This post details CVE-2024-4367, a vulnerability in PDF.js found by Codean Labs. PDF.js is a JavaScript-based PDF viewer maintained by Mozilla. This bug allows an attacker to execute arbitrary JavaScript code as soon as a malicious PDF file is opened. This affects all Firefox users (<126) because PDF.js is used by Firefox to show PDF files, but also seriously impacts many web- and Electron-based a
Intro CSRF ã¨ããå¤ã®æ»æãããããã®æ»æããå¤(ãã«ãã)ãã®ãã®ã«ãããã¨ãã§ãããã©ãããã©ã¼ã ã®é²åã®èæ¯ãããCookie ã SameSite Lax by Default ã«ãªã£ãããã ãã¨ãã解説ãè¦ããã¨ãããã 確ãã«ãç¾å®çã«ããã«ãã£ã¦æ»æã®æç«ã¯é£ãããªããæããã¦ãããµã¼ãã¹ããããããããããã¯ãã©ãããã©ã¼ã ãç¨æãã対çã®æ¬è³ªããè¨ãã¨ãè§£éãå°ãããã¦ããã¨è¨ããã ããã ä»åã¯ããCSRF ãã©ããã¦æç«ãã¦ããã®ãããæ¯ãè¿ããã¨ã§ãæ¬å½ã«ãã©ãããã©ã¼ã ã«è¶³ãã¦ããªãã£ããã®ã¨ããããè£ã£ã¦ãã£ãçµç·¯ãæ¬å½ã«ãã¹ã対çã¯ä½ã§ãããã解説ãã¦ããã çµæã¨ãã¦è¦ãã¦ããã®ã¯ãä»ãµã¼ãã¹ãå®è£ ããä¸ã§ã®ããã¼ã¹ã(not ãã¹ã)ã¨ãªããã©ã¯ãã£ã¹ã ã¨çè ã¯èãã¦ããã CSRF æç«ã®æ¡ä»¶ ä¾ãã°ãæ»æè ãç¨æãã attack.examp
freeeæ ªå¼ä¼ç¤¾ PSIRT ããã¼ã¸ã£ã¼ã®ãã ãã ãæ°ãã ãã ãæ°ï¼freeeæ ªå¼ä¼ç¤¾ã®ãã ãã ãã¨ç³ãã¾ãã 仿¥ã¯ããGitHub Copilot å°å ¥æã«èããã»ãã¥ãªãã£ã®ãããããã¨ãããã¨ã§ãCopilotã®ã»ãã¥ãªãã£ãªã¹ã¯ã«ã¤ãã¦èªãããã§ãããèãã¦ã¿ãããGitHubã®ä¸ã®äººãåã«ãããªãã¨ãããã¹ãã®ã¯ç¸å½å¤§èãªè©±ã ã¨æãã¾ããæå¾ã«ãããã¨ã§ç· ããã®ã§ã¡ãã£ã¨ææ ¢ãã¦ãã ããã èªå·±ç´¹ä»ããããã¾ãããã ãã ãã¨ç³ãã¾ããPSIRTã¨ããçµç¹ã§ããã¼ã¸ã£ã¼ããã£ã¦ãã¾ããPSIRTã¨ããã®ã¯ããããã¯ãå°éã®ã»ãã¥ãªãã£ãã¼ã ã§ãã ããã§ãããã¯ãã®å®å ¨ãå®ãä»äºããã¦ããããã§ããããããããªãã¨ãããã¤ã¤ããã®1ã2å¹´ã¡ããã¡ãã話é¡ã«ä¸ãã£ã¦ãã¾ãããfreeeã®å¤§è¦æ¨¡ãªå ¨ç¤¾é害è¨ç·´ã®ä»æã人ãªããããããã ãã¨ã¯ãfreeeã¯å æ¥OSSããªã·ã¼ãå ¬é
