2004-07-01ãã1ã¶æéã®è¨äºä¸è¦§
â IEBlogã¨ãããçºè¦ IEéçºã®ä¸ã®äººã®ããã°ããããIEãã³ã»ã¼çºè¨ã«å¯¾ãã¦ã®ã³ã¡ã³ãã®åµããæ°ã®æ¯ã IEBlog the Microsoft Internet Explorer Weblog http://blogs.msdn.com/ie/ æãã«ãIEã«å¯¾ãã¦ã¯ãã¾ãã¯OSããã®ç¬ç«ããé¡ããããã§ããã»ãã¥ãªâ¦
â ãã£ãã²ã¨ã¤ã®å´ãããããã æ¸åºã«è¡ã£ããã¸ã§ã¤ã ãºã»ãã£ãããªã¼ã»ã¸ã¥ãã¢èã®ããã£ãã²ã¨ã¤ã®å´ãããããããã¨ããSFãç®ã«æ¢ã¾ã£ãã訳è ãã¨ããããªã«ãã«èªãã ãããã®å°èª¬ãèªã¿ãããåã«ãã³ã«ããã»ãããªããªãã£ãããããªãã¯äººâ¦
â èå¼±æ§ã¦ãããã ãã¥ã¼ã¹ãæµãã ã»ãã¥ãªãã£ã¼ãã¼ã«ï¼ï¼¥ï¼ï¼¯ã¨ã¹ã©ãã·ã¥ãããã¸ã£ãã³ã§èå¼±æ§ã¦ãããããµã¤ãã®ãã¥ã¼ã¹ãæ¬æ¥æµãã¾ãããåå¿ããã¡ãã¡ã§ããªãã¨è¨ãã¾ãããããè²ã èãããããã¾ãã IEç¹æã®ã³ã¡ã³ãã«ã¦ã¹ã¯ãªããè¦ç´ â¦
â ç¾äººãã£ã«ã¿ã¼ è¶ ç¾äººåã仲éç±ç´æµãã¯çãã¦ãã人éã¨ã¯æããªãç¨ã®ç¾äºº è¶ ç¾äººåã仲éç±ç´æµãã¯çãã¦ãã人éã¨ã¯æããªãç¨ã®ç¾äººã«ãªã£ã¦ãããã¨ãå¤ãã«éããªããã¨ã®ãã¨ã御æã 帰ã£ã¦ãããç¾äººãã£ã«ã¿ãã§çæ¯å¦ç ç·¨ - ãªãã¨ãã¾ã¨â¦
â Mozillaã¨alert() çºç«¯ ãã人ããã¡ã¼ã«ãæ¥ã¾ãããï¼éç®ã§ä»°ãã«ã¯ãMozilla Firefoxã¯IEãããXSSèå¼±æ§ã«å¯¾ãã¦å¼·ãã®ã§æ¯éãå§ãããããã¨ã®ãã¨ãhoshikuzu | stardustã®æ¸æã§ããã®æ¹åã§ä½ãæ¸ãã¦ãããäºã ãã¨ããå 容ã§ããæ ¹æ ã¯ç¹ã«æ¸ãâ¦
ãã£ãã¯ã¨ã³ã¸ãã¢ã§ã¯ããã¾ãããå¿ã«é¿ãã¾ããã Engineerãèãã http://jibun.atmarkit.co.jp/fengineer/column/kayama01/kayama01.html
å¤ãã¯ãã©ãã¯ããã¯ãã±ã対çã§ãã®ãããªãã¨ãããè¦ãããã
ãã¨ãã° http://www.popuptest.com/ã¨ç·¨éç»é¢ã§æ¸ãã
æè¿ã«ãªã£ã¦ããéå»ãã°ãèªãç¿æ £ãã¤ãããã¨ããfull-disclosureãªMLãªã®ã§ãããã©ããä¸æ±ã®è©±ã¨ãåºã¦ãã¦ãã¬ã¼ã ã®åµãæããå¼ãã¦ãã¾ããèªã¿ãããªããç¿æ £ãã¤ããã®ã¯å¤§å¤ã§ããä¸æ¥å主ã§çµãããããã¾ãã§ãããããã«ã¦POPUPãåºãã¨ãâ¦
