2005-10-01ãã1ã¶æéã®è¨äºä¸è¦§
â WindowXPSP2ä¸ã§ã®ä¸å¤§ãã©ã¦ã¶ãç¹ã«Firefoxã§ãããã¨ãªãã§ãããã¨style屿§ããjavascriptãèµ·åãã¦cookieãalertãããã¨ãå¯è½ Wikiã¨ãRSSã¨ãBLOGã¨ãã§style屿§(éstyleè¦ç´ )ããã¡ãã¨ãµãã¿ã¤ãºãã¾ãããã¨ãã話é¡ã§ãã(styleè¦ç´ ã¨styleâ¦
â ã¨ããXSS ãã ãã¨ããå©ç¨äººå£ã夿°ã¨æãããWebã¢ããªã®XSSãå¶ç¶ã«ãã¿ã¤ãã¦ãã¾ã£ããããããã®ã¯åãã¦ã ãªããçãããã¿ã¼ã³ã ããªã¦ã è¿ããããªãã®ã«XSSã ããã¼ãããµããã¡ã¤ã³ã§ã®XSSãããCookieã¯åãã¦ããããã²ãã£ã¨ãã¦ã»ãã·ã§ã³â¦
â é»éã®é å«åããé ããã¨ãªã殿å ã«ããããé»éã®éä¸ã¤ãã¤ï¼ä¸è¬éæ¶åï¼ ç§ã¯é»éã¯ãããæ®éã®éããæã£ã¦ãã¾ããããããä½ããããçè·¡ã¨ãã¦æ®ããã¨æãã¾ããä½ã«ãªãã®ãã¯æªã ç¥ããã¨ãåºæ¥ã¾ããã â è¦æ¸ï¼XPSP2:ãã¼ã«ã«ã§HTMLãã¡ã¤ã«â¦
â ç¹è¨±ï¼å転ä½ã¨éåé»åæ© ç¹è¨±ï¼å転ä½ã¨éåé»åæ©ãå ¬éæ¥å¹³æï¼ï¼å¹´ï¼ï¼ï¼ï¼ï¼ï¼ï¼æï¼ï¼æ¥ ã®ç¹è¨±ãåºé¡äººã¯ç¬ç«è¡æ¿æ³äºº ç§å¦æè¡æ¯èæ©æ§ ããã³ ç¬ç«è¡æ¿æ³äººç©è³ªã»ææç ç©¶æ©æ§ ã J-STORE(å転ä½ã¨éåé»åæ© ä¸è°· å) æç§æ¸ããã¡ã¤ã³ãã³ç©çâ¦
â ããªãã¼ãºã®ã¤ããã¼é¸æãå¤çä»»ä¸éã«ç¯äººå½¹ã¨ãã¦åºæ¼ ãã¸ã§ãããæ¬¡ã®ãæ£æãå¤çä»»ä¸éã®ï¼åé£ç¶ã®ã·ãªã¼ãºãããããã©ããã®ãã¡ã®ç¬¬ï¼åç®ã«ã¤ããã¼é¸æãã²ã¹ãåºæ¼æ±ºå®ã¨ã®å ±éãããã¾ãããé常ãã²ã¹ãã¯å¿ ãç¯äººå½¹ã§ããããã©ããªãã¾â¦
â ãåææ¥ãæ¥ç¼ããµãã³ã¤ã³ã¦ã¼ãã ã¨ããã®ãã¯ãã£ã¦ããã®ããªï¼ é¢ä¿ãªããã©ç·çã¯ãæææ¥ãéå½ã«ã¤ã³ã¦ã¼ãç¶æ ã§ãããã¬ãã§æã¡ããã§ããããã¨æ¢ã«å¤åçã®ã¨ã©ã¤äººãä¸å½ã«éæã«è¡ã£ã¦ããæ¨¡æ§ã§ãã â æ¨æ¥ããæ®ããIPAã¸ã®å ±åã¯é å»¶ã« â¦
â Opera XML parsing failed: not well-formed Operaã§ãXML parsing failed: not well-formed ãªã®ã«ãJavaSvriptãä½åãã¦ãã¾ã£ããFirefoxã§ã¯ã確ãããããã®ã¯ãªãã£ãã¨æãã®ã§ããã â ãããµã¼ããµã¤ãHTTPæ©è½ã®XSSèå¼±æ§ ãããµã¼ããµã¤ãHTTPæ©â¦
â ææããã©æé¬± å¤é£ãé£ã¹ãå¾ãåçªã«æ°çºè¦ããããIPAã«å ±åãã¦ã§ãã¢ããªã±ã¼ã·ã§ã³èå¼±æ§é¢é£æ å ±å±åºã ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³èå¼±æ§é¢é£æ å ±å±åºã®æ¹ã¯ã以åã¡ã¼ã«ã§ããã£ã¦ããã®ãè¦è¿ãã¦ãããç§ã®è¦è½ã¨ãã«æ°ãã¤ãããã®ãå³å¯ã«è¨ãã°â¦
