â
â IEï¼æ°ææ³CSSXSSãGoogle Desktopã®æ å ±ãçã¾ããæãâ¦ã¨ãããGoogleã°ããã§ãªãã§ããã¤ãã¤ã®ã¯ããããåãã¾ãããã
2006-01-30 追è¨ï¼2006å¹´01æ20æ¥ä»ãã§ä»¥ä¸ã®ç¶æ ã§ãããã¤ã¯ãã½ãã社ããã®è¨æã§ãã
æç¨ãªæ å ±ãé©åãªæ¹æ³ã§ãé£çµ¡ããã ã大å¤æè¬ãããã¦ããã¾ãããWeb ãµã¤ãå´ã§ã®å¯¾å¿ãå°é£ã§ããäºãå¤æããã¾ããInternet Explorer ã®èå¼±æ§ãè¿ã 対å¿ã§ããè¦è¾¼ã¿ã§ãããããInternet Explorer ã®ä¿®æ£ã«ããããã®åé¡ã«å¯¾å¿ããæ¹åã§ä½æ¥ãé²ãã¦ããã¾ãã
(snip)
ã¾ãããã®åé¡ã®æ ¹å¹¹ã¨ãªãã¾ã Internet Explorer ã®èå¼±æ§ã«ã¤ãã¦ã¯ãç¾å¨éæ対å¿ä¸ã§ãããã¾ããããã¡ãã®ãªãªã¼ã¹ææã«ã¤ãã¾ãã¦ã¯ã詳細ããä¼ããããã¨ãã§ãã¾ããã
èª ã«ç³ã訳ãããã¾ããããä½åãç解ã¨ã客æ§ã®ä¿è·ã«ãååã®ç¨ãããã ãé¡ããããã¾ãã
ãã¨ãã¨ãã©ã¦ã¶ã®åé¡ã§ã¯ããããã§ãç§ã¨ãã¦ãåã¦ã§ããµã¤ãéå¶ç¤¾å´ã«å¯¾å¿ãæ±ãããã¨ã¯é£ããã¨å¤æãã¦ãã¾ããã®ã§ä¸ã®è¨æã¯æé£ãã£ãã§ãã追è¨çµããã
styleè¦ç´ ã®@importã§ãã¯ãã¹ãã¡ã¤ã³ãªå¤é¨ã¹ã¿ã¤ã«ã·ã¼ããã¡ã¤ã«ãã¤ã³ãã¼ãåºæ¥ããã¨ã¯å½ç¶ã§ããaddImportã§ãè¯ããããã§ãããèªã¿åºããã¹ã¿ã¤ã«ã¯JavaScriptã§document.styleSheets(0).imports(0).cssTextã使ã£ã¦ãã³ããªã³ã°ã§ãã¾ãããã¦ãæ
æã«ã¹ã¿ã¤ã«ã·ã¼ã以å¤ã®ãã¡ã¤ã«ãä¾ãã°HTMLãã¡ã¤ã«ãªã©ãèªãããã©ããã§ãããç§ã¯èªè¡ã®çºã以å試ãããã¨ãããã¾ãã以ä¸ã§è¿°ã¹ãæ¹æ³ã§ç§å¯ãªã¢ã¬ã@importã§ãã¦ãã¾ã£ããæãã§ã¯ããã¾ããããçµæã¨ãã¦ã¾ãã£ããéç¨ããã§ããï¼é ãç®ï¼ãã¨ããã§ãInternetExplorerã§ã¯ããã®æ¹æ³ã§èªã¿è¾¼ããã¡ã¤ã«ãã¹ã¿ã¤ã«ã·ã¼ãã«ä¼¼ãç¹å¾´ãæã£ã¦ããã¨èªãã¦ãã¾ãã®ã§ããï¼{
ã¨ã}
ã¨ã:
ã¨ããé©å®ã¯ãã£ã¦ããã°è¯ãããããã§ãããããã³ã¼ããã¯ãã£ã¦ãããã¼ã¸ãªãçµæ§ãããããªããã§ãããããã«å
ç·ã«ãã¦ããã¹ãæ
å ±ãã¯ãã£ã¦ããã°çããã¨ãåççã«å¯è½ã«ãªã£ã¦ãã¾ãã¾ããã©ããããããã£ãææ³ã«å¯¾ãã¦CSSXSSã¨ãããã¼ãã³ã°ããã¦ãããããã®ã§ããã@importã¯ç¢ºãã«ã¯ãã¹ãã¡ã¤ã³ãã¨ãããã¨ã§ã