ã¡ã¢ãªã¼é¢é£ã®ä¸å ·åãæ¸ããããã«ããAndroidãã®æ°ããã³ã¼ãã«Rustã使ç¨ããã¨ããGoogleã®å¤æã¯ãææãæãã¦ããããã ããã®æ°å¹´ã§ãAndroidã®ã¡ã¢ãªã¼å®å ¨æ§é¢é£ã®èå¼±æ§ã¯åå以ä¸ã«ãªã£ãããã®ææãéæãããææã¯ãGoogleãCãC++ããã¡ã¢ãªã¼å®å ¨æ§ã®é«ãããã°ã©ãã³ã°è¨èªã§ããRustã«åãæ¿ããææã¨ä¸è´ããã Androidã«çºè¦ãããã»ãã¥ãªãã£ãã¼ã«ã®ä¸ã§ãæãä»¶æ°ãå¤ãã£ãã«ãã´ãªã¼ãã¡ã¢ãªã¼å®å ¨æ§é¢é£ã®èå¼±æ§ã§ãªãã£ãã®ã¯2022å¹´ãåãã§ãããGoogleã¯1å¹´åã«ããAndroid Open Source Projectï¼AOSPï¼ãã§æ°ããã³ã¼ãã®ããã©ã«ãè¨èªãRustã«åãæ¿ãã¦ããã GoogleãAndroidã«ä½¿ç¨ãã¦ããã»ãã®ã¡ã¢ãªã¼å®å ¨æ§ãåããè¨èªã«ã¯ãJavaãJavaäºæã®KotlinããããAOSPã§ä¸»æµã®è¨èªã¯ã¾
ã¯ããã« 2022å¹´ã®ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼ã«è¬å¸«ã¨ãã¦åå ãã¾ããããã®éã«ãGoã«ãããèå¼±æ§ã¸ã®å¯¾çã¯ã©ããªã£ã¦ããã®ã調ã¹ã¾ããããã®è¨äºã§ã¯ãgithub.com/google/go-safeweb/safesqlãã©ã®ããã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãé²ãã§ãã®ãã«ã¤ãã¦è§£èª¬ãã¾ãã ãªãã@rungããã®ææ¸ãå¤ãã«åèã«ãã¦ããã¾ããã¾ããã»ãã¥ãªãã£ã»ãã£ã³ãã§ç¨ããè³æã¯ãã¡ãããé²è¦§ã§ãã¾ãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ã¯ï¼ ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ãå ¬éãã¦ããå®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ãè¦ãã¨ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ä»¥ä¸ã®ããã«èª¬æããã¦ãã¾ãã ãã¼ã¿ãã¼ã¹ã¨é£æºããã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã®å¤ãã¯ãå©ç¨è ããã®å ¥åæ å ±ãåºã«SQLæï¼ãã¼ã¿ãã¼ã¹ã¸ã®å½ä»¤æï¼ãçµã¿ç«ã¦ã¦ãã¾ããããã§ãSQLæã®çµã¿ç«ã¦æ¹æ³ã«åé¡ãããå ´åãæ»æã«ãã£ã¦ãã¼ã¿ã
ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾Flatt Securityã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®å¿è³(@Ga_ryo_)ã§ãã iOSã¢ããªã±ã¼ã·ã§ã³ãéçºããä¸ã§ãã¡ãã£ã¢ãã¡ã¤ã«ãããã¥ã¡ã³ããã¡ã¤ã«ãä»ã®ã¢ããªã±ã¼ã·ã§ã³ã¨å ±æããæ©è½ãå®è£ ããã±ã¼ã¹ãããã¨æãã¾ããiOSã§ã¯ããã¡ã¤ã«å ±æã®ããã«æ§ã ãªæ©è½ãæä¾ãã¦ãã¾ãããOSã®æ´æ°ã«å¾ã£ã¦æ©è½ãå¢ããææ¡ãå°é£ã«ãªã£ã¦ããã¨æãã¦ããæ¹ããããã¨ãã¨æãã¾ãã ã¾ãããããã£ãæ©è½ã追å ãããéã«å®è£ æ¹æ³ã«é¢ãã解説ããã¦ãã ããæ¹ã ãããã£ãããã¨æãã¾ãããç´°ãã仿§ã«ã¤ãã¦èªããããã¨ã¯ãã¾ãå¤ãç¡ãã¨ããå°è±¡ã§ãã ããã§æ¬ç¨¿ã§ã¯ãiOSã¢ããªã±ã¼ã·ã§ã³ä¸ã§å©ç¨ã§ããå種ãã¡ã¤ã«å ±ææ©è½ã5ã¤ã®ãã¿ã¼ã³ã«åãã¦æ¤è¨¼ãã¤ã¤ãããããå©ç¨ããä¸ã§æ³¨æãã¹ãç¹ã«ã¤ãã¦ã解説ãã¦ãããã¨æãã¾ãã æ³¨) æ¬ç¨¿ã§ã¯åº¦ã ãµã³ãã«ã³ã¼ããæç¤ºãã
Linuxã«ã¼ãã«ãCã§è¨è¿°ããã¦ããã¨ããã®ã¯èª°ããç¥ãã¨ããã ããã ããã®Cãããªãæã®Cãããªãã¡1989å¹´ã®è¦æ ¼ã§ãããC89ãã ã¨ããäºå®ã«ã¤ãã¦ã¯ç¥ããªã人ããããããããªããC89ã¯ãANSI X3.159-1989ãããããã¯ãANSI Cãã¨ãã¦ãç¥ããã¦ãããLinus Torvaldsæ°ã¯ãããããC89ã«å¥ããåããæã ã¨å¤æããLinuxã«ã¼ãã«ã®å ¬å¼ãªéçºè¨èªã2011å¹´è¦æ ¼ã®ãC11ãã«ç§»è¡ãããã¨ãã¦ããã ããã¯è¦ããã»ã©å¤§ããªå¤æ´ã§ã¯ãªããC89ã¯ç¾å¨ã§ãã»ã¼æ®éçã«ãµãã¼ãããã¦ãããã©ã®ãããªCã³ã³ãã¤ã©ã¼ã§ã以åã®è¦æ ¼ã¨ã®å¾æ¹äºææ§ãåãã¦ãããããC89ã§è¨è¿°ãããããã°ã©ã ã®ã³ã³ãã¤ã«ãå®è¡ã¯åé¡ã«ãªããªããã¤ã¾ããC11æºæ ã®ã³ã³ãã¤ã©ã¼ã§ããC89ã§è¨è¿°ãããã¬ã¬ã·ã¼ãªã³ã¼ãã«ãã£ã¦åé¡ãå¼ãèµ·ãããããã¨ã¯ãªãã¯ãã ã Torvaldsæ°
