Developers Summit 2023 10-A-4 ãããã³ãã¨ã³ãéçºã®ããã®ã»ãã¥ãªãã£å ¥éãã®çºè¡¨è³æã§ãã https://event.shoeisha.jp/devsumi/20230209/session/4176/ ãHTTPSåããCORSããXSSããèå¼±ãªã©ã¤ãã©ãªã®â¦
Developers Summit 2023 10-A-4 ãããã³ãã¨ã³ãéçºã®ããã®ã»ãã¥ãªãã£å ¥éãã®çºè¡¨è³æã§ãã https://event.shoeisha.jp/devsumi/20230209/session/4176/ ãHTTPSåããCORSããXSSããèå¼±ãªã©ã¤ãã©ãªã®â¦
Kickstarterã§è³é調éä¸ã®ãTrackerPadãã¯ã10ãã³ã¹ç¡¬è²¨ï¼ç´24.5ããªï¼ã¨ã»ã¼åããµã¤ãºã®æ¬ä½ã«ããªãã¤ãSIMãçµã¿è¾¼ã¾ãã¦ãããæ大7æ¥éã¹ããã«ä½ç½®æ å ±ãå ±åã§ããGPSãã©ãã«ã¼ãè²¼ãä»ããã¢ã¤ãã ã®ä½ç½®æ å ±ã®è¿½è·¡ã ãã§ãªããã¸ãªãã§ã³ã·ã³ã°ï¼æ©å¨ãæå®ç¯å²ããå¤ããã¨æ±ºããããåä½ãå®è¡ï¼ãå¯è½ããã¨ãã°é§è¼ªå ´ããèªè»¢è»ã移åãããéã«ã¹ããã«ç§»åè¦åãéç¥ããã¨ãã£ã使ãæ¹ãã§ããã ã¢ã¼ãªã¼ãã¼ãæ ã®ä¾¡æ ¼ã¯ãTrackerPadã2æã¨ã¯ã¤ã¤ã¬ã¹å é»ãã£ã¼ã¸ã£ã¼ãå°ç¨ã¢ããªã®ããã¢ã¼ã·ã§ã³ã³ã¼ãã®ã»ããã§30è±ãã³ãï¼ç´5800åï¼ããTrackerPadã5æã»ããã®ä¾¡æ ¼ã¯45è±ãã³ãï¼ç´8700åï¼ãåºè·ã¯ä»å¹´12æãäºå®ãã¦ãããå ¨ä¸çã¸ã®çºéã«å¯¾å¿ããã 使ãæ¹ã¯ã«ã³ã¿ã³ããTrackerPadã表ã«å°å·ãããQRã³ã¼ããã¹ããã¢ããªã§èªã¿è¾¼ã¿
It's time to update your passwords to various sites affected by the Heartbleed bug. Credit: Mashable composite. iStockphoto, SoberP An encryption flaw called the Heartbleed bug is already being dubbed one of the biggest security threats the Internet has ever seen. The bug has affected many popular websites and services -- ones you might use every day, like Gmail and Facebook -- and could have quie
