2006-06-01ãã1ã¶æéã®è¨äºä¸è¦§
â Firefoxã¨ã¹ã¯ãªããã«ããèªåçãªã¯ãªãããã¼ãã¢ã¯ã»ã¹ ã¯ãªãããã¼ããã¼ã¿ãçã¾ãã æ¦è¦ Microsoftã®Webãã©ã¦ã¶ãInternet Explorerãï¼ä»¥ä¸ãIEãã¨ç¥ãï¼ã«ã¯ããã¹ã¯ãªããã«ããè²¼ãä»ããã¨ããåã®æ©è½ãããã¾ããããã¯ããJScriptãï¼Jaâ¦
â object.documentElement.outerHTMLããããã£å¦çã®èå¼±æ§ï¼IEï¼(Firefox) ãªãã§ãã¨ï¼ã¾ããããã¼ã¿çã¿ãã¿ã§ãã ä»åº¦ã¯IEã«ãããFirefoxãã§ãããã⦠object.documentElement.outerHTMLããããã£å¦çã®èå¼±æ§ ãããæªç¨ããã¨ãç¾å¨ã¦ã¼ã¶ã¼ãåâ¦
â æè¬CSSXSSèå¼±æ§ã®ç¾æ³ããã³æ³¨æç¹ ããããCSSXSSèå¼±æ§ã«ã¯SecurityUpdateãåºã¦ãã CVE-2005-4089ã®ãããããCSSXSSèå¼±æ§ã¯ãæ¢ã«MS06-021ã«ãã£ã¦FIXããã¦ãã¾ããã¦ã¼ã¶ãé常ã®ä½¿ãæ¹ããã¦ããã®ã§ãããªãã°ãã»ã¼å®å ¨ã§ããã¨èãããã¾ããâ¦
â IEã«ããã¦US-ASCIIãªã¨ã³ã³ã¼ãã£ã³ã°ã§XSSçºçï¼ US-ASCII ãªè¨è¿°ã§ã<,>,", ã®ãã£ã«ã¿ãªã³ã°ãåé¿å¯è½ããã®å®è¨¼ã³ã¼ã(IEã®ã¿ãèå¼±) ã¡ãã£ã¨å¤ãããã·ãªã®ã§ãããããã©ã ASCII Test: www.iku-ag.de åå ã¯ã©ãã«ããã®ã ä¸è¨å®ä¾ã«ã¦ãµã¼ããâ¦
â OTD BBS ã® spam 対ç OTD BBSã¸ã®spam対çãé£ãã å¿ è¦ã«è¿«ããã¦ãæ¥é½ã調ã¹ã¦ã¿ã¾ãããã¬ã³ã¿ã«ã®OTD BBSã¸ã®spamã¯ãã»ã¨ãã©ããæ¢ã«spywareçã«ãããã¡ã¾ã£ã¦ãããå¤æ°ã®åæã®ã¦ã¼ã¶ã®ãã½ã³ã³ã«å·£é£ã£ã¦ããbotã«ãã£ã¦ç¡å·®å¥ã«æ稿ããã¦ãã¾â¦
æè¿è¦ã夢ã®ä¸ã§ãã²ãã¯ãã¦æããã£ã¦ãããã©ããã³çºãããç§ã«èªã£ãè¨èãé¢ç½ãã£ãã§ãã ãã©ããã³å¸«å ・・・ã¨ããããã§ãï¼ã¤ã®åº§æ¨è»¸ã¨ã¯å¥ã«ããã®ä»ã®ããã¤ãã®åº§æ¨è»¸ããã£ã¦ããã®ä»ã®åº§æ¨è»¸ãè¦ããªãã»ã©å°ããç³ã¿è¾¼ã¾ãã¦ããã¨ããèâ¦
ä¹ ãã¶ãã«ãã½ã³ã³ããã£ã¦Operaã®iniãã¡ã¤ã«ãè¦ã¦ã¿ãã確ãã«ãããã¯å°ãããã§ããã³ã¡ã³ããé ããå¿åã®èç è ãããæé£ããããã¾ãããç§ã ãã§ã¯ãªãããã§ãã http://d.hatena.ne.jp/hoshikuzu/20060530#p1 http://d.hatena.ne.jp/hoshikuzu/â¦
ãããã Firefoxã§ãããã®çºè¦ãã¾ããã詳細ã¯ã¾ã æ¸ãã¾ãããããå±éºãªãã¿ã°ã®ã¿ã殺ãã¦ãããããªWebã¢ããªã±ã¼ã·ã§ã³ã§XSSãè¶ ç°¡åã«æç«ãã¾ã(ãã¯ã¤ããªã¹ãæ¹å¼ãªãåé¡ãªãã¯ãã§ãã)ã2000å¹´é ããã®Geckoã¨ã³ã¸ã³ãã©ã¦ã¶ãã¹ã¦ãåæ§ã«å½±â¦
MS06-021ã®é©ç¨ã«ãã£ã¦ãCVE-2006-2384ã®èå¼±æ§ã解決ããã¾ããCVE-2006-2384ã®èå¼±æ§ã«ã¤ãã¦ãJVN#74969119ã«ã¦è§£èª¬ãèªããã¨ãåºæ¥ã¾ããä¸èç§ãããå ±åè ã¨ãªã£ã¦ããããã§ããâ¦æ®å¿µãã¤é¢ç½ããã¨ã«ãIPAããã¸ã®å ±åæã«ããã¦ç§ãæ示ããå®è¨¼â¦