ãã®ã¨ã³ããªã¯ãPHP Advent Calendar 2021 ã®20æ¥ç®ã®ã¨ã³ããªã§ãã19æ¥ç®ã¯ @takoba ããã«ãã PHPããã¸ã§ã¯ãã®Composerããã±ã¼ã¸ãRenovateã§å®æã¢ãããã¼ããã ã§ããã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°(XSS)ã®å¯¾çãè¡ãéã«ã¯ãã¨ã¹ã±ã¼ãå¦çãããã¾ãããã¨è¨ããã¾ããããã®å²ã«PHP以å¤ã®è¨èªã§ã¯ãã¾ãã¨ã¹ã±ã¼ãå¦çã®é¢æ°ãç¨æããã¦ããªãã£ãããã¾ããããã«æ¯ã¹ã¦PHPã¯ã¨ã¹ã±ã¼ãå¦çã®é¢æ°ãé常ã«è±å¯ã§ããããã ãè¦ã¦ããPHPã¯ãªãã¦ã»ãã¥ã¢ãªãã ! ã¨æ©ã¨ã¡ããã人ãããããããã¾ããããããããä»è¨èªã§ã¨ã¹ã±ã¼ãå¦ç颿°ããã¾ããªãã®ã¯ã¡ããã¨çç±ãããã¨æãã®ã§ãã æ¬ç¨¿ã§ã¯ãPHPã®ã¨ã¹ã±ã¼ãå¦çç¨ã®é¢æ°ãç´¹ä»ããªããããã®å©ç¨ç®çã¨ããã®é¢æ°ã使ããªãã§æ¸ã¾ããæ¹æ³ã説æãã¾ãã SQLç¨
ãã®è¨äºã¯Rust Advent Calendar 2021ã®12/8æ¥ã®è¨äºã§ãã Ruståæã®è¨äºã¨ãã¦æ¸ãã¾ããããä»ã®è¨èªã«ãé©ç¨ã§ããèãæ¹ãªã®ã§ãã»ãã®è¨èªå¢ã®æ¹ã ããããã°ãä»ãåãä¸ããã ä»åã®ãã¼ãã¯ãRustã§çã«å®å ¨ãªããã°ã©ã ãæ¸ãæ¹æ³ãã«ã¤ãã¦ã§ãã ãçã«å®å ¨ãªããã°ã©ã ãã®å®ç¾©ã¯ä»¥ä¸ã¨ãã¾ãã æåãå®å®ããçµæãäºæ¸¬å¯è½ã¨ãªã æ£ããã®åºæºã«åºã¥ããããã°ã©ã ã®ééããæ¤ç¥ãããã¨ãã§ãã ãçã«ãã¨ã¯ãã¡ã¤ã³ç¥èã«åºã¥ãæ£ããã¨ããæå³ã§ãã詳ããã¯å¾è¿°ãã¾ãã ããã¨ãããããRustã§å®è£ ãããããã°ã©ã ã¯å®å ¨ãããªãã®ããã¨ããæ³å®è³ªåã«ã¤ãã¦ã¯ãã¡ã¢ãªã®æä½ã¯å®å ¨ãã ããããã ãã§ã¯çã«å®å ¨ãªããã°ã©ã ã«ã¯ãªããªãããçãã«ãªãã¾ããããã«ã¤ãã¦èå³ãããæ¹ããã²æå¾ã¾ã§ãä»ãåããã ããã ãçã«å®å ¨ãªããã°ã©ã ããå®ç¾ããã¬ã·ãã¨ãã¦ã¯ãé¢
Linuxã¯ããã°ã©ãã³ã°è¨èªCã®ç³ãåã®ãããªåå¨ã ããããæã¯æµããç¶æ³ã¯å¤ãã£ããRustãLinuxã®ã·ã¹ãã è¨è¿°è¨èªã¨ãã¦æ¡ç¨ãããã¨ããåããå°ããã¤æ¯æãéãã¦ãã¦ãããä¾ãæããã¨ãLinuxã«ã¼ãã«éçºè ã®ããã®å¹´æ¬¡ã«ã³ãã¡ã¬ã³ã¹ãLinux Plumbers Conferenceï¼LPCï¼2020ãã«ããã¦ãéçºè ãã¯Linuxã®ã¤ã³ã©ã¤ã³ã³ã¼ãé¨åã§ã®Rustã®æ¡ç¨ãçå£ã«è°è«ãã¦ããããã®è°è«ã¯ç¾å¨ã©ããªã£ã¦ããã®ã ãããï¼çè ã¯Linuxã®ç¶ã¨ç®ãããLinus Torvaldsæ°ã¨ãLinuxã®å®å®çã«ã¼ãã«ã®ã¡ã³ããã¼ã§ããGreg Kroah-Hartmanæ°ããèããèããã ããã¯Rustã«é äºãããä¸é¨ã®éçºè ãã«ãã£ã¦æ¨ãé²ãããã¦ããæºä¸ã®ç©ºè«ã§ã¯ãªããLinuxã§Rustãç©æ¥µçã«å©ç¨ãããã¨ããã¢ããã¼ãã¯ãæ¢ã«ä¸ã®ä¸ã§è¦ãããããã«ãªã£ã¦ãã