â æãè¦ä¸ãã¦æã è³¢ã人ã¨ã¯ãèªåã®å¿ã ã³ã³ããã¼ã«ãã¦ãã人ã§ããã æããªäººã¨ã¯éã« ããã«ã³ã³ããã¼ã«ããã¦ãã人ã§ããã ç§éããçã«å¤§åãªäººçã®æè¨ã ãã£ããã¨å¦ã¹ãã®ã¯ãåªãããæ¸ ããã§ã 幸ããªäººéã«ãªããéç¨ã«ããã¦ã§ããã â¦
â ä¸ç¢ºããªæ³å(ç¶ã) æ¨å¤å¯ãåã«æãã¤ãããã¨ï¼ãã§ã«ãã£ã¦ãããããããªãããããªãã®ããã¿ãããã¦ã¿ããããã¿ï¼ãä»ç¢ºèªãã¾ãããæ³åéãã§ããã ãã¼ã«ã«ãã·ã³ããã¯ãã¦ã³ãå¹ãã¦ããXPSP2ã«ã¦IE6ã®ãè©±ãæ£è¦ãªææ³ã使ãããã®è¾ºã®å ¥éâ¦
â ããããèå¼±ã«ä½ã£ã¦ãããµã¤ã Home of Acunetix Art Webãµã¤ããèå¼±ã§ãããã©ããã調ã¹ããã¼ã«ã®è©ä¾¡ã®çºã«ããã¨èå¼±ã«ä½ã£ã¦ãããµã¤ããAcunetix Web Vulnerability Scannerãè©ä¾¡ããããã®ãã®ã ãã©ç¡è«ãä»ã®ã¹ãã£ãã¼ã¨å¯¾è±¡æ¯è¼ããã¦ãä»â¦
â ä¸çå¼ã®è¨¼æ(ï¼) æ¨æ¥ã®æ¥è¨ã®ç¶ãã åé¡ï¼ 4ã¤ã®æ£æ°ãa,b,c,d ãã abcd=1 ãæºããã¨ãã a^2 + b^2 + c^2 + d^2 + ab + ac + ad + bc + bd + cd ã¯10以ä¸ã§ãããã¨ã示ãã tamoããããããã³ãããã£ãããã«ç¸å å¹³åç¸ä¹å¹³åã®é¢ä¿ã使ãã®ãæã£â¦
â ä¸çå¼ã®è¨¼æ 4ã¤ã®æ£æ°ãa,b,c,d ãã abcd=1 ãæºããã¨ããa^2 + b^2 + c^2 + d^2 + ab + ac + ad + bc + bd + cd ã¯10以ä¸ã§ãããã¨ã示ãã ã¡ãã£ã¨è¦ãããããªã⦠ããããã£ãï¼ï¼¾ï¼¾ï¼ â å¹´é½¢ãå½ã¦ã 以ä¸ã¯ç§ãè§£ãã¦ããªãããºã«ãé«åããããâ¦
â Webãã©ã¦ã¶ã¨SSLè¨å® ãã¡ãã¡åã£ã¦ãããSSL2.0åãã§å¿ èªæç®ã«ééãSSL2ããæ®ºãã¦ããªãã¢ãã¿ãèªãã°ç¦ãã [Technik]ä½ç¨åº¦ãªæå·åï¼RC4-40 40 bitï¼@niftyã»ã«ã³ãã¡ã¼ã«-æãéèµ°ã®æ¥ã [Technik]Webãã©ã¦ã¶ã¨SSLè¨å®-æãéèµ°ã®æ¥ã [Securâ¦
â ã¡ã¢ï¼ä¼¸ã³ãå®å®è¹ã®è¬ ä¸åå¼·ãªããã伸ã³ãå®å®è¹ã®è¬ãã¨ããã®ã仿¥åãã¦ç¥ãã¾ããã[éææ¥è¨] 1998å¹´5æ16æ¥(å)ã§ç¥ã£ãã®ã§ãããã¡ãã£ã¨å¼ç¨ããã¦é ãã¾ãã ãã¦ãããããããããã«æ¥µç«¯ãªä¾ã¨ãã¦ãé·ããä¸å å¹´ããããã«ã§ããå®å®è¹ãâ¦
â ç«èªå°ã²ã¼ã ç«èªå°ã²ã¼ã ãã¯ãªã¢ãã¦ãã¾ããããªã¢ã«ã¿ã¤ã ã¯ãªãã¯ã²ã¼ã ãéåç¥çµãä¸è¦ãªã®ã§ããã¿ãªéã¹ã¾ããã軽ãè¬è§£ãæããå¤å½èªã¯ä¸è¦ãé°å²æ°ã§ãä¸è¨ç»åã¯ãã¯ãªã¢å¾ãä¸»äººå ¬ç«ã¨ç¸æ¹ç«ã¨ãæãè¦ä¸ãã¦ã©ãã©ããªæ¨¡æ§ã¨ããã®ã¹ã¯ãªâ¦