æ£ç´ãªã¨ãããIEã«ã¤ãã¦ãããç´ãã®ã¯ã¡ãã£ã¨åä»ããããã¾ãããããã®CSSãã¡ã¤ã«ãVALIDã§ãããã©ããæ¤æ»ãããã¸ãã¯ãã©ãã¾ã§å³ããããã°è¯ãã®ãã¨ããè°è«ã«ãªãã®ã§ã¯ãªãããªãããï¼IEç¬èªã®ä¾ã®ä»æ§ããã¡ã¤ã«ã®å
容ãåæã«sniffãããããããªãã®ããªï¼ãã¬ã¼ã³ãªããã¹ããã¡ã¤ã«ã§ãã¿ã°ãæ¸ãã¦ããã¨åæã«HTMLãã¡ã¤ã«ã¨ãã¦èªããããä¾ã®ã¢ã¬ã§ããã©ãèªè¡çã¨ãã¦ã¤ã³ã¿ã¼ããããªãã·ã§ã³ã®åã¾ã¼ã³ã®ã»ãã¥ãªãã£è¨å®ã§èª¿ç¯ã§ããã®ããâ¦
ã¨ããããã§ä»¥ä¸ã®è¨äºã«å¯¾ããåå¿ã§ãããä½ã«ãæ¤è¨¼ãã¦ãã¾ããããµã¼ãããã£ãã·ã³ã°çãªææ³ã§èªå°ãã¦Google Desktopã«èãããã¦ããå
容ãçãã®ã§ããããããã°ããæ¢å®å¤è¨å®ã®IEã§ã®å·¡åã¯ç¦æ¢ãï¼ã£ã¦ç§ãGoogle Desktopãªãã¦ä½¿ã£ã¦ãã¾ããããåããã¨ã§ããï¼åçãèããã°ãã©ãã§ãããã§ããªãã§ãããã§ãçãããããã¡ãã£ã¨ç
½ãããã§ãããããã§ããããã£ããã¯ã¨ãªã¼ã«}{
ã¨ããå
¥ããã¨ãã¯ãã£ã±ãããã¨ãã§ããã
- ITmedia ã¨ã³ã¿ã¼ãã©ã¤ãºï¼IEã«ã¾ãèå¼±æ§å ±åãGoogle Desktopã®æ å ±ãçã¾ããæã
- Google Desktop Exposed: Exploiting an Internet Explorer Vulnerability to Phish User Information
ãã¦ã¨ãã¾ã¼ã³ã®ã»ãã¥ãªãã£è¨å®ãè¦ç´ãã¦å ¬éããã¦ããPoCã試ãã¦ã¿ã¾ããâ¦ã©ãããé§ç®ã£ã½ãã対çã«ãªããâ¦sniffå¨ãã§ã¯ãªããããã§ãã
追è¨ï¼ãã£ããGoogle以å¤ã§å人æ å ±ãæ¼ããã¤ãããªã®ãçºè¦ãã¾ããããã£ãä»IPAã«å ±åãã¾ãããå ±åçªå·ã¯[IPA#21753252]ãã®CSSXSSææ³ãç°¡åãããæ¬å½ã«è å¨ã ã¨æãã¾ãããµã¤ã管çè ããéã¯è¦æ³¨æã§ããã¨ãã£ã¦ãé²å¾¡ã®æ¹æ³ãè¦å½ãããªããã§ããããIEã®ã¦ã¼ã¶ã¹ã¿ã¤ã«ã·ã¼ããªã!importantåºãã¾ããã§é²è¡ã§ãããã¨ãæãã¾ããã[IPA#21753252]ã®exploitã¯ãã£ã¨å¼·ãã£ãâ¦ããã«è¿½è¨ï¼ããã¯XSSç³»ã§ã¯ãªããCSRFæ´å©ç³»ã§ãããã¨å¼·ãæãã¾ããååãééã£ããªããCSSXSSã£ã¦ããããããï¼@importã®ãªã¯ã¨ã¹ããã¯ãã¹ãµã¤ãã§ãªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªãã¦ãããã§ããããã£ã¨ã
12/6追è¨ï¼
