®ã¾ã¾ã ã¨åãä¿¡é ¼ãã¦ããã¦ããªãããã©ã³ã®ï¼å ·ä½çã«ããã¨2016å¹´ãããã¾ã§ã®ï¼å¤ãã¯ã©ã¤ã¢ã³ããã¡ã¯ Let's Encryptãããä¿¡ç¨ãã¦ãããªããªã£ã¡ããã»ã»ã»ã©ããããã DST Root CA X3ãã©ãããããæ»ã¬åã«(æå¹æéãåããåã«)ãåãä¿¡é ¼ã«å¤ããæ¨ãä¸çæ¸ãã¦æ®ãã°ããããããããµã©ãµã©ã Issuer: O = Digital Signature Trust Co., CN = DST Root CA X3 Validity Not Bef
å¯å£«éãéå¶ããããã¸ã§ã¯ãæ å ±å ±æãã¼ã«ãProjectWEBããä¸æ£ã¢ã¯ã»ã¹ãåã顧客ã®æ å ±ãæµåºããåé¡ã§ãè¦å¯åºã®ã·ã¹ãã æ å ±ãæ¼æ´©ãã¦ãããã¨ãæ¥çµã¯ãã¹ããã¯ã®åæã§2021å¹´9æ6æ¥ã¾ã§ã«åãã£ãã è¦å¯åºã¯æ¥çµã¯ãã¹ããã¯ã®åæã«å¯¾ããæµåºããæ å ±ã¯ãéå»ã«éç¨ãã¦ããã·ã¹ãã ã®è¨è¨æ å ±ãªã©ãã¨æ¸é¢ã§åçããå½è©²ã·ã¹ãã æ¤å»å¾ã«ããã¦ãå¯å£«éãï¼ãã¼ã¿ãï¼å»æ£ãã¦ããããå社ã«å¯¾ããä¸æ£ã¢ã¯ã»ã¹ã«ããæ å ±ãæµåºããã¨ã2021å¹´5ææ«ä»¥éã«å ±åãåãããï¼è¦å¯åºï¼ã¨èª¬æãããå¯å£«éã«å¯¾ãã¦è¢«å®³ã®å®æ ã調æ»ããããæ±ãã¦ããã¨ããã è¦å¯åºã¯ãæ å ±ãæµåºããã·ã¹ãã ã¯ä¸æ£ã¢ã¯ã»ã¹ããã£ãã¨ãããæç¹ã§æ¢ã«éç¨ãçµäºãæ¤å»æ¸ã¿ã§ãããç¹æ®µã®åé¡ã¯çãã¦ããªããã¨èª¬æãå¯å£«éã«éçºãè¨è¨ãä¿å®ãªã©ãå§è¨ãã¦ããç¾å¨éç¨ä¸ã®ã·ã¹ãã ã«ã¤ãã¦ã¯ã追å ã®å¯¾çãè¬ãããªã©ã»ãã¥ãªãã£ã¼ã®
ãã¨ã¿ã®ç¡äººã¬ã³ã¿ã«ã¼ããã§ã¯ããªããã¢ããªã®Bluetoothã§éµã®ééãããã®ã ããé£é¨¨ã®å±±å¥¥ã¾ã§æ¥ãã¨ããã§çªç¶ã©ããã£ã¦ãæ¥ç¶ã§ããªããªããã¢ãéããªããªã£ã¦è©°ãã ããã¨ã¿ã¯ããããäºæ ãæ³å®ãã¦ãªãã£ããããã®ã ããã¨ã³ã¸ãã¢ã¨ãã¦ã¯ãã¾ããããã¨ããã»ããªãã
æ¦è¦ Dockerã®æ¬çªç°å¢ã§ç§å¯æ å ±ã使ãéã«ãç°å¢å¤æ°ã使ããã¨ã¯æ¨å¥¨ããã¦ã¾ããã ç§å¯æ å ±ãæ±ãã«ã¯ãã³ã³ãããªã¼ã±ã¹ãã¬ã¼ã·ã§ã³ã®secret supportã使ããã¨ãæ¨å¥¨ããã¦ã¾ãã Docker Composeã«ã¯ç§å¯æ å ±ãæ±ãããã«ãsecretsãããã¾ãã(Docker Composeã®secretsã¯Docker Swarmã¨ä½µç¨ãããã¨ãåæã®æ©è½ã§ã) ç°å¢å¤æ°ã§ç§å¯æ å ±ãæ±ãæã®åé¡ç¹ ç§å¯æ å ±ãæ±ãæã«ãããããæ¹æ³ã¨ãã¦ãç°å¢å¤æ°ã使ãæ¹æ³ãããã¾ãã (ãã®è¨äºã«ããã¦ãç§å¯æ å ±ã¨ã¯ãã¹ã¯ã¼ããAPIãã¼ãæ³å®ãã¾ãã) ããããDockerã®ããã¥ã¡ã³ãhttps://docs.docker.com/get-started/07_multi_container/ ã«ã¯ While using env vars to set connection set
åç (14件ä¸ã®1件ç®) ã¡ããã¡ããã£ã¨èªåã§ã§ãã人ã§ããããã¾ã§20å以ä¸ä½æ¥ãã¦ãã¾ãã ãã®ä¸ã§é©æ£ä¾¡æ ¼ã ã¨æãã¾ãã SSL証ææ¸ã¯ããããã©ãããå®ã«è±å¯ã§ãã 1. SSL証ææ¸èªä½ã®åå¾æ¹æ³ããã³ãã¼ã«ãã£ã¦ããªãéããæ¥æ¬ã®çµç¹ã®åå¨è¨¼æãªã©å¥å¤©çãªæ¹æ³ãè¦æ±ãããã®ããããNginx Apacheãªã©ãµã¼ãã¼ã«ãã£ã¦ãå¤ããªãã¦ã¯ãªããªãã 2. æä¾ãããä¸é証ææ¸ããã¡ãã§ä¸ã¤ã®ãã¡ã¤ã«ã«ã¾ã¨ããªãã¦ã¯ãªãããã©ã®ããã«ãã³ãã«ãããããã³ãã¼ããã®æ å ±ã ãã§ã¯èªæã§ã¯ãªããã®ãçµæ§ãã£ã¦ããã 3. SSLã®ãããã³ã«ã¯å®ã«ä½è¨ãªãã®ãããããããã...