Windowsãã·ã¼ã³+IEã§ã¨ããã¨ããã«è¨ªåããããã¦ã£ã³ãã¦ãPOPUPã§éãã¦å³ä¸ã®ãããã³ãã¼ã¯ããªãããã«ãªã£ã¦ãã¾ã£ããããã§ã¯éãããªããalt+F4ã§è±åºãããªã©ããªããï¼é ããã§ãã°ãªã³ç»é¢åºããã¦ããããã£ã±ãã¦ã¼ã¶ã¨ãã¹ã¯ã¼ãããã人â¦
åãåå¼·ã«ãªã£ããããèå¼±æ§å ±åã®ä¸ã§æãè¡ãã«ããã®ã¯ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã«é¢ããèå¯ã ã¨æã£ã¦ãã¾ãããããã£ã±ãããã§ãããããã³ãããããããããããã¶ãã
ãã®æ¥è¨ã«ããã¦ã¯ç¿æ £ã§ä¸æã«ä¸åãããã¢ã¯ã»ã¹ãã°ã®çµ±è¨å¦çã試ã¿ã¦ã¯æ¯å失æãã¦ãã¾ãã失æã®åå ã¯ã²ã¨ãã«çµ±è¨å¤ã®è§£éãåºæ¥ãªãäºã§ããã¯ã¦ãªæ¨å¥¨ã®ã¢ã¯ã»ã¹ã«ã¦ã³ã¿ã¼ã®çºè¨ã«ããã°ã(ç§ã¯ãã®çºè¨ãé»åã§éè¨ãã¾ãã)ãªãã¡ã©ã¼ãé£ãâ¦
ãã§ãFireFoxææ°çãã¼ããããã¾ãå¤ã£ã¦ããªããããããæ¿ãã¨ãããå»»ã£ã¦ãã¦ãªã³ã¯ããã©ã£ã¦ãããã¡ã«ãããªãInternetExplorerãèµ·åãããããããã¨ããï¼çç¥ï¼ãã¾ããããªãã ãããPDFãªãAcrobatReaderãèµ·åãããã®ã¨åãããªã®ããã§ãâ¦
ï¼æ¥ä¸ãããªã快調ä¹ãã§ãå¤å°ãã¡ã½ãªãã¨ãããã®ãä»ãã¨ããã¡ã¼ãªã³ã°ãªã¹ãã§è¦ã¦ãã¾ãããããããã£ãã·ã³ã°è©æ¬ºã«ã¯ä½¿ããªãã®ã ããã©ããããããæå³ã§ã¯ã»ãã¥ãªãã£ã¼ãã¼ã«ã§ã¯ãªãã®ã ããã©ããé·æçã«è¦ãã¨ã¦ã¼ã¶ãããã¢ãã¬ã¹ãã¼â¦
ãããã§ãåãã¦æ°æ¥ã¦è¯ãå ´åã®éª¨åï¼ï¼ï¼ï¼ï¼æã®æ¬ç©ã®ã³ã¤ã³ãåãã¦ãããæ¤æ»è¦ã®æå ã®ï¼ï¼æã¨è¨éããã ï¼âAï¼é£ãåããªããã°ãï¼ï¼æã®ä¸ã«ç¯äººã¯ããããç¯äººãæ£å¸¸ãããéãã軽ããã¯æ¢ã«å¤ã£ã¦ãããæ®ãï¼åã®è¨éã§ç¯äººããç¸ã«æãâ¦
â ããã«ã¹ã¿ã³ãã¼ã ããã«ã¹ã¿ã³ãã¼ã ããã«ã¹ã¿ã³ãã¼ãã¨ããè¨èã使ãããæã«ã¯å¤§æ¦ãä½ãè¯ããªããã®ã¨ãã¦æå³ãã¦ä½¿ãããã®ã§ã¯ãªãã§ãããããä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³ã«ã¤ãã¦ã®åãæ¢ãæ¹ãããã¨æãã¾ããããã«ã¹ã¿ã³ãã¼ãã«ãªããããå¾ãªâ¦