CSSXSSã«ã¦MIXIãæ»æããDEMOãããã¾ãããï¼å¯¾å¦æ¸ã¿ã®ããï¼ãCSRFç³»ã§ã®å¿ç¨ã®ããã§ãããã®ããã«ç°¡åã«ä½¿ãã¦ãã¾ãã®ã§ã¨ã¦ãæãã§ããããµã¼ãã¼å´ã®å¯¾å¿ã¯ã¢ãããã¯ãªãã®ããèãã¥ããã¨ããã§ãã
yamagataããã¡ã§ç¥ãã¾ãããä¸è¨ã®ãªã³ã¯ã¯ä¸åº¦å¯¾å¦æ¸ã¿ã«ãªã£ããã®ã®version2ã«ãªã£ã¦ãã¦çãã¦ããããã§ããå±éºãªã®ã§è¡ããªãã§ä¸ãããé ¼ã¿ã¾ãã(ãªã®ã§ãªã³ã¯ã¯ã¯ããã¾ãããããã®äººã ãè¡ã£ã¦ãã)
12/6追è¨çµãã
12/9追è¨ï¼
ãéè¦ãã§ããcleemyããã«ããæ¤è¨¼ã§åããã¨ããããã¾ãããUNICODEç³»åã¨ANSIç³»åã¨ã®ã¢ã¬ã«ã¡ããä¼¼ã¦ãããããææ³ãæã¡ã¾ãããå¼ç¨ããã¦é ãã¾ãã
- cleemy
- å¤å { ããã¢ã£ã½ãã§ããã{ ãå ¨ãç¡ãããã¹ãã¯èªã¿åºãã¾ããã§ããã ãã¨ãå°ãªãã¨ããã¼ã«ã«ã«ãããHTMLã§ã¯ã@import ãããã¼ã«ã«ã®ãã¡ã¤ã«ã cssTextã§èªã¿åºãã¦ãã¾ãã®ã§ãå§ç¸®ããzipãã¡ã¤ã«ã¨ãã¦HTMLãé å¸ãããããªå ´åã¨ãã ã¨ããã¼ã«ã«ã®ä»»æã®ãã¡ã¤ã«ãæãåãäºãå¯è½ã§ãããæããããã¡ã¤ã«ã®ãã¡ã¤ã«åãåãã£ã¦ãã®ã¨ããã¡ã¤ã«ã®ä¸ã« { ãããå¿ è¦ãããã¾ããã ãã¨HTMLã¡ã¼ã«ã¨ãããã°ããã§ãã
- ããããªãããè¨æ£ãã¾ããæ»æç¨HTMLãUTF-8ã§è¨è¿°ããã¦ã¦ @importå ãShift_JISã®å ´åã¯ã { ãå ¨ãç¡ãããã¹ãã§ããããããããããªã©ã® 7B, 7D ãå«ãæåãããã°èªã¿åºãã¦ãã¾ãã¾ãããShift_JISã§ãã¼ã¸ãåããããªãµã¤ãã¯ããã«ã¤ãããã§ã
- t_trace
- cleemyããã大å¤ãããã¨ããããã¾ãããããããæ°ã¥ãã¾ãããææãã¾ãã CMSã¯ãµãã¿ã¤ãºã«ã¼ã«å¤æ´ã§åé¿ãããã¨æã£ã¦ãã®ã«â¦â¦orz
å¼ç¨å ã¯ãTaiyo@hatenaããã®ã¨ããã§ããUnderconstruction by Taiyo@hatena (2005-12-04)
ã¤ããé§ç®ãããï¼å®ãæ¹æ³ã¯ãµã¼ãå´ã«ã¯ãªãããJavaScriptã®æ©æµãåãããWindowsã¦ã¼ã¶ã¯IEã使ã£ã¦ã¯ãããªããã¨ã決å®çã§ãã
12/9追è¨çµãã
以ä¸:12/10追è¨
addimportã@importã§ãªãã¦ãlinkè¦ç´ ã§åºæ¥ããããâ¦ã¨ã»ã»ãMS02-023 ã§å¯¾çãããã¯ãã® GM#004-IE (注ï¼ã¹ã¿ã¤ã«ã·ã¼ã以å¤ã§ãèªãã¦ãã®ã ã£ã)ã®ç³»ã ã£ãã®ããä»åã®CSSXSSã¯ããªãã»ã©ãååã®MS02-023ã§ã¯ãªã¢ã¼ããããã¼ã«ã«ã«ã ãæåºãåºæ¥ãªãããã«ãã¦ããã®ããããã¼ãã