Anonymous Cowardæ°ãã Chromiumããã¸ã§ã¯ãã¯ä»é±ãé大度ã®é«ãã»ãã¥ãªãã£ãã°ã®ç´70ï¼ ã¯ãã¡ã¢ãªã®å®å ¨æ§ã«é¢ããåé¡ï¼ãã¤ã³ã¿ã®èª¤ãï¼ã«ç±æ¥ããã¨çºè¡¨ãããããã¯Googleã®ã¨ã³ã¸ãã¢ã2015年以éã®912ã®é大度ã®é«ãããããã¯é大ãªã»ãã¥ãªãã£ãã°ãåæããçµæããå°ãåºããããã®ã ã¨ãããããã¯ã¦ã¼ã¶ã¼ã®ã»ãã¥ãªãã£ãå±éºã«ãããã ãã§ãªããChromeã®ä¿®æ£ã¨åºè·ã«ããã¦ã³ã¹ããå¢å¤§ããã¦ããã¨ãã¦ããã åæ§ã®åé¡ã¯Microsoftãææãã¦ããã2019å¹´2æã®ã»ãã¥ãªãã£ä¼è°ã§è¬æ¼ããMicrosoftã®ã¨ã³ã¸ãã¢ã¯éå»12å¹´éãMicrosoft製åã®ãã¹ã¦ã®ã»ãã¥ãªãã£ã¢ãããã¼ãã®ç´70ï¼ ãã¡ã¢ãªã®å®å ¨æ§ãåå ã ã£ãã¨ææãã¦ããã端çã«è¨ãã°ãã³ã¼ããã¼ã¹ã§2ã¤ã®ä¸»è¦ãªããã°ã©ãã³ã°è¨èªã§ããCã¨C++ã¯ãå®å ¨ã§ãªããè¨èªã§ããã¨ãã
ãã®è¨äºã¯PHP Advent Calendar 2019ã®5æ¥ç®ã®è¨äºã§ãã ã¯ããã« ç§ã¯6å¹´åã«ãPHP Advent Calendar 2013ã¨ãã¦ãPHPã ã£ã¦ã·ã§ã«çµç±ã§ãªãã³ãã³ãå¼ã³åºãæ©è½ã欲ãããã¨ããè¨äºãæ¸ãã¾ããããã®ä¸ã§ãOSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çã®æ ¹æ¬çãã¤å®å ¨ãªå¯¾çã¯ãã·ã§ã«ãçµç±ããªãã³ãã³ãå¼ã³åºããã§ãããã¨ãææããä¸ã§ãæ«å°¾ã«ä»¥ä¸ã®ããã«æ¸ãã¾ããã PHPã³ããã¿ã®ã¿ãªãã¾ãPHP5.6ã®æ°æ©è½ã¨ãã¦ãã·ã§ã«ãçµç±ããªãã³ãã³ãå¼ã³åºãã®æ©è½ã追å ã§ãã¾ããã? ç¾å®ã«ã¯å½æããPCNTL颿°ã«ã¦ã·ã§ã«ãçµç±ããªãã³ãã³ãå¼ã³åºãã¯ã§ããã®ã§ãããå½é¢æ°ã®ä½¿ç¨ãé£ãããã¨ã¨ãCLIçãããã¯CGIçï¼FastCGIã¯å¯ï¼ã®PHPã§ãªãã¨ãµãã¼ãããã¦ããªããªã©ã®å¶éããããpopenãproc_openãªã©ä½¿ããããã³ãã³ãå¼ã³åºã颿°ã«