â ã¨ãããã¸ã·ã§ã³ãã¤ãã¼ ãã¸ã·ã§ã³ãã¤ãã¼ï¼ ã²ãããã®å¸ä¸è¦å»»ãæ¥è¨ http://d.hatena.ne.jp/toshichan/20040718#p1 ç´ æ´ãããã¨ããããªãã¨ãããã絶è³ãä¸è¨ã®èå¯ããå¼ç¨ãããã¦é ãã¨ãã¦ã»ãã¥ã¢è¨è«ã®å ´åãæããã¦ï¼ï¼ï¼ã妥å½ããã®ã ãâ¦
â Mozillaã«ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°èå¼±æ§ã®å¯è½æ§ Full-Disclosure ML ãè¦ã¦ãããå¤ãªãã®ãã Mozillaç³»ã«ã¦ä¸è¨ã®ãããªã½ã¼ã¹ã§å¤é¨JSãå¼ã³åºãã¦ãã¾ãã¨ã®ãã¨ã <html> <head> </head> <body> <p>If you cannot see "VULNERABLE" below, the browser is safe.</p> <div> <script src="indexvuln.js" </div> <p>I am able</p></div></body></html>â¦
éæ¹é£ã¨ãããã®ããåç¥ã§ããããã 4 9 2 3 5 7 8 1 6ä¸ã¯ãï¼ï¼ï¼ï¼ï¼ ã®éæ¹é£ã§ããã©ã®åãè¡ãåè¨ãï¼ï¼ã¨ãªã£ã¦ãã¾ãã対è§ç·ä¸ãåè¨ãï¼ï¼ã§ãããã¦ãï¼ã°ã©ã ããï¼ã°ã©ã ã¾ã§ã®åé ãæºã®ä¸ã«éæ¹é£ã®ããã«ç½®ãã¦ããã¾ããã©ããï¼æãéâ¦
表è¨æ¹æ³ï¼¡ãï¼¢ï¼ï¼£ï¼ï¼¤ï¼ï¼¥ã®ï¼æãããã»ã³ã¤ã³ãè¦ã¤ãã¾ãã天秤ã«ããããã¨ãããå·¦ï¼ï¼å³ãã®ããã«æ¸ãã¾ãããã¨ãã°ãAï¼ï¼¢ãå·¦ã«ãï¼£ï¼ï¼¤ãå³ã«ããã¦ã¯ãããã¨ããAï¼ï¼¢ï¼ï¼ï¼£ãDãã¨æ¸ãã¾ããæ¢ã«æ¬ç©ã§ãããã¨ãããã£ã¦ããã³ã¤ã³ããâ¦
ãªãã ãé¢åãããã®ã§ããæ°åå ¨ä½ãéãããã§ããªãã§ããããã¬ãã§é¢ç½ãäºãã£ã¦ãã°ãã³ãã³ãã¡ããããèªåã§ããããããã¾ããããããããæãããããããªæ¥ãããããã
â Browser Security Test ããªãã®ä½¿ã£ã¦ãããã©ã¦ã¶ã¯ã©ã®ãããã»ãã¥ã¢ãªã®ã§ããããï¼ãããªãµã¤ããããã¾ããã²ã¨ã¤ã®åèã¨ãã¦ãä»ã«ãåºæºã¯ããã§ãããããBrowser Security Test: http://bcheck.scanit.be/bcheck/ãªãã ãOpera7.52ãããªãå¼·â¦
