CSRF, HTML Form Protocol Attack, Cross-protocol scripting attackã«ã¤ãã¦
2015/4/16(æ¨)ï¼ãã¼ã¸ã®ä¸çªä¸ã«è¿½è¨ãè¨è¿°ãã¾ããã ãã®æããªãã¨ããã£ã³ãã¨ããã»ãã¥ãªãã£ã®ã¤ãã³ãã«åå ããæãã¢ã¦ããããã大äºãã¨è¨ãããã®ãæãåºãã¾ããã ã§ããæ®éèªåã®è¦ã¤ããç¥èã¯å¾ç大äºã«æ±ãã¦ããããããã ã¨æãã¾ãã ããã§ä»åã¯ãããã£ãä½ãããã¼ããªããã®ãæ¨ã¦ãã¹ããæºãè¾¼ãã è²ããªXSSã®PoCãå°ãæ¸ãåºãã¦ã¾ã¨ãã¾ããã ä»ã¾ã§èªåã§è¦ã¤ãããã®ãæµ·å¤ã®Security Researcheréããåéãããã®ãããã¾ãã ãã¦ãä»åãªã¹ãã¢ããããPoCã®è¦æ¹ã§ããããã¤ãã®é ç®ãããã¾ãã ä¸çªä¸ã®ãææ³ãã¯ã¿ã¤ãã«ã¿ãããªãã®ã ã¨æã£ã¦ä¸ããã äºçªç®ã®ãPoCãã¯ã¹ã¯ãªãããå®è¡ããçºã®ã³ã¼ãã§ããæ®ã©ãã¢ã©ã¼ããåºãã ãã®ã¹ã¯ãªããã®çºå±éºãªã³ã¼ãã¯ç¡ãã¤ããã§ãããèªåã®ãã©ã¦ã¶ã§å®è¡ããéã¯èªå·±è²¬ä»»ã§ãé¡ããã¾ãããªã³ã¯ãã¯ãªã
ããã«ã¡ã¯ãkintone éçºãã¼ã ã®å¤©é (@ama_ch) ã§ãããã£ããæ¥ããããªãã¾ãããã å°ãåã« JS ã®èªåã¬ãã¥ã¼ãã¼ã« jswatchdog ããªã¼ãã³ã½ã¼ã¹ã§å ¬éãã¾ããã®ã§ããã¡ãã§ç´¹ä»ããã¦ããã ãã¾ãã ä½¿ãæ¹ https://kintone.github.io/jswatchdog/ ä¸è¨ã® URL ãéããå·¦å´ã®ã¨ãã£ã¿ã« JS ã³ã¼ããè²¼ãä»ããã ãã§ãã å³å´ã«ä¿®æ£ãå¿ è¦ãªç®æã表示ãããã®ã§ãé©å®ä¿®æ£ãã¾ãã ç¹å¾´ ããªããªã®éçºè ãããªãã¦ã使ããããä¸ç»é¢å®çµã® Web ã¤ã³ã¿ã¼ãã§ã¼ã¹ lint ãã¼ã«ã§ã馴æã¿ã®æ§æãã§ãã¯ã®ä»ãç¥ããã«èå¼±æ§ãä½ãè¾¼ããã¨ãé¿ãããããXSS ã®å¯è½æ§ãããç®æã«ãè¦åã表示 å é¨çã«ã¯ãJS ã®éçæ§æãã§ãã¯ãã¼ã«ã¨ã㦠ESLint 㨠JSHint ãçµã¿è¾¼ãã§ãã¾ãã ããã« XSS ã®å¯è½æ§ãã
ååã«å¼ãç¶ããUTF-7ã«ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã«ã¤ãã¦èª¬æãã¦ããã¾ãã UTF-7ã«ããXSSã¯ãæ»æå¯¾è±¡ã®ã³ã³ãã³ãã®æåã¨ã³ã³ã¼ãã£ã³ã°ã䏿çãªå ´åã«ããã®ã³ã³ãã³ãã被害è ã®ãã©ã¦ã¶ï¼Internet Explorerï¼ã§éããã¨ãã«ããã®ã³ã³ãã³ãã®æåã¨ã³ã³ã¼ãã£ã³ã°ãUTF-7ã§ããã¨IEã«èª¤èªããããâ +ADw-script+AD4-ãã®ãããªUTF-7ã®æååãæå¹ãªHTMLè¦ç´ ã¨ãã¦èªèãããããã«çºçãã¾ãã ããã¦ããâ æåã¨ã³ã³ã¼ãã£ã³ã°ã䏿çããªå ·ä½çãªç¶æ³ã¨ãã¦ã以ä¸ã®ãããªæ¡ä»¶ã®ããããã«è©²å½ããã¨ãããã¨ãåå説æãã¾ããã ã¬ã¹ãã³ã¹ããããmetaè¦ç´ ã®ã©ã¡ãã§ãcharsetãæå®ããã¦ããªã charsetã«IEãè§£éã§ããªãã¨ã³ã³ã¼ãã£ã³ã°åãæå®ããã¦ãã metaè¦ç´ ã§charsetãæå®ãã¦ããã¨ãã«ãmetaè¦
å ¨ä¸çã§5å人以ä¸ãå©ç¨ãã¦ããã¡ãã»ã¼ã¸ã»ã¢ããªãLINEãã«æ·±å»ãªã»ãã¥ãªãã£èå¼±æ§ãåå¨ãã¦ãããã¨ãå¤ã£ãããã®èå¼±æ§ãæªæããæ»æè ã«çªãããã¨ãå©ç¨è ã®ã¹ãã¼ããã©ã³ã«ä¿åããã¦ããLINEå ã®ãã¼ã¯å±¥æ´ãåçãåéãªã¹ããªã©ãå¤é¨ãã䏿£ã«æãåºãããããæ¹ç«ãããæãããããLINEã¯3æ4æ¥ã«ããã®èå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ãç·æ¥ãªãªã¼ã¹ãã¦ãããå©ç¨è ã¯èªèº«ã®ã¢ããªãææ°çã«ã¢ãããã¼ãããã¦ãããã©ãããè³æ¥ç¢ºèªããã»ããããã ããã ãã®èå¼±æ§ã¯ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã©ãã®ã¹ãã©ã¦ãï¼æ¬è¨äºæ²è¼ã®ããµã¤ãã¼ã¤ã³ã·ãã³ãã»ã¬ãã¼ããçºè¡å ï¼ãçºè¦ãã1æ30æ¥ã«ã½ããã¦ã§ã¢çã®èå¼±æ§æ å ±ãåãæ±ãIPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼ã«å ±åãããã®ã ãIPAãã2æ2æ¥ã«èå¼±æ§ã®éç¥ãåããLINEã¯ã2æ12æ¥ã«èå¼±æ§ã®ä¸é¨ã«ã¤ãã¦ãµã¼ãã¼å´ã§å¯¾çã3æ4æ¥ã®ã¢ãã
SQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çã¯é常ã«ç°¡åã§ããããããã©ã¦ã¶ã«å¯¾ãããã¹ã¯ãªããã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¯ãªããªãç¡ããªãã¾ãããã¹ã¯ãªããã¤ã³ã¸ã§ã¯ã·ã§ã³ãç¡ããªããªã10ã®çç±ãããã¦ã¿ã¾ãã è¤éãªæ»æçµè·¯ã¨å¯¾ç ååç´¹ä»ããããã«ããã©ã¦ã¶ã«å¯¾ããã¹ã¯ãªããã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã®çµè·¯ã¯3種é¡ããã¾ããã¨ã¹ã±ã¼ãæ¹æ³ãæ°ç¨®é¡ããã¾ãããã¹ã¦ã®åºåãå®å ¨ã«ã¨ã¹ã±ã¼ãã§ããã°ã»ãã¥ãªãã£ç¶æã容æã«ãªãã¾ãããã¿ã°ã屿§ãåºåãããå ´åããããããå¿ ããããã¹ã¦ã®åºåãã¨ã¹ã±ã¼ãã§ããããã§ã¯ããã¾ãããããã«æ»æææ³ã«ãããµã¤ããã¾ããã£ãæ»æãç´æ¥æ»æãéæ¥æ»æãªã©ãã¿ã¼ã³ãããã¾ããã¨ã¹ã±ã¼ãã§ããªããã¼ã¿ã¸ã®ä¸æ£ãªã¹ã¯ãªããã®æ¿å ¥ãé²ãã«ã¯ããã¼ã¿ã®èµ·æºã¾ã§ããã®ã¼ãå®å ¨æ§ã確ä¿ããªããã°ãªãã¾ããããã©ã¦ã¶ã«å¯¾ããã¹ã¯ãªããã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çã¯ãã¼ã¿ãã¼ã¹ãµã¼ãã¸ã®SQLã¤ã³ã¸ã§ã¯ã·
ä¸ç¹å®ã®ã¦ã¼ã¶ã¼ãå ¥åããMarkdownããã©ã¦ã¶ä¸ã§JavaScriptã使ã£ã¦HTMLã«å¤æããã¨ããå ´é¢ã«ããã¦ã¯ãJavaScriptã§å¤æãã¦HTMLãçæããã¨ããå¦çã®é½åä¸ã©ããã¦ãDOM-based XSSã®çºçãèããªãããã«ã¯ãããªãããã¨ãã£ã¦ãMarkdownããã¼ã¹ãHTMLãçæããã¨ããå¦çãã¹ã¦ãXSSãåå¨ããªãããã«æ³¨æããªããèªåã§æ¸ãã®ã大å¤ã ããmarkedãmarkdown-jsãªã©ã®æ¢åã®å¤æç¨ã®JSãæã£ã¦ãã¦ãããããXSSããªããã確èªããã®ã¯çµæ§å¤§å¤ã ã£ããããã ãããã£ãå ´åã«ã¯ãMarkdownããçæãããHTMLãRickDOMãéããã¨ã§ãä¸ãä¸HTMLå ã«JavaScriptãå«ã¾ãã¦ããã¨ãã¦ãããããé¤å¤ãã許å¯ãããè¦ç´ ã許å¯ããã屿§ã ãã§æ§ç¯ãããå®å ¨ãªHTMLã«åæ§ç¯ãããã¨ãã§ãããããã«ããããã£ã¦çæ
èå¼±æ§ãè¦ã¤ãã¦ã»ãã¥ãªãã£å¯¾çã«è²¢ç®ãã¦ããã®ããããã°ãã³ã¿ã¼ãã¨å¼ã°ããåå¨ã ãGoogleãªã©ãã³ãã¼ã®å ±å¥¨éã§çè¨ãç«ã¦ã¦ããã¨ãããããã¬ã¯ ããµããããããããã®ãã°ãã³ã¿ã¼ã¨ãã¦ã®âæãã¿âãç´¹ä»ãã¦ãããã ã½ããã¦ã§ã¢ã®ãã°ãèå¼±æ§ã¯ã軽微ãªä¸å ·åããã»ãã¥ãªãã£ä¸ã®æ·±å»ãªåé¡ãå¼ãèµ·ãããã®ã¾ã§ãæ§ã ãªãã®ããããéçºè ãå¹¾ãæ³¨æãã¦ãèå¼±æ§ããªãããã¨ã¯é常ã«é£ããããå¤é¨ã®ç«å ´ããèå¼±æ§ãè¦ã¤ãã¦ã»ãã¥ãªãã£å¯¾çã«è²¢ç®ããããã°ãã³ã¿ã¼ãã¨ããåå¨ããåãã ãããã GoogleãMicrosoftããµã¤ãã¦ãºãªã©ä¸é¨ã®ãã³ãã¼ã¯ãèå¼±æ§ãå ±åãããã°ãã³ã¿ã¼ã«å ±å¥¨éãªã©ãæ¯æãå¶åº¦ãéå¶ããã®å ±å¥¨éã§çè¨ãç«ã¦ãããã®ä¸äººããããã¬ã¯ ããµããããã ã12æ18ã19æ¥ã«è¡ãããã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ãCODE BLUEãã§ã¯ãããã¬ã¯ãããããã®ãã°ãã³ã¿