解決çã¯ããã¾ã§ããã£ããâ¦â¦ éçºè ãå®å ¨ãªã³ã¼ãã使ã§ããããæ¯æ´ãããã¼ã«ã¯å¤ããå¦ç¿ã«1ï½2ã«æã¯å¿ è¦ã¨ãªããããªè¤éãªéçåæãã¼ã«ããã¯ã©ãã·ã¥ããå ´åã®åªå é ä½ã決ãããã¨ãå¯è½ãªå¤§è¦æ¨¡ãªãã¡ã¸ã³ã°ããã¤ã³ãè§£æãå¶ç´ã½ã«ãã¼ãªã©ã ã éçºè ãå®å ¨ãªãã©ã¯ãã£ã¹ãæ¡ç¨ããããã®ã¬ã¤ãã³ã¹ããããã»ãã¥ã¢ãªéçºã©ã¤ããµã¤ã¯ã«ããã³ã¼ãã£ã³ã°ã¬ã¤ãã©ã¤ã³ã使éãã®ã³ã¼ãã¬ãã¥ã¼ããã¬ã¼ãã³ã°ãè å¨ã¢ããªã³ã°ã®ã¬ã¤ãã³ã¹ãªã©ã ã Microsoftã«ããæ¹åãããããVisual Studioãã¯æ½å¨çãªæ¬ é¥ã強調ãã表示ãåºåãããå社ã¯ã³ã³ãã¤ã©ãæ¹åããã¡ã¢ãªç ´å£ãèµ·ãããããªã¨ã©ã¼ããéçºè ãå®ããã¨ãã¦ããã ããããããã°ã©ãã³ã°è¨èªãããºãã®ã§ã¯ï¼ ããã«ãããããããã¡ã¢ãªç ´å£ãã°ã¯ä¸åã«æ¸ã£ã¦ããªããããã¯éçºè ã«éãããã®ã ãããã éçºè ã®æ¬åã¯ãã»ãã¥ãª
CVE-2019-5736ãè¦ãã¦ãã¾ããï¼ä»å¹´ã®2æã«è¦ã¤ãã£ãruncï¼Dockerãããã©ã«ãã§å©ç¨ãã¦ããã³ã³ããã®ã©ã³ã¿ã¤ã ï¼ã®èå¼±æ§ã§ããã¹ãã®runcãã¤ããªã好ãåæã«ã³ã³ããå é¨ããæ¸ãæãããã¨ãã§ããã¨ãããã®ã§ãã èå¼±æ§ã®ä»çµã¿ã«èå³ããã£ãã®ã§èª¿ã¹ãã¨ãããã³ã³ãããæ»æããæ¹æ³ã¨ããã®ã¯ä»ã«ããããããã£ã¦ãruncã¯é å¼µã£ã¦ãããå¡ãã§ããããã§ããããã¾ã¨ããã¨é¢ç½ããããã¨æã£ãã®ã§ä»¥ä¸ã®ãããªããã¡ããä½ãã¾ããã Drofuneã¯ç°¡åãªã³ã³ããã©ã³ã¿ã¤ã ã§ããdrofune runã¨ãdrofune execãªã©ã§ã³ã³ãããèµ·åããããå ¥ã£ãããããã¨ãã§ãã¾ããã¨ããã°æ³åãã¤ãã§ããããã ããã ãã§ã¯ä½ãé¢ç½ããªãã®ã§ãDrofuneã¯ããã¨å®å ¨ã§ãªãå®è£ ã«ãªã£ã¦ãã¾ãããªã®ã§ãä»åçºè¦ãããCVE-2019-5736ãå©ç¨ããæ»æãæç«ãã¾ã
ã»ãã¥ãã£ã³ã®Cã³ã³ãã¤ã©ä½æã³ã¼ã¹ã®è©±ãCGã§ããã§ã¦ãããã£ã¼ãããã®å®ç©ãå ¥æãã話ãhikaliumã®ä¸å¦çæä»£ã®OSèªä½ã®è©±ããã¾ãããåºæ¼è : hikalium (@hikalium)ãRui Ueyama (@rui314) https://turingcomplete.fm/29 ããã·ã¥ã¿ã°ã¯#tcfmã§ãã TCFMã¯ãµãã¼ã¿ã¼ã®æãéã«ãã£ã¦åçãä¸ãã¦ãã¾ãããã®ã³ã³ãã³ãã«èª²éãã¦ããããã¨ããæ¹ã¯ãã²ã¯ãªã¨ã¤ã¿ã¼æ¯æ´ãµã¤ãPatreonããç»é²ãã¦ãååãã ããã ã¤ã³ãã (0:00) ã»ãã¥ãã£ã³äºåå¦ç¿å§ã¾ãã¾ãã (1:33) ãä½ã¬ã¤ã¤ãç¥ããã人ã®ããã®Cã³ã³ãã¤ã©ä½æå ¥éãï¼ä»®é¡ï¼ãç¾å¨7ä¸å (3:58) Cã®ä¸å¯è§£ãªè¨èªä»æ§ã®ã«ã¼ããç¥ãããã«1972å¹´ã®æåæã®Cã³ã³ãã¤ã©ã®ã³ã¼ããèªãã§ã¿ã (6:07) ç¬¦å·æ¡å¼µã¨ãã¤ãã¹2鲿° (13:
