2015-10-01ãã1ã¶æéã®è¨äºä¸è¦§
å æ¥ãPaX Teamãå ¬è¡¨ããROPï¼Return-oriented Programmingï¼æ¤ç¥ææ³RAPã«ã¤ãã¦ã¾ã¨ãã¦ã¿ãã RAP: RIP ROP (H2HC 2015) ç¨èªã«éè¤ãããã¾ãããããããè«æã§ã¯Return Address Protectionããã³Indirect Control Transfer Protectionã®äºã¤ã®ææ³ãâ¦
Word 2013ã使ããVBAãã¯ãã§é»åãèµ·åããWordææ¸ãä½æããæ¹æ³ã®ã¡ã¢ã ã¾ãããªãã·ã§ã³ã®ããªãã³ã®ã¦ã¼ã¶ã¼è¨å®ãã§ãéçºãã¿ãã表示ããããã«ãã¦ããã 次ã«ãé©å½ãªWordææ¸ãä½æãããéçºãâãVisual Basicããé¸æããã ããã¦ããProjeâ¦
ä¸éè æ»æã®ãã¨ã§ã®Cookie Injectionã«ããHTTPSã®çè´ã»ãã¤ã¸ã£ãã¯ã«ã¤ãã¦ã次ã®ãããªã¢ãã¦ã³ã¹ãåºã¦ããã Vulnerability Note VU#804060 - Cookies set via HTTP requests may be used to bypass HTTPS and reveal private information JVNVU#929â¦