2007-05-01ãã1ã¶æéã®è¨äºä¸è¦§
å¤ã£ã½ãé½æ°ãªã®ã§ãã¼ãªã¼ç³»ãæãããªãã¾ããã ã¢ã»ãã©ã¨ã¢ãã¨ã®ã¸ã¥ã¬ï¼å·¦ï¼ã¯ãã¢ã»ãã©ã®é ¸å³ã¨ã¢ãã¨ã®é£æã涼ããã¦ãã¾ãã¾ããããã£ã©ã¡ã«ã®ãªãã¨ãï¼å¿ããâ¦ï¼ï¼å³ï¼ã¯ããã£ã©ã¡ã«ã®è¦ã¿ãããã¦ã¦å¤§äººãªæãã§ãç§çã«ã¯ä»å4種é¡ã®ä¸ã§â¦
Top 10 2007 - OWASPããï¼bunããã¨ãçµç±ï¼ 1.Cross Site Scripting (XSS) ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° 2.Injection Flaws 主ã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ 3.Malicious File Execution Remote File Inclusion (RFI) 4.Insecure Direct Object Reference ãã¡ã¤â¦
Top 15 free SQL Injection Scanners - Security-Hacks.com ãã¨ã§è©¦ããããã15ã ãã©é ä½ãããããããªããä¸ãã1ä½ï¼ SQLIer Sqlbftools SQL Injection Brute-forcer (.tar.gz) SQLBrute (.py) BobCat sqlmap: a blind SQL injection tool Absinthe ::â¦
æ¨æ¥æ¸ããããããæå¦æ¥è¨ - 御社ã®Webãµã¤ãã«XSS (ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°)ã®èå¼±æ§ãããã¨ä½ãåé¡ãªã®ããããããªãã§æ¥ã«ãXSSãã¿ãªã®ãã¨ãããã¨ããã¾ã£ã¡ãããããHiromitsuTakagiãããæ°ã«ãªãããããç§ãçãç©ã®è©±æãã§ã»ãã¥ãªâ¦
æè¡ã«æãããªã人ã§ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ããã¼ã¿ãã¼ã¹ããããããããã¨ãããã¨ã§ãããã«ãããã¯ã¤ã±ãã¤ï¼ãã¨åå¿ãã人ãå¤ãããã«æãã¾ããããããXSSã¯ã©ãã軽ãè¦ããã¦ããæ°ããã¦ãã¾ããXSS (ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°)ã£ã¦â¦
å£ç¯éå®ã®ããã¹ãå¤ããã¹ã§ãã京é½é§ ããæ°å¹¹ç·ã§å¸°ãã¨ãã«ããã£ããé§ ã®ãã¼ã ã§è²·ã£ã¦ãã¾ãã¾ãããç®ã®é¨åãããã³é¤ ã£ã½ãã¦ãããããã§ãããæ®éã®ããã¹å¥½ãã«ã¯ç©è¶³ããªãããã ããããã°ãæã®ããã¹ã£ã¦ãã£ã¨ãããã®å³ãæ¿ãã£ãæ°ãâ¦
ã¨ããããã®ã¿ãªããã®ãããã§ããã®é£ããå«ãçã®è¸è½äººå¾¡ç¨éãåç£ã©ã³ãã³ã°ï¼2007/03/29æ¾éï¼ã§ç¬¬16ä½ã§å¤§ææ¼£ãããæã£ã¦ãããåç£ã§ããæ¾éãè¦ã¦æ³¨æããã¨ãããç´1ã¶æåå¾ ã¡ã§å±ãã¾ããããã¤ãæ±é¨ãã¬ã¹ãã³ã®å°æ¹èåã§ãã¢ã¤ã¢ã¯ãåµâ¦