å æ¥ã®ng-mtg#4 AngularJS åå¼·ä¼ã§LTãããã¨æã£ããã©ç³ãè¾¼ã¿ãéã«åããªãã£ãã®ã§ããã°ã«æ¸ãã¾ãã å æãªãªã¼ã¹ãããAngularJS 1.2ã¯ã»ãã¥ãªãã£ããã°ã£ã¦ãçãªãã¨ãèããã®ã§ãã»ãã¥ãªãã£å¨ãã®ä»çµã¿ã調ã¹ã¦ã¿ã¾ããã ãé¡ã¯ä»¥ä¸ã§ãã CSRF JSON CSP (Content Security Policy) Escaping CSRF ã¦ãã¼ã¯ãªãã¼ã¯ã³ãHTTPãªã¯ã¨ã¹ãã«è¼ãã¦ãµã¼ãã¼ã§ãã§ãã¯ãã対å¿ãä¸ã®ä¸ã§ã¯ä¸»æµï¼æè¿ã¯ã«ã¹ã¿ã ãããã®ãã§ãã¯ã«ãã対çãï¼ AngularJSã§ã¯ãXSRF-TOKEN Cookieã«ãã¼ã¯ã³ãè¼ã£ã¦ããã¨ã$httpã使ã£ãHTTPãªã¯ã¨ã¹ãã®ãããã«èªåçã«X-XSRF-TOKENãããã¼ãä»ãã XSRF-TOKEN Cookieã¯ãã¡ããNot HttpOnlyã§ã Angularçã§ã¯CS
Webã¢ããªã±ã¼ã·ã§ã³ã«ããã¦JSONãç¨ãã¦ãã©ã¦ã¶ - ãµã¼ãéã§ãã¼ã¿ã®ããåããè¡ããã¨ã¯ãã¯ãæ®éã®ãã¨ã§ããããã®ã¨ãJSONå ã«ç¬¬ä¸è ã«æ¼ãã¦ã¯å°ãæ©å¯æ å ±ãå«ã¾ããå ´åã¯ãå¿ ã X-Content-Type-Options: nosniff ã¬ã¹ãã³ã¹ããããã¤ããããã«ãã¾ããã(ãããæ©å¯æ å ±ãã©ããã«é¢ããããå ¨ã¦ã®ã³ã³ãã³ãã«ã¤ããã»ãããããé¢é£:X-Content-Type-Options: nosniff ã¤ãããªããã¤ã¯æ»ãã°ããã®ã«! - èã£ã±æ¥è¨)ã ä¾ãã°ãæ©å¯æ å ±ãå«ã以ä¸ã®ãããªJSONé åãè¿ããªã½ã¼ã¹(http://example.jp/target.json)ããã£ãã¨ãã¾ãã [ "secret", "data", "is", "here" ] æ»æè ã¯ç½ ãã¼ã¸ãä½æãã以ä¸ã®ããã«JSONé åãvbscriptã¨ãã¦èªã¿è¾¼ã¿ã¾ãããã¡ã
以ä¸ã¯ãWEBããã°ã©ãã¼ç¨ã®WEBèå¼±æ§ã®åºç¤ç¥èã®ä¸è¦§ã§ãã WEBããã°ã©ãã¼ã®äººã¯ãããèªãã°WEBèå¼±æ§ã®åºç¤ããã¹ã¿ã¼ãã¦WEBããã°ã©ã ãæ¸ããã¨ãã§ããããã«ãªã£ã¦ããããã§ãã ã¾ããWEBèå¼±æ§ã®ç°¡æãªãã¡ã¬ã³ã¹ã¨ãã¦ãå°ãå©ç¨ã§ããããããã¾ããã WEBã¢ããªã±ã¼ã·ã§ã³ãéçºããã«ã¯ãéçºè¦ä»¶æ¸ãããã°ã©ã ä»æ§æ¸éãã«éçºããã°è¯ãã¨ããããã«ã¯ããã¾ããã ãããWEBèå¼±æ§ãçãæªæã®ã¦ã¼ã¶ã«ã対å¦ããªãã¨ãããªãã®ã§ãã ä»åãWEBã¢ããªã±ã¼ã·ã§ã³ãéçºã«ããã£ã¦ã®WEBèå¼±æ§ãã以ä¸ã®ä¸è¦§ã«ã¾ã¨ãã¦ã¿ã¾ããã ãã®ã¾ã¨ããWEBã¢ããªã±ã¼ã·ã§ã³éçºã®åèã«ãªãã°å¹¸ãã§ãã ã¤ã³ã¸ã§ã¯ã·ã§ã³ ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° ã»ãã·ã§ã³ã»ãã¤ã¸ã£ã㯠ã¢ã¯ã»ã¹å¶å¾¡ãèªå¯å¶å¾¡ã®æ¬ è½ ãã£ã¬ã¯ããªã»ãã©ãã¼ãµã«(Directory Traversal) CSRFï¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}