jQueryãã©ã°ã¤ã³ã®CAPTCHAã¹ã¯ãªããã«ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã®èå¼±æ§ãè¦ã¤ãã£ãã¨ãã¦ãã»ãã¥ãªãã£ç ç©¶è ãæ å ±ãå ¬éããã Webãµã¤ãã®æ¤è¨¼æ©è½å®è£ ã«ä½¿ããã¦ãããjQuery Validation Pluginãã®CAPTCHAã¹ã¯ãªããã«æ·±å»ãªèå¼±æ§ãè¦ã¤ãã£ãã¨ãã¦ãã»ãã¥ãªãã£ç ç©¶è ãèªèº«ã®ããã°ã§11æ18æ¥ã«æ å ±ãå ¬éãããåãã©ã°ã¤ã³ã®ä½è ã¯ãã®èå¼±æ§ãä¿®æ£ãããããã19æ¥ã«å ¬éãã¦ããã ã»ãã¥ãªãã£ç ç©¶è Sijmen Ruwhofæ°ã®ããã°ã«ããã¨ãèå¼±æ§ã¯jQuery Validation Pluginã®ãã¼ã¸ã§ã³1.13.0ã«åå¨ããã2014å¹´8æã«çºè¦ãã¦ä½è ãjQueryã«ã¡ã¼ã«ã§é£çµ¡ããããè¿äºããªãã£ãããæ å ±ã®å ¬éã«è¸ã¿åã£ãã¨ããã ãã®èå¼±æ§ã¯CAPTCHAãã¢ã³ã¹ãã¬ã¼ã·ã§ã³ã¹ã¯ãªããã«èµ·å ããã¨ãããjQuery
WordPress 4.0.1ã§ã¯XSSã®èå¼±æ§ãªã©ãä¿®æ£ããããæªç¨ãããå ´åãWebãµã¤ãããããã³ã°ãããããã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼æ»æã仿ãããããããæããããã ããã°ä½æã½ããã®æ´æ°çã¨ãªããWordPress 4.0.1ãã11æ20æ¥ã«å ¬éããããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ãªã©ã®æ·±å»ãªèå¼±æ§ãä¿®æ£ããã¦ãããã¦ã¼ã¶ã¼ã«å¯¾ãã¦èªåã®Webãµã¤ããç´ã¡ã«æ´æ°ããããå¼ã³æãã¦ããã WordPressã®ããã°ã«ããã¨ãWordPress 4.0.1ã§ã¯3ä»¶ã®XSSã®èå¼±æ§ãå«ããè¨8ä»¶ã®èå¼±æ§ãä¿®æ£ãããæªç¨ãããå ´åãWebãµã¤ãããããã³ã°ãããããã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼æ»æã仿ãããããããæãããããèå¼±æ§ã¯3.9.2ã¾ã§ã®ãã¼ã¸ã§ã³ã«åå¨ããã æ´æ°çã¯ãèªåæ´æ°ãæå¹ã«ãã¦ããã°èªåçã«é ä¿¡ããããè