ããªãã®æªããåéã¯ãçµå±ç¯ç½ªã諦ããããã§ãããã«ãã³ã®å¥¥ãã天秤ã®ä»å±åã®åé ãåºã¦æ¥ã¾ãããåé ã¯ï¼ã°ã©ã ããï¼ã°ã©ã ã¾ã§é ã«ï¼ã°ã©ã ãã¤éããå¢ãã¦ããï¼ç¨®é¡ã®åé ã§ããããã¦é©ãã¹ãäºã«ããã®ä¸ã®ï¼ç¨®é¡ã ãã¯ãããªãã®æªããåéâ¦
ããªãã®æªãåéããããä¹ ãæ¯ããã¾ããã®ã«ãã³ã®ä¸ãè¦ã¦ã¿ããããªãå°ããªè¢ããã£ã±ãããã ãï¼å®ã¯ãªããã®è¢ã«ã¯å ¨é¨ï¼ï¼ï¼åçï¼æãã¤ãã¯ãã£ã¦ãããã ãã²ã¨è¢ï¼ï¼ï¼ï¼åãã§ãè¢ã¯æ°ãåããªãã»ã©ãã®ã«ãã³ã«ã¯ãã£ã¦ãããã ããããªãâ¦
IEã§SUNã®JAVAãã¤ã³ã¹ãã¼ã«ãã¦ããã¨ãªã¢ã¼ãããã®æ»æãæç«ãããããã®ã§ããé²è¡æ¹æ³ã¯ã©ãããã°ããã®ã§ããããæ©ãçµè«ã§ãªãããªããã¨ããããJAVA使ããªãæé ã¯ããã®ã ããã©ã
ãªãã ããããã¾ããããshellã¹ãã¼ã ã¯IEã ãæ°ãã¤ããã°è¯ãã¨ãããã¨ã§ã¯ãªãããã§ãã¦ãMicrosoft製ã®ãããããªã¢ããªã¯å ¨é¨æ°ãã¤ããªãã¦ã¯ãããªã風å³ã§ããããããããã®ããããåºãããææªå ¨ã¨ã£ããã ããä»åº¦ã®æä¾ãããã«ã¯æéçãªâ¦
application.shellã¨ã¯éã話é¡ã ãããç³»ã®ãã©ã¦ã¶ã§ãªã¢ã¼ãããï¼ãã¨ãã°Webãµã¤ãããï¼shellã¹ãã¼ã ã§ç´æ¥ããããããå±éºæ§ããã£ã¦ããã®ãããã¯æ¢ã«åºã¦ãã¾ãããã¨å ±éããã¦ãã¾ãããSMBçµç±ã§shellã¹ãã¼ã ãæªç¨ãããå¯è½æ§ããããã§â¦
ãã¼ããapplication.shellã«ãã代ç¨åãæ©æ©åºã¾ããã§ãããç¾å¨ãè³æ¥Microsoftããã«ã¯æå½ã¦ããé¡ãããããã®ã§ããã¾ãã¬ã¸ã¹ããªã§æ®ºãããããã¯ntbugtraqã«åºã¦ãã¿ããã§ããã©ãWindowsUpdateãããªãã¨ãããªã«ãã¨ã åèï¼ http://www.st.râ¦
ãã¾ããããã¯ææ°ã®Opera7.52ã§FIXããã¦ãã¦ãã¾ãããã¾ããããã¯ã¾ã èå¼±ã åèï¼ http://www.st.ryukoku.ac.jp/%7Ekjm/security/memo/2004/07.html#20040709_tuiki
æ¬æ¥ææãã¢ã¼ãã§æ¸ãã¦ãã¾ãããã¤ãã¯HTMLãç´æ¥æ¸ãã¦ãããã ãã©ä»æ¥ã¯ã¯ã¦ãªå¼ã«ãªã³ãã«ããã³ãããããã¸ç²¾ç¥çã«å¤å¿ã§ããèä½çã«ã¯ããã§ãããã©ããã¨ã§ãã¼ã¯ã¢ããããªããã®ã ãããï¼ãªã¤ã©ãããããã¶ãããªããªãã