<!-- saved from url=(0014)about:internet -->
<link id="oFile" rel="stylesheet" href="ãTARGETURLã" disabled>
<script language="jscript">
onload=function () {
alert(document.styleSheets.oFile.cssText || "Could not extract any text from file.");
}
</script>
以ä¸:2006/01/30追è¨
addimportã@importãlinkè¦ç´ 以å¤ã«xml-stylesheetãæ»æãã¯ã¿ã¼ã«ãªããã¨ãå¤æãã¦ãã¾ããhtmlã°ããã§ãªãæ¡å¼µåãxmlã®ãã¡ã¤ã«ããããã¨ãããã¨ã§ã以ä¸ã«ä¾ãã
ãããã«ãããæ ¹æ¬åå ã¯IEã§invalidãªã¹ã¿ã¤ã«ã·ã¼ããjavascriptãçããéãã¦èªã¿åºããä»çµã¿ãªã®ã§ãã©ã®æ»æãã¯ã¿ã¼ãç価ã§ãã
ã¾ããä¸é¨ã®ãã«ããã¤ãç³»ã³ã¼ãã®è¨èªã®å ´åã{ ã } ãåãé¤ããããªï¼Googleãã¹ã¯ãããã対å¿ãããããªï¼ããæ¹ã§ã¯ãµã¼ãå´ã®ã¯ã¼ã¯ã¢ã©ã¦ã³ãã«ã¯ãªããªããã¨ãããã£ã¦ãã¾ããã«ã¿ã«ãã®ããããããããªã©ãèãã¦ã¿ãã¨ããããããã¾ãããããã«ãµã¼ãå´å¯¾çã¯æ¥µãã¦å°é£ããã©ã¦ã¶å´ï¼IEï¼ã®å¯¾å¿ãä¸å¯æ¬ å¿ é ã§ãããã¨ãçµè«ä»ãããã¾ãã
追è¨çµãã
以ä¸:2006/01/30追è¨(ãã®2)
ä¸è¨ã¾ã§ã§ã¡ãã£ã¨é²è¡ä¸ä¸ç¢ºãã§ã¾ããè¨è¿°ãããããã¯ããã®ã§ã¯ã¨å·ãæ±ãããã¦ããã¾ããIEã®JavaScript(=JscriptâActiveScript)ãåç´ã«åã£ã¦ãã¦ãé²è¡ã«ã¯ãªã£ã¦ããªãå¯è½æ§ãããããã§ããå¥ãªè¨ãæ¹ãããã°åç´ã«ãJavaScript ã® same origin ã»ãã¥ãªãã£ã®ç©´ã¨ã¯è¨ãåããªãã¨ãããã¨ã«ãªãã¾ãã確èªãå¿ è¦ããç¥ãã¾ããã
è¯ãè¦ãããCSSXSS(ãã®ååèªä½ããã¨ã®æ¬è³ªãæ²ãã¦ããã¨æãããã®ã§ãã)ã®è§£èª¬ã§ã¯ã JavaScript ã§ãæªäººãç½ ã¨ãã¦ç¨æãããµã¤ãã®ãã¼ã¸ã«ã¦ã¼ã¶ã訪åããéã«ãæªæã®ãµã¤ãã®èªãã¡ã¤ã³ã®document.styleSheets(0).imports(0).cssTextãéãã¦ã被害è ã¿ã¼ã²ããã®ãµã¤ãã®ï¼ãã°ã¤ã³ä¸ããããã¯Basicèªè¨¼ä¸ãªã©ã§ã®ã¿è¦ããã¨ãåºæ¥ããæ¬æ¥ç§å¯ã§ããã¹ãï¼æ å ±ãæãåãã¨ãããã®ã§ããç½ ãµã¤ããã¼ã¸ã® DOMã« IEã®ã¹ã¿ã¤ã«ã·ã¼ãèªã¿è¾¼ã¿ã®æ¬ é¥ãæªç¨ãã¦ãã¹ã¿ã¤ã«ã·ã¼ã以å¤ã®æ å ±ããã¨ãã°ã(X)HTMLåºåãJSãã¡ã¤ã«ãXMLãã¡ã¤ã«çããã©ã¦ã¶ã® DOM ã«èç©ã§ããããã§ãããã®èç©ã®è¡çºãã®ãã®ã¯ãã¹ã¿ã¤ã«ã·ã¼ãèªã¿è¾¼ã¿ã®æ©è½ã§ããããjavascriptããªãã«ãã¦ãã¦ãå®è¡ããã¾ããä½è«ã§ããããããããä¸éãæã£ã¦ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®ããã«ã¿ã¼ã²ããã®è¢«å®³è ãã¼ã¸ã«èªç±ã«ã¹ã¯ãªãããHTMLè¦ç´ ã»å±æ§ãæ¿å ¥ããããã§ã¯ããã¾ããã被害è ãã¼ã¸ããã¹ã¿ã¤ã«ã·ã¼ãã¨ãã¦æ å ±ãçãã§ããã ããªã®ã§ããï¼è¢«å®³è ãµã¤ãã«ä½ãæ¿å ¥ããªãã¨ãå®éã«æ å ±ãæãåããã¨ãåºæ¥ã in the wild 㪠å®è¨¼ã³ã¼ããç§ã¯ IPAã«å±ãæ¸ã¿ã§ãåä½ã確èªãããåçããã¦ãã¾ãããã¡ãããä¾ãã°è¢«å®³è ãµã¤ãã®æ¤ç´¢ç»é¢çããç¹å®ç¬¦å·ãã¤ã£ãããããªç¹æ®ãªURLãå«ãç½ ãã¼ã¸ã®ã»ããæ»æè ã¯ä½æã楽ãã³ã§ãããããã©ãå¿ ããããã®ãããªæ¿å ¥ã¯å¿ é ã§ã¯ããã¾ããã)ãã®ã¹ã¿ã¤ã«ã·ã¼ãã®èªã¿è¾¼ã¿æç¹ã§ã¯ãç¹°ãè¿ãã«ãªãã¾ãããJavaScriptã¯å¿ è¦ã§ã¯ããã¾ããã
ãã¦ã DOM ã¨è¨ãã°ãæããJavaScriptãé£æ³ãããã¨ãå¤ããããã¾ãããã§ããã DOM ã®ãã³ããªã³ã°ã§ã¯ãå¿ ããã JavaScript ãå¿ é ã¨ããããã§ã¯ããã¾ããã ä¸ä¾ã§ãããJavaScript ã使ãã Java ã¢ãã¬ããçµç±ã§ãã©ã¦ã¶ã® DOMã« ã¢ã¯ã»ã¹å¯è½ã§ããã¨èãåãã ãã¨ãããã¾ãããã㯠Java ã¢ãã¬ããã®èå¼±æ§ã§ã¯ãªãä»æ§ã§ããã¨ãããã¨ã¨ä¼ºã£ã¦ãã¾ãã
ç§ã¯ããã°ã©ãã³ã°ã®ç¥èã¯çç¡ã«çããã®ã§ãªãã¨ã確èªã®ããããããã¾ããããã²ãã£ã¨ããã次ã®ãããªãã¨ãèµ·ããå¾ãã®ã§ã¯ãªãã§ããããã
- æªæãããã¼ã¸ãä½æã被害è ãã¼ã¸ããã¹ã¿ã¤ã«ã·ã¼ãã§æ å ±ãæãåãã
- æªæãããµã¤ãã®èªãã¡ã¤ã³ã®ç½ ãã¼ã¸é²è¦§ä¸ã®ãã©ã¦ã¶ã® DOM ããJava ã¢ãã¬ããã§å¶å¾¡ãã¦ãdocument.styleSheets(0).imports(0).cssText ç¸å½ãèªã¿åãã
以ä¸ã¯å®é¨ããã¦ãã¾ããããJava ã¢ãã¬ããã®ä»æ§ã確èªãã¦ãã¾ããã(ç¹ã«MS謹製ï¼ãæ°ã«ãªãã¨ããã§ããã)