ååã¯Web2.0ã®ä¸æ ¸æè¡ã¨ããããAjaxãè¦ã¦ããããã¨æãã¾ãã Ajaxã®ã»ãã¥ãªãã£ã«ã¤ãã¦èãã¦ããã¾ããããã®åã«Ajaxã«ã¤ãã¦ç°¡åã«ãããããã¦ã¿ã¾ãããã Ajaxã¨ã¯Asynchronous JavaScript XMLã®ç¥ã§ãããä¸è¨ã§è¨ãã°JavaScriptã¨XMLã使ã£ã¦éåæã«éä¿¡ããã¨ãããã¨ã§ãï¼XML以å¤ã®å½¢å¼ã使ããããã¨ãå¤ããªãã¾ããâ ï¼â ãéä¿¡ãéåæã«ãããã¨ã§ãä½ãå¦çãããå ´åã«ãã¡ãã¡å¾ ããªãã¦ã次ã®å¦çã«ç§»ããã¨ãã§ãã¾ãããã®çµæãã¦ã¼ã¶ãå¾ ãããã«å¤ãã®å¦çãè¡ããããã«ãªãã¾ãããã¾ããç»é¢å ¨ä½ãåèªã¿è¾¼ã¿ããå¿ è¦ããªããªã£ããã¨ãã使ãåæã®åä¸ããçç±ã§ãã Ajaxã®åä½ ããã§ã¯ç°¡åãªãµã³ãã«ã³ã¼ãã§Ajaxã®åä½ãè¦ã¦ããããã¨æãã¾ãï¼ãªã¹ã1â ï¼â ããããã¯Ajaxã®å ¥éãµã¤ããæ¸ç±ã§ä¸çªæåã«åºã¦ããã³ã¼ãã§ã
ä»åã¯Webã¢ããªã±ã¼ã·ã§ã³ãä½ã£ããã¨ããªãæ¹ã§ãåããããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°èå¼±æ§ã解説ãã¾ãã ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã¨ã¯ï¼ åãã¦ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã¨èãã¦ãã©ã®ãããªåé¡ãªã®ãããã«çè§£ã§ãã人ã¯ããªãã¨æãã¾ãããµã¤ãAã«è¨è¿°ãããJavaScriptããã°ã©ã ããµã¤ãBä¸ã§å®è¡ãããããã«çºçãããã¨ãåé¡ã¨ãããã®ã§ããâ ãµã¤ãéãã¾ãããã¹ã¯ãªããã®å®è¡ãåé¡ã¨ãã¦ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã¨ååãä»ãããã¾ããããã®å½åã§ã¯ç´æçã«åããã¥ããããµã¤ãéã«ã¾ããããHTMLã¡ã¼ã«ãªã©ã«JavaScriptãæ¿å ¥ããæ»æã§ãåã广ãå¾ããããã¨ããããâ JavaScriptã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¨ãå¼ã°ããããã«ãªã£ã¦ãã¾ãã å³1ãç°¡åãªã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° ä¾1ãç°¡åãªç´æ¥æ»æ æ²ç¤ºæ¿ãµã¤ãã«æç¨¿ããããã¼ã¿ãã¨ã¹ã±ã¼ãå¦