ãããæå¦æ¥è¨ - FizzBuzzã®ç¶ãã ããããèãããã©ããããéçã®64bytesã§ãããååã®ã¯80bytesã ã£ãã®ã§ã16bytesç縮ã perl -le'print(($_%3?"":"Fizz").($_%5?"":"Buzz")||$_)for 1..100'ãã¨ã§ã"Fizz"ã"Buzz"ã®"ãåããã®ãç¥ã£ããã©ãããâ¦
ãã«ãã¡ãã£ã¢æ å ±ãã¤ãã£ã³ã°ç 究ä¼(MIH)ã¯ï¼ããã¹ãã»é³ã»ç»åã»åç»çï¼ãã«ãã¡ãã£ã¢æ å ±ã«å¯¾ããé»åéããæè¡ãã¹ãã¬ãã°ã©ãã£ï¼åã³ãããã«é¢ããæ å ±çè«ã»ã»ãã¥ãªãã£æè¡ã»å¿ç¨ã·ã¹ãã çã«å¯¾ãã¦ï¼å¹ åºãæè¦äº¤æãã§ããå ´ãæä¾ãããâ¦
ãªããæµè¡ã£ã¦ããããã 1ãã100ã¾ã§ã®æ°ãããªã³ãããããã°ã©ã ãæ¸ãããã ã3ã®åæ°ã®ã¨ãã¯æ°ã®ä»£ããã«ï½¢Fizzï½£ã¨ã5ã®åæ°ã®ã¨ãã¯ï½¢Buzzï½£ã¨ããªã³ããã3ã¨5両æ¹ã®åæ°ã®å ´åã«ã¯ï½¢FizzBuzzï½£ã¨ããªã³ããããã¨ã å ãã¿ã¯ãã©ããã¦ããã°ã©ãã«ã»â¦
æ¯ã®æ¥ã¯å®¶æã§ã¹ã³ã¼ã³ä½ã£ã¦ãåºè¿ãããã©ã¤ãã«ã¼ãã¨ãããããã£ã·ãã§ãã
ã¿ã¤ãã§ã¹ãã£ãã«Thai Festival ãããã¨ãï¼å¹´ãããæ¯å¹´è¡ã£ã¦ããæä¾è¡äºã¨åãã¦ãã¾ããã»ã¨ãã©ã飯ã¨é£æç®å½ã¦ãã¾ãæ¥å¹´ãGWæãã®é±ãããã«ããã«éããªãã ä½ã¯ã¨ãããã«ãªãã³ã¬ã¤ï¼è¹ã§ãé¶ã¨ãã¹ã¼ãã§çããã飯ãããã¦ã½ã¼ã¹ã®æ¨ã¿ãâ¦
ç§ãã»ãã¥ãªãã£ãç¥ããªã人ãã¡ãä½ã¨ããããã¨æã£ãã¨ãã以ä¸ã®ãã¨ã«æ°ãä»ãã¦æããããã«ãã¦ãã¾ãã ã»ãã¥ãªãã£ã®æè¡ã§ã¯ãªããã»ãã¥ãªãã£ã®åï¼ãªãã©ã·ï¼ã身ã«ä»ãã¦ããã ã»ãã¥ãªãã£ããªãç ´ãããã®ããæããèªåã対çå´ã«ããâ¦
Penetration Testing and Network Defense (Networking Technology)ä½è : Andrew Whitaker,Daniel P. Newmanåºç社/ã¡ã¼ã«ã¼: Cisco Pressçºå£²æ¥: 2005/10/31ã¡ãã£ã¢: ãã¼ãã¼ããã¯ãã®ååãå«ãããã° (1件) ãè¦ã主ã«ãããã¯ã¼ã¯ç³»ã®ãããã¬ã¼ã·ã§â¦
ãã®æ°æ¥ã®æãã®ããããä¸æ°ã«è²ã£ã¦ã«ãã³ã©ãã¨ãç«ã¡ãã¦ãã¾ãã¾ãããã§ãããã®è±ãé£ããããããä»ã«ãå°æ¾èãã¨ãç«ã¡ãã¦ããã
ã¢ã¡ã¼ãçµå¶âã²ã¨ãã²ã¨ãã®ç¤¾å¡ã主役ä½è : 稲çå夫åºç社/ã¡ã¼ã«ã¼: æ¥æ¬çµæ¸æ°è社çºå£²æ¥: 2006/09/01ã¡ãã£ã¢: åè¡æ¬è³¼å ¥: 6人 ã¯ãªãã¯: 159åãã®ååãå«ãããã° (83件) ãè¦ã京ã»ã©ã®ç¨²çå夫æ°ã説ãããã¢ã¡ã¼ãçµå¶ãã¨ããçµå¶ç®¡çææ³ã®æâ¦
次ã¯ActiveXã®ããã§ããã·ãªã¼ãºåãã¦ã¾ãããä¸çºç®ã¯ãPowerPointViewer.ocx 3.1 multiple methods DoS MoAxB - Month of ActiveX Bug