ç ãè©°ããã¨ãJavaScriptã ããªãã«ãã¦ã® IE ã§å®å¿ã§ããã®ãã¨ããã¨ããã§ã¯ãªããããããªããã¨ãããã¨ã«ãªãã¾ããæ¬ç¨¿ã¯å¤å°ãªãã¨ã FUD æ°å³ã§ããããããããJavaScriptãªããªãã°ãé常ã¯ActiveX ã³ã³ããã¼ã«ãåãã®ãæ£è§£ã§ãããããâ¦èå©å¿ã¾ã§ãè¦ç¥ãã¬ãµã¤ããIEã§è¦ã«è¡ããªããå®ç³éããã¤ã³ã¿ã¼ãããã¾ã¼ã³ã®ã»ãã¥ãªãã£ã¬ãã«ããé«ãã«ãã¦ããã°å®ãããã¨æãã¾ããè¯ã使ããµã¤ãã¯ä¿¡é ¼æ¸ã¿ãµã¤ãã¾ã¼ã³ã«è¿½å ããä¸ã§ãä¿¡é ¼æ¸ã¿ãµã¤ãã¾ã¼ã³ã®ã»ãã¥ãªãã£è¨å®ã¯ãä¸ãã«ãããã§å®å¿ã§ãããã®å¯¾å¦æ¹æ³ã¯ãã¤ã¯ãã½ãã社ã«ããæå±ã¨åãã§ãã御åèã¾ã§ã«ãªã½ã¼ã¹ã¸ã®ãã¤ã³ã¿ããâãã©ã¦ã¸ã³ã°ã¨é»åã¡ã¼ã«ã®å®å ¨æ§ãå¼·åãã::Microsoft Security ãã¼ã
ã¾ããJavaScript ã® same origin ã»ãã¥ãªãã£ã®ç©´ãªã®ãã©ãããèªä¿¡ãæã¦ã¾ããã®ã§ã©ãã御æ示é¡ãã¾ãï¼èè ãã¾ããå°ãªãã¨ããJavaScriptã¯ãä»åã®å ´åã§ã¯ãç½ ãã¼ã¸ã®èªãã¡ã¤ã³ããããã£ã¦ããªãã¯ãã§ãã
追è¨çµããâ ã¯ã¦ãªæ¤ç´¢ã®ã¦ã§ãæ¤ç´¢æ©è½è¿½å é¨åã«ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°èå¼±æ§
ã¦ã§ãæ¤ç´¢æ©è½è¿½å ã追å ãããã¯ã¦ãªæ¤ç´¢ã«ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°èå¼±æ§ãããã¾ãããæ¢ã«2005å¹´12æ03æ¥ 11:04ã¾ã§ã«ã¯ä¿®æ£ãå®äºãã¦ãã¾ããå ±åã¯05/12/02 21:45ãåææ¥ãªã®ã«ãç²ãæ§ã§ããï¼ã¯ã¦ãªã
http://search.hatena.ne.jp/websearch?word=%22%3E%3Ciframe%2Fsrc%3D%27http%3A%2F%2Fwww.google.com%27%3E%3Cq%2F%22
ã¨ãããããªåç´ãªãã®ã
ãããããexpres/**/sionãã¿ã§ãã¯ã¦ãªãèå¼±ã§ãããã¨ããããªãã é·æéIPã¢ã³ãªã¼ãã¢ãã«ã§ãã£ãæã«ç¥ã£ãã¨ãã«ã¯å·ãæ±ãããããã®ã§ããä¸ææã«ç¡çããIPæ¥ç¶ç°å¢ãæ¢ãã¦ããã¦ã¦å ±åãããã®ã§ãããå¾ã«ç¢ºèªãã¾ãããããã®ã¨ããã¯ã¦ãªãããè¿ éã«ä¿®æ£ãªãã£ã¦ããã§ã§ããã
â IEãOperaãFirefoxãã«é¢ãããã¨ããCSSé©ç¨ã®å®è£ ã®å·®ï¼ãã¿ï¼
ãã¿ã§ãããã
IEã«ã ããµã¤ãã®ã³ã³ãã³ããè¦ãã¦ãããªããï¼ã¨ããä»æãã®ä¸ã§æãç°¡åãªã®ã¯ä½ã ãããã¨ã¤ã¿ãºã©ã§èãããã¨ãããã¾ããã¯ã¦ãªãã¤ã¢ãªã¼ã§è©¦ãããã£ãã®ã§JavaScriptããCGIããã¯ä½¿ãã¾ããããªãã°CSSã ãã§æ¯ãåããã°è¯ãã¨ãããããªãã§ãããè²ã ãã¯ããã¯ãããããã¨ã¯æãã¾ããããã¯ä¸çºã以ä¸ã®ããã«ã¹ãããªãããã®ãã¨ã