Flashãç¨ããã¯ãã¹ãã¡ã¤ã³ã¢ã¯ã»ã¹ ååã¾ã§ã¯ãã¯ãã¹ãã¡ã¤ã³ã¢ã¯ã»ã¹ãè¡ãããã®æ¹æ³ã¨ãã¦ããªãã¼ã¹Proxyãä½¿ãæ¹æ³ã¨JSONPãä½¿ãæ¹æ³ãç´¹ä»ãã¾ããããã©ã¡ãã®æ¹æ³ãå°ãå¤ãã£ãæ¹æ³ã ã£ãã¨æãã¾ãããªã«ãç¡çããã®ããã«æããæ¹ãããã®ã§ã¯ãªãã§ãããããä»åç´¹ä»ããFlashã使ã£ãæ¹æ³ã§ã¯ååã¾ã§ã®æ¹æ³ã¨ã¯éããèªç¶ãªå½¢ã§ã¯ãã¹ãã¡ã¤ã³ã¢ã¯ã»ã¹ãè¡ããã¨ãã§ãã¾ãã Flashã§ã¯ãå¼ã³åºãããå´ã§è¨å®ãè¡ããã¨ã§ã¯ãã¹ãã¡ã¤ã³ã¢ã¯ã»ã¹ãå¯è½ã«ãªãã¾ãã è¨å®ã¨ãã£ã¦ãé常ã«ç°¡åã§ãå¼ã³åºãããå´ã®Webãµã¼ãã«crossdomain.xmlã¨ãããã¡ã¤ã«ãè¨ç½®ããã ãã§ãããã®ã¨ãã®URL㯠http://www.example.com/crossdomain.xml ã¨ãªãã¾ãã ãã¡ã¤ã«ã®å 容ã¯ä»¥ä¸ã®ããã«ãªãã¾ãã crossdomain.xmlã®å 容 <cr
æåã³ã¼ããå¼ãèµ·ããã»ãã¥ãªãã£ä¸ã®åé¡ã¨ãã¦ããã£ã¨ãè峿·±ããã®ã®ã²ã¨ã¤ã§ãããUnicodeããä»ã®æåã³ã¼ãã¸ã®ãå¤å¯¾ä¸ã®å¤æãã§å¼ãèµ·ããããåé¡ç¹ã«ã¤ãã¦ãä»åã¨æ¬¡åã§èª¬æãã¾ãã ãåãã®ã¨ãããUnicodeã«ã¯é常ã«å¤æ°ã®æåãåé²ããã¦ãã¾ããï¼ç¾å¨ææ°çã®Unicode 5.1.0ã§ã¯100,713æåãåé²ããã¦ããããã§ãâ ï¼â ãUnicodeããä»ã®æåã³ã¼ãã¸ã®å¤æã«ããã¦ã¯ãäºææ§ãå¯èªæ§ã®ç¶æã®ããããè¤æ°ã®Unicodeã®æåãä»ã®æåã³ã¼ãã§ã¯åä¸ã®æåã«å¤æããããã¨ãããã¾ãã ãã®ãå¤å¯¾ä¸ãã®å¤æããéçºè ãæ³å®ãã¦ããªãã£ããããªåé¡ãå¼ãèµ·ããåå ã¨ãªããã¨ãå¤ã ããã¾ãã å ·ä½çãªä¾ã¨ãã¦ãWindowsä¸ã§ã®Unicodeããã®å¤æã«ã¤ãã¦èª¬æãã¾ãã Windowsä¸ã§ã®UnicodeããShift_JISã¸ã®å¤æ Windowsä¸ã§
ä»åã¯çç·´ããWebã¢ããªéçºè ãªã常èã®ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°å¯¾çã®è½ã¨ãç©´ãç´¹ä»ãã¾ãã JavaScriptãæé¤ãã¦ããã¤ããã§æé¤ã«å¤±æï¼ï¼ æè¿ã¯Sanitizeï¼ãµãã¿ã¤ãºï¼ã¨ããè¨èã®ä»£ããã«Validationï¼æ¤è¨¼ï¼ã¨ããè¨èãããèãããã«ãªã£ãã¨æãã¾ããSanitizeã®æå³ãè¾æ¸ã§èª¿ã¹ãã¨ãæ±ãã¦ããç©ããããã«ãããã¨ãã¨ããã¦ãã¾ãããã®æå³ã®éãæ±ãã夿°ããããã«ãã¦ä½¿ãã°å®å ¨ã«å©ç¨ã§ããã¨ããèãæ¹ã«åºã¥ãã®ããµãã¿ã¤ãºææ³ã§ããå ¸åçãªä¾ã¯ããâ ããã¹ããåºåããåã«"<"ã¨">"ãåãé¤ããæ¹æ³ãããã¾ãã ä¾1ã"<"ã¨">"ãereg_replaceã§åãé¤ã $safe_text = ereg_replace($_GET['text'], '[<>]', ''); ãã®$safe_textã <a href="/script.php?t
