ãã¹ããããã¢ããã¼ã·ã§ã³
注æ
æ¬ç¨¿ã¯@kyon_mmã®é ãããããã®ãããã¹ãã¨ã³ã¸ãã¢ã®é ãããããã®ãã¯ä¸æã§ããçµé¨è«ã§ãã
ã¢ããã¼ã·ã§ã³
ãã¹ãããã¦ããã¨ãã®ã¢ããã¼ã·ã§ã³ã¯ããã¤ããããããã«ãã£ã¦ãã£ã¦ãããã¨ãããã¶ãã¨éãã åºæ¬çã«åããã¹ãããã¦ããã¨ãã¯ã対象ãã¶ã£ãããããã対象ã楽ãããã¨ããããã対象ãç¥ããã¨ããããããã®3ã¤ã§ããã©ããã«åã£ã¦ãããã¹ãæ¦ç¥ã¯åã£ã製åãåºãããã¨ãããã¨ã«ä»ãªããªãã®ã§ãPOã«ç¢ºèªããå¿ è¦ãããããèªåã®ãã¹ãæ¦ç¥ããã¡ãªå ´åããããããªã
ã¶ã£ããã
åºæ¬çã«ãã®å¯¾è±¡ãã¯ã©ãã·ã¥ããããã¨ã«éä¸ãã¾ããã©ããã£ãããã®ã½ããã¦ã§ã¢ã¯ä¾å¤ãã¯ãã¦çµäºããã®ããã©ããã£ããæ£å¸¸èµ·åããªããªãã®ããã©ããã£ããæ£å¸¸ã«çµäºããªãã®ããã©ããã£ããã¬ã¹ãã³ã¹ãããã£ã¦ããªããªãã®ãã
ã§ãããããã®ã¯æå¤ã«æéãããã£ãããã¾ããã¨ãããã¨ã§æ®æ®µãããã¼ã«ãã¤ãã£ã¦ããã¨ããã§ãã ãã¬ã¼ã ã¯ã¼ã¯ãã¤ãã£ã¦ãããªããç¹å®ã®ã¹ãããããBNFããæ§ã ãªã³ã¼ããçæãããããªãã¼ã«ãã¤ãã£ã¦ããã¾ãããããã®ã®æ°åã§åããªãã±ã¼ã¹ãåºãããã¾ãã楽ããã§ããHTTPéä¿¡ãªããã¡ã¸ã³ã°çã«å¯¾è±¡ã®ãã©ã¡ã¼ã¿é¨åãããããå¤åã§ãããããªãã¼ã«ãã¤ãã£ã¦ããã¾ãããããã¤ããªãããã®æ¥½ãããããããã ãããµã¼ãã¼ç³»ã®ã³ãã³ããOSç³»ã®ã³ãã³ãé¡ãçµã¿åããããããªã¹ã¯ãªããçæãã¼ã«ãã¤ãã£ã¦ããã¾ããããã ãããä½ããäºæãã¦ããªãã¦ã½ããã¦ã§ã¢ãã¨ã©ã¼ãã¯ãã¾ãã 楽ããã§ãããã²ãã¯ã£ã
楽ãããã¨ãã
対象ã®ã½ããã¦ã§ã¢ã使ãäºã§ã©ããã£ãã楽ããäºãåºæ¥ããããããããã£ããã¨ããããããã£ã¦ãããã¨ã試ãã¾ããããããããå®ç¾ã§ããªããããããªãããæå¤ãªä½¿ãæ¹ãçºè¦ãããããããªãã§ããããã®å ´åã«ã©ããªåä½ããããã¯ã¾ã ããããªãããããã¾ããã
大åãªã®ã¯ããã®ã½ããã¦ã§ã¢ã使ã£ã¦ä½ã楽ããã¨ãçç£æ§ããããã¨ããèªåã®ãªã«ãããããããããªå¯è½æ§ãæ¢ããã¨ãããã¨ã§ããã ã¾ãããã¨æã£ã¦ãã£ã¦ã¿ãªï¼ã£ã¦è¨ããã¦èªãã ããã£ããããå°èª¬ã¨ãã²ã¼ã ã¨ãããã¾ãããããããªæãã§ãããã¨ãå¾ æã®ã½ããã¦ã§ã¢ãåºãã¨ãã¨ãã§ããããã¯ã¦ãªããã¯ãã¼ã¯ã¨ãTwitterã¨ãã§ããã¹ããããwãããã¯ãããwãã¨ãè¨ããã¡ãã£ã¦ããæãã®ãã¤ã§ããããããªæãã§ãã®ã½ããã¦ã§ã¢ã楽ãããã¨ãã¾ããããããããã¨ä½¿ããã¨ãããããã¦æå¤ã«ä½¿ããªãé¨åãããã£ãããã¾ããã¬ãã«ãªãããªãããã«ã¯ããããã®å¤§åã§ããã
対象ãç¥ããã¨ãã