<style>
* {
display : inline ;
display = none ;
}
</style>
<p>ã</p>
<p>ã</p>
<p>ã</p>
<p>ã</p>
<p>ã</p>
ããã¨ãããããã£ã¨ãã®å¤ã¨ã®éã®ã³ãã³(:)ã®æ¿ããã«ã¤ã³ã¼ã«(=)ã使ãã¾ãã¨ãIEã§ã¯æå¹ãªã®ã§ãããç´ æ´ãããHackã§ããï¼ä¸ã®ä¾ã§ã¯ãIEã§ã¯ãã£ãããå ¨ã¦ã«å¯¾ãã¦displayãinlineã«ããå¾ãnoneã«ä¸æ¸ããã¦è¦ããªããã¦ãã¾ããå®éã«è©¦ãã¨æã£ãã¨ããä½ãè¦ããªããªã£ã¦ã¤ã¿ãºã©æåãï¼ã¨å¬ãããªã£ãã®ã§ããâ¦
ããã¨ãOperaã§ã¯æå¾ éããdisplayã¯inlineã«ãªãã¾ããæ®éã®æ®µè½ã®è¡¨ç¤ºã§ãããããã¯ãåãã¡ãã£ã¦ãinlineã§ãããããããããã横ä¸åã«ãªãã³ã¾ããã¨ãããã§ãããFirefoxã§ã¯å ¨ãäºæ³ããªãã£ããã¨ãèµ·ããã¾ããã大ä½ã«ããã¦ä»¥ä¸ã®ããã«è¡¨ç¤ºããã¾ãã
* { display : inline ; display = none ; } ã ã ã ã ã
ãããã¹ã¿ã¤ã«ã表示ããããã¨ã¯ï¼ï¼ï¼
ãããã¦ããã£ã¨æããããã¨ãã表示ãããé¨å(ä¸è¡)ãã³ãã¼ãã¦ã¡ã¢å¸³ã«è²¼ãä»ãããã¹ã¿ã¤ã«é¨åã¯æ¶ãã¦ãã¾ã£ã¦ãã ã ã ã ã ã¯æ¹è¡ããã¦ãã¾ããã以ä¸ã®ãããªæãã
ã ã ã ã ã
ããããã©ãããdisplay:inline; ãå¹ãã¦ããªãæããªã®ã§ããâ¦ã¯ã¦ï¼ã§ãããã²ãã£ã¨ãããFirefoxã®ã»ããæ£ããæåã ã£ãããã¾ããï¼ãããã¡ã¢å¸³ã«è²¼ãä»ãããã®ã¨ããã¯å¥ã«ãã¦ãstyleè¦ç´ ã®ä¸èº«ãdisplay:inlineãå¹ãã¦ãã¾ãã®ãæ¬æ¥ã ã£ãããã¾ãï¼æãã¦ã¨ã©ã¤äººã
ã¨ããããã§IEã¸ã®ãã¬ãã£ããã£ã³ãã¼ã³ã¯ä¸æ¢ã(ããã¾ã§ãã¿ã§ãã)
ãã®ã話ããªãã°ããããã ããã¨ãã§ããã¦é ãã¾ãããèå¯ãã¤ãã¦ãã¾ããå ç«¥å°é .456(20051206)
â ã¹ã¿ã¤ã«ã·ã¼ãã§ããã¹ãæ±ãå¹æ
ããã¹ãæ±ã - 186(000)ãæè¦ãè¦åºãã®ããã¹ããé ãã¤ã¤(èæ¯)ç»åã¨ãã§ãªãã¨ããã¡ãããã®ï¼ãã htmlã