ä»åã¯ããâ å è¡ãã¤ãã®åãè¾¼ã¿ãã¨ããæ»ææ¹æ³ã«ã¤ãã¦ç´¹ä»ãã¾ãã ãåãã®ã¨ãããã»ã¨ãã©ã®ç¬¦å·åæ¹å¼ï¼æåã¨ã³ã³ã¼ãã£ã³ã°ï¼ã«ããã¦ã¯ãã²ãããªãæ¼¢åãªã©ASCII以å¤ã®ã»ã¨ãã©ã®æåã¯ã1æåãè¤æ°ãã¤ãã«ã¦æ§æããã¦ãã¾ãããã¨ãã°ãã²ãããªã®ãããã¯ãShift_JISã«ããã¦ã¯0x82 0xA0ã¨ãã2ãã¤ããUTF-8ã«ããã¦ã¯0xE3 0x81 0x82ã¨ãã3ãã¤ãã§è¡¨ç¾ããã¾ãã æ»æè ããã«ããã¤ãæåã®å è¡ãã¤ãé¨åã ããä¸ãããã¨ã«ãããæ¬æ¥åå¨ãã¦ããå¾ç¶ã®æåãç¡å¹ã«ãã¦ãã¾ãã®ããä»åç´¹ä»ãããå è¡ãã¤ãã®åãè¾¼ã¿ãã¨ããæ»ææ¹æ³ã§ãã å è¡ãã¤ãåãè¾¼ã¿ã®å ·ä½ä¾ ã§ã¯ãå ·ä½çãªä¾ãè¦ã¦ããã¾ãããã ãã¨ãã°ãShift_JISã§æ¸ãããHTMLã¨ãã¦ã次ã®ãããªãã®ããã£ãã¨ãã¾ãã name: <input type=text value="" />
第11åã¬ã¸ã§ããâ â ãã¦ã£ã¸ã§ããã®ã»ãã¥ãªãã£ ç¦æ£®å¤§å 2007-11-14
2014-09-27: 該å½ãµã¤ãä¸ã«XSSããªãã¦ãæ»æå¯è½ã§ãããã¨ã id:mayuki ããã®ã³ã¡ã³ãã§å¤æãã¾ããã®ã§å ¨é¢çã«æ¸ãç´ãã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã§ãã£ã¦ãæ»æè ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«å ã®Shellshockæ»æãéç¨ããCGIã®URLãããã£ã¦ããã ãã§æ»æå¯è½ã§ãã®ã§æ©æ¥ã«å¯¾å¿ãå¿ è¦ã§ãï¼ä¼ç¤¾ã®ããã°ã«ãæ¸ãã¦ã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã«ç½®ãã¦ãããµã¼ãã§æ»æè ãç´æ¥ã¢ã¯ã»ã¹ã§ããªãããã¨ãã£ã¦bashã®æ´æ°ãæ ã£ã¦ããã¨ãæ¡ä»¶ã«ãã£ã¦ã¯æ»æãå¯è½ã¨ãªãã¾ãã æ¡ä»¶ã¨ãã¦ã¯ã ãã®ãµã¼ãã«ã¯ã·ã§ã«ãçµç±ãã¦å¤é¨ã³ãã³ããèµ·åããCGIçãåãã¦ãã(é常ã®Shellshockã®æ»æã¨åæ¡ä»¶) æ»æè ããã®URLãäºåã«ç¥ã£ã¦ãã(ãããã¯æ¨æ¸¬å¯è½) ã¨ãªãã¾ãã æ»æè ã¯ãã¦ã¼ã¶ã¼ãç½ URLã¸èªå°ãã以ä¸ã®ãããªJavaScriptãç½ ãã¼ã¸ä¸ã§åãããæ»æå¯¾è±¡ã®W
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}