Qualysã¯7æ20æ¥(ç±³å½æé)ããQualys Security Advisory - Sequoia: A deep root in Linux's filesystem layer (CVE-2021-33909)ãã«ããã¦ãLinuxã«ã¼ãã«ã«ç¹æ¨©ææ ¼å¯è½ãªèå¼±æ§ãåå¨ããã¨ä¼ããããã®èå¼±æ§ãå°ãªãã¨ã2014å¹´7æã«Linux 3.16ã«æ··å ¥ãã¦ä»¥æ¥åå¨ãã¦ããã¨èª¬æãã¦ããã7å¹´éã«ããã£ã¦Linuxã«ã¼ãã«ã«åå¨ãã¦ãããã¨ã«ãªããå¤ãã®Linuxãã£ã¹ããªãã¥ã¼ã·ã§ã³ããã®èå¼±æ§ã®å½±é¿ãåããã¨ã¿ãããã Qualys Security Advisory - Sequoia: A deep root in Linux's filesystem layer (CVE-2021-33909) ããã¯Linuxã«ã¼ãã«ã®ãã¡ã¤ã«ã·ã¹ãã ã¬ã¤ã¤ã«åå¨ããsize_t-intå¤
ãä¸å½äººæ°ã¯ã¿ããªã18æ¡ã®èº«å証çªå·ï¼IDçªå·ãå ¬æ°èº«ä»½å·ç¢¼ï¼ãå²ãå½ã¦ããã¦ããããã®ãã¡ãæåã®6æ¡ãæ¸ç±ç»é²å°ã®å°åçªå·ã§ã次ã®8æ¡ãçå¹´ææ¥ãæ®ã4æ¡ã¯èªè¨¼çªå·ã ãããã®ãã¡1æ¡ã¯æ§å¥ã§æ±ºå®ãããããã®ã«ã¼ã«ã¯ãã¨ãå½å®¶æå°è ã ã£ã¦ä¾å¤ãããªããä¸å½ã®ãããã¦ã¼ã¶ã¼ã®éã§ãç¿è¿å¹³ã®èº«å証çªå·ãç¹å®ãããã®ã¯2018å¹´9æã®ãã¨ã ã£ãã ç®ã®åã®è¥è ãåãç¶ãã¦ãããå½¼ã¯ä¸å½ã®åä½å¶çãªã¤ã³ã¿ã¼ãããã³ãã¥ããã£ï¼é称ãæªä¿åè sú quÄnãï¼ã®ä¸»è¦äººç©ã®1人ã§ãåºæ±çæ·±å³å¸çã¾ãã®è彦éï¼26ï¼ã¨ããã
Osumi, Yusuke @ozuma5119 Threat Intelligence, Cyber Security Researcher, PenTester. CISSP,CISA https://t.co/8kTFSGuuoZ Osumi, Yusuke @ozuma5119 ã¤ãªã³ã«ã¼ãããããã®æ³¨æåèµ·ã¯å¤§ééãã§ãã ãã¡ã¤ã³ã¯ãå§ã¾ã£ã¦ãããã§ã¯ãªããçµãã£ã¦ãããé¨åãè¦ãªãã¨æå³ãããã¾ããã https://aeon .co .jp .example. com/ ã®ãããªã¾ããããããã¡ã¤ã³ããããä¸çªè©æ¬ºã«ä½¿ããã¾ããåºãåã«ã社å ã®ã¨ã³ã¸ãã¢ã®ã¬ãã¥ã¼ãåãã¾ãããã pic.twitter.com/hLVrhHisPH
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}