ã¨ããsmoking186ããã®å¾¡æè¦ã¯ãå°¤ãããã®ããã¹ãæ±ãã¯ãã²ãã¨ãã¦Using Background-Image to Replace Text - Stopdesignã«ããªãè¿ãã¨æã£ã¦ãã¾ããUsing Background-Image to Replace Text ã§ã¯spanè¦ç´ ã®ä¸èº«ãspan {display:none;}ã¨ãã¦è¦ããªããã¦ãã¾ããæ¿ããã«èæ¯ç»åãããã«ã¡ã¯ãã¨ããæããªã®ã§ãããããã¹ãæ±ãã§ã¯ãspan {display:none;}ã¯ããã¶ãï¼ããªãã¦ã大ä¸å¤«ä½æ¦ã§ãããããæ°ã«ãªããã¨ãããã®ã§ããã¹ã¯ãªã¼ã³ãªã¼ãã¼ã§é²è¦§ããã¨ã©ããªãã®ãã¨ããè¦ç¹ã§ãããã®è¾ºããããªããªãã®ã§ããããIBMã®ãªã¼ãã¼ã ã¨IEã®ã¨ã³ã¸ã³ã§è§£éããå¾ã«çºå£°ãã¦ãããä»çµã¿ã ã£ããã¨æãã®ã§ããï¼ééããªãããããªããï¼ãããªãã¨{display:none;}ãªè¦åºãã®ããã¹ãã¯ãã¿ããã¨èªã¾ãã¾ãããç¡è«èæ¯ç»åãç¡è¦ãããã¡ãããã¨ãããã¨ã¯Hnè¦ç´ ã®è¦åºãã®ãªãã³ã³ãã³ããæä¾ãã¦ãããã¨ã«ãªãã¾ããããã¯å°ã£ãã¡ãããªã®ã§ãããã¨ããããã§Using Background-Image to Replace Text ã¯ãã¯çã«ã¯ã¡ãã£ã¨æè¦ãä¿çãããææ³ãªã®ã§ããä¸æ¹ãããã¹ãæ±ãã§ã¯ã{display:none;}ã¯ãããªãã®ã§ã¹ã¯ãªã¼ã³ãªã¼ãã«ã¯åªããã§ããããå°ãªãã¨ããèæ¯ç»åã¯ç¡è¦ããããã¨ã§ãããããé©å½ã«æ±ãã¦ééãã¦ããèæ¯ç»åãããã¹ãã«ãªã¼ãã¼ã¬ã¤ããã ããªã®ã§ããããã(ã¦ã¼ã¶ã¹ã¿ã¤ã«ã·ã¼ãã使ã£ãå ´åã«ã©ããªãã®ãã¡ãã£ã¨ãããã¾ããã大ä¸å¤«ãªã®ããªï¼)<h2><span></span>Worn Text</h2>
ã¨ç©ºspanãå
¥ã£ã¦æ°æã¡æªã
ã¨ããã§ç©ºspanãå
¥ã£ã¦æ°æã¡æªãã¨ããã話ã§ããã£ããImage Replacement?No Span - CSS Playã¨ããæ¹è¯åããã£ã¦ã空spanã¯ä½¿ã£ã¦ããªããã
ãªæãã«ã¹ã¿ã¤ã«ãå®ç¾©ãã¦ãã¾ã系統ãåé¡ã¯ã{height: 0;}ãªããã¹ãï¼ãããã£ã¦æ¶ãããã§ããï¼ãIBMã®ãªã¼ããï¼ä»ã®ã¹ã¯ãªã¼ã³ãªã¼ããï¼ãã¡ãã¨èªãã§ãããã®ã§ããããï¼ã¨ããå¿é
ã ãã«ãªãã¾ããããããããããã¹ãæ±ããªã大ä¸å¤«ãªã®ããªï¼{height: 0;}ã§é ãå¿
è¦ããªããããããããTantek's hack ãã²ãã£ã¨ããããã¶ããã¯ã¦ãªã®ã¹ã¿ã¤ã«ã·ã¼ãã§ã¯ä½¿ããªãã®ããªï¼XSS対çã§ãªãã§ãããã§ãããã¯ã¹ã©ãã·ã¥æ®ºãã¾ãã£ã¦ã¾ããããã¯ã¦ãã¦ã
<h3 id="ex1">Example Text for the Image Replacement</h3>
å®éã«ã³ã¼ãæ¸ãã¦ç¢ºèªãã¦ããããã§ã¯ããã¾ããã®ã§ã¨ã¨ã«ã²ã³ã§ãããã¿ã¾ããï¼smoking186ãããçããã