æ¥æ¬PHPã¦ã¼ã¶ä¼ã¯2018å¹´12æ15æ¥ã«PHP Conference 2018ãéå¬ãããæ¬ç¨¿ã§ã¯ãEGã»ãã¥ã¢ã½ãªã¥ã¼ã·ã§ã³ãº 代表åç· å½¹ 徳丸浩æ°ã®è¬æ¼ãå®å ¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹2018ãã®å 容ãè¦ç´ãã¦ãä¼ãããã 徳丸æ°ã¯ãå²è³¦ï¼ãã£ã·ï¼è²©å£²æ³ã®æ¹æ£ããçµæ¸ç£æ¥çãæ¨å¥¨ãããã¯ã¬ã¸ããã«ã¼ãæ å ±ã®éä¿æåããç´¹ä»ãé大ãªã»ãã¥ãªãã£ãªã¹ã¯ãç¡è¦ããå ´åãã¯ã¬ã¸ããã«ã¼ãæ å ±ï¼ä»¥ä¸ãã«ã¼ãæ å ±ï¼ãéä¿æåããã·ã¹ãã ã§ããã«ã¼ãæ å ±ãçã¾ããå¯è½æ§ãããã¨ææããã ã¯ã¬ã¸ããã«ã¼ãå¨ãã®ã»ãã¥ãªãã£å¯¾çã®åå 徳丸æ°ã¯ãã«ã¼ãæ å ±ã«é¢é£ããæ³å¾ã®ååã¨ãã¦ãå²è³¦è²©å£²æ³æ¹æ£ã¨çµæ¸ç£æ¥çã®å®è¡è¨ç»ãæç²ãã¦ç´¹ä»ãå²è³¦è²©å£²æ³ã¨ã¯ãã¯ã¬ã¸ããã«ã¼ããªã©ã«ããä¿¡ç¨åå¼ã«é¢ããæ³å¾ã ã2018å¹´6æ1æ¥ã«æ¹æ£ãããã¯ã¬ã¸ããã«ã¼ããåãæ±ãäºæ¥è ã«å¯¾ãã¦ãã«ã¼ãæ å ±ãæ¼ãããã
1. ã¯ããã« æè¿ãããã£ã¦Nodeã®ã»ãã¥ãªãã£èª¿æ»ããã¦ããã®ã§ãããä»å¹´ã®5æã«éå¬ããã North Sec 2018 ã§ã»ãã¥ãªãã£ç ç©¶è ã® Olivier Arteau æ°ã«ãã ãPrototype pollution attacks in NodeJS applicationsãã¨ããé¢ç½ãçºè¡¨ãè¦ã¤ãã¾ããã ãã®çºè¡¨ã®è«æãçºè¡¨è³æããã¢åç»ãªã©ãgithubã§å ¬éããã¦ãã¾ãããã¡ããã©ã¿ã¤ãã³ã°ããã»ãã·ã§ã³åç»ãæè¿å ¬éããã¾ããã github.com Olivier Arteau -- Prototype pollution attacks in NodeJS applications ãã®çºè¡¨ã§è§£èª¬ããã¦ããã®ã¯ãæªæã®ããæ»æè ããJavaScriptè¨èªåºæã®ãããã¿ã¤ããã§ã¼ã³ã®æåãå©ç¨ãã¦ãWebãµã¼ããæ»æããæ¹æ³ã§ãã çºè¡¨è ã¯ãnpmããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}