ããã¯ã©ããªãã®ãªãã ãããï¼ã¨å¯¾è±¡ã®ã½ããã¦ã§ã¢ã®ã¦ã¼ã¶ã¼ã¬ã¤ããä»æ§æ¸ãæ¸ãã¤ããã§ãã¹ããã¾ããå ´åã«ãã£ã¦ã¯ã³ã¼ããè¦ããã¨ããJVMãªã©ã®å®è¡ç°å¢ã®ç£è¦ããã¾ãããã®ã½ããã¦ã§ã¢ã¯ã©ããã£ã¦åãã¦ããã®ãï¼ä½ãæä¾ãã¦ããã®ãï¼è¨è¨ææ³ã¯ãªã«ãï¼ã©ãã§ãªãåãã¦ãã©ãã§ãªãåããªãã®ãï¼ãªã©ã§ãã
楽ãããã¨ããã¨ãã¨éãã®ã¯ã楽ãããã¨ãã¡ã¤ã³ãªã®ã§ã¯ãªãã¦å¯¾è±¡ãããæ´çç«ã¦ã¦ç¥ããã¨ããã¨ããã§ããããã¯ãªãã¼ã¹ã¨ã³ã¸ãã¢ãªã³ã°ãããããã®æ°æã¡ã§ãã対象ã®ã½ããã¦ã§ã¢ãå¯è½ãªãã¨ããããã°ãããã妥å½ã§ãããã©ãããã¾ãå¤æãããã¨ãå¯è½ã§ãã楽ããã¨ãå£ãããã ãã ã¨ããµãã¼ãå¤ã§ãã£ã¦è¨ããããããã¾ã§ã§ãããªã®ã§ããã®ã½ããã¦ã§ã¢èªä½ãä½ã§ããããç¥ãã¨ãããã¨ãããã大åãªã¢ããã¼ã·ã§ã³ã§ãã
è足
ã½ããã¦ã§ã¢ãã¶ã£å£ãã¨ãã¯åºæ¬çã«ã¸ã´ã£ã¼ã¡ã¿ã«ããªã«ã¿ããã£ãããã¯ãèãã¦ãã¾ãããã³ã·ã§ã³ä¸ããã
åèæ¸ç±
ä¸ã®æ¸ç±ãã¡ã®å½±é¿ã大ãããã¨ã¯è¨ãã¾ã§ããªã
Exploiting Software: How to Break Code (Addison-Wesley Software Security Series)
- ä½è : Greg McGraw, Gary Hoglund
- åºç社/ã¡ã¼ã«ã¼: Addison-Wesley Professional
- çºå£²æ¥: 2004/02/17
- ã¡ãã£ã¢: ãã¼ãã¼ããã¯
- ãã®ååãå«ãããã° (2件) ãè¦ã
How to Break Software: A Practical Guide to Testing
- ä½è : James A. Whittaker
- åºç社/ã¡ã¼ã«ã¼: Addison Wesley
- çºå£²æ¥: 2002/05/09
- ã¡ãã£ã¢: ãã¼ãã¼ããã¯
- ãã®ååãå«ãããã°ãè¦ã
How to Break Software: AND Software Engineering: A Practical Guide to Testing
- ä½è : Whittaker,Sommerville
- åºç社/ã¡ã¼ã«ã¼: Addison Wesley
- çºå£²æ¥: 2004/06/17
- ã¡ãã£ã¢: ãã¼ãã«ãã¼
- ãã®ååãå«ãããã°ãè¦ã
- ä½è : Chris Goward
- åºç社/ã¡ã¼ã«ã¼: Sybex
- çºå£²æ¥: 2012/12/21
- ã¡ãã£ã¢: Kindleç
- ãã®ååãå«ãããã°ãè¦ã
Exploratory Software Testing: Tips, Tricks, Tours, and Techniques to Guide Test Design
- ä½è : James A. Whittaker
- åºç社/ã¡ã¼ã«ã¼: Addison-Wesley Professional
- çºå£²æ¥: 2009/08/25
- ã¡ãã£ã¢: Kindleç
- ãã®ååãå«ãããã°ãè¦ã
Explore It!: Reduce Risk and Increase Confidence with Exploratory Testing
- ä½è : Elisabeth Hendrickson
- åºç社/ã¡ã¼ã«ã¼: Pragmatic Bookshelf
- çºå£²æ¥: 2014/02/04
- ã¡ãã£ã¢: Kindleç
- ãã®ååãå«ãããã°ãè¦ã