Code Archive Skip to content Google About Google Privacy Terms
ãHacking Intranet Websites from the Outsideãã¨ããè¬æ¼ã2006å¹´ã«ããã¾ããã Black Hatã§ã®è¬æ¼ã§ãã 以ä¸ã«èª¬æããææ³ã¯æ¢ã«å ¬éããã¦ããç¨åº¦æéãçµéãã¦ããæ å ±ãªã®ã§ããåç¥ã®æ¹ã«ã¨ã£ã¦ã¯æ¢ã«å¤ãã¨ã¯æãã¾ãã 詳細ã¯ãã¬ã¼ã³è³æãã覧ä¸ããã æ¦è¦ ãã¡ã¤ã¢ã¦ã©ã¼ã«ãªã©ã«å®ãããã¤ã³ãã©ãããããã¼ã ãããã¯ã¼ã¯ã®å é¨ãæ»æããææ³ã解説ãã¦ããã¾ããã JavaScriptã®åºæ¬ä»æ§ãçµã¿åããã¦æ å ±ãåéããã¨ãããã®ã§ããã æçµçã«ã¯ãããªã³ã¿ããå°å·ãè¡ã£ãããã«ã¼ã¿ã®è¨å®ã夿´ãããªã©ã®æ»æãå¯è½ã«ãªãããã§ãã ãã以å¤ã«ããWebçµç±ã§è¨å®å¤æ´ãåºæ¥ããã®ã¯ç¶æ³ã«ãã£ã¦ã¯å½±é¿ãããããç¥ãã¾ããã ãã¬ã¼ã³å¾åã§ã¯CSRF(XSRF, cross-site request forgery)ã解説ããã¦ãã¾ãã
ã¨ã¦ãã·ã³ãã«ã«èªåèªèº«ãå±ãã script è¦ç´ ãåå¾ http://d.hatena.ne.jp/amachang/20061201/1164986067 document.writeãDOM仿§ã«ãã http://nyarla.net/blog/javascript-tips1 ãããã«çæ³ãåãã¦ãä½ã£ã¦ã¿ã¾ããã http://la.ma.la/misc/js/lazy_writer/ ç¹å®ã®script srcå ã®document.writeããã³ãã¤ã³ãã«ç½®ãæãããã¨ãã§ãã¾ãã å¶éäºé ã¨ãã¦ã¯ãdocument.writeã使ã£ã¦scriptã¿ã°ãçæãããããªã³ã¼ãã®å ´åãIEã§ã¯innerHTMLã«scriptãæ¸ãã¦ãå®è¡ãããªãã¨ãã仿§ãããã®ã§å®è¡ããã¾ããããã®ç¹ãé¤ãã°ãIFRAMEãdocument.writeã§æ¿å ¥ãããããªãè¯ãããåºåç³»ã®do
â»å ¬éç¨ã«ããã¤ãæãå ãã¦ããã¾ã åããªãé·ãã¨ã®ããã³ããããã¾ããã®ã§ãä»åã®çºè¡¨å 容ãå°ãè¦ç´ãã¦ã¿ããã¨æãã¾ãã 1. GIF Format Hacks (Server side) ã¾ãã¯ãä»»æã®pixelãµã¤ãºï¼å¹ ã»é«ãï¼ãæã£ãç»åãã¡ã¤ã«ãåºå®é·ã®35byteã§åºåããæ¹æ³ #!/usr/bin/perl use strict; use warnings; sub create_gif { my $size = pack "S2", @_; return "GIF89a$size\xf0\x00\x00\x00\x00\x00\xff\xff\xff," . "\x00\x00\x00\x00\x01\x00\x01\x00\x00\x02\x02L\x01\x00;"; } print "Content-Length: 35\n"; print "Content-Ty
My experiments with .Net : Combine CSS with JS and make it into a single download! ï¼ã¤ã®ãã¡ã¤ã«ã«JavaScriptã¨CSSãã¾ã¨ãã¦è¨è¿°ããæ¹æ³ã ã¾ããtest.jscss ã¨ãããã¡ã¤ã«ãä½ã£ã¦ã次ã®ããã«å 容ãè¨è¿°ãã¾ãã <!-- /* function t(){alert('test');} <!-- */ <!-- body { background-color: Aqua; } ããã¦ã次ã®ããã«JavaScriptã¨CSSãå¼ã³åºãéã«å ã»ã©ä½æããtest.jscssãæå®ãããã¨ãã§ãã¾ãã <html> <link type="text/css" rel="stylesheet" href="test.jscss" /> <script type="text/javascript"
ã¯ã¦ãªããã¯ãã¼ã¯ãããããããï¼ ã¨ããã§ãã¼ããã¯ã¦ãªããã¯ãã¼ã¯ã§ä¸çªä½¿ãã·ã³ãã«(?)ã£ã¦ [B!] ã§ã [âB] ã§ããªã [108 users] ã ã¨æããã ãã©ï¼ ã ããèªåã®ãµã¤ãã§ users ã表示ã§ãããã¤ãã¤ãã£ã¦ã¿ããï¼ï¼ â ã²ã¦ã(js) v0.2 (ãã¦ã³ãã¼ã) ã©ããªæããã¯ããµã³ãã«ãã¼ã¸ãã¿ã¦ãï¼ ã¤ããããã¯ããã ãï¼ 1. ã¾ã㯠prototype.js ããã¦ã³ãã¼ããã¦ãèªåã®ãµã¤ãã«è»¢éãã¦ããããï¼ 2. ããã¦ãã£ãã® hihate_v01.zip ã®ä¸ã® nuluerer.cgi ãããã¿ã®ãµã¤ãä¸ã«ç½®ãã¦ãã¼ããã·ã§ã³ã®è¨å®ã ï¼ chmod 755 nuluerer.cgi 3. ã¤ãã«ä½¿ããããã¼ã¸ã® <head> ã®ä¸ã«ä»¥ä¸ã®ããã«è¨è¿°ãã¦ãï¼ <script type="text/javascript" src="prot
IE5.5ã«ã¤ãã¦ã¯ãif gte IE 5.5ãã¯éãã®ã«ãif IE 5.5ããéããªãããã§ãã ãif IE 5.5000ããªã©ã¨ããªãªã以ä¸4æ¡å ¨ã¦æ¸ãã¨éãã¾ãã
ActivePerl ã§ PerlScript 㨠Google Maps Google Maps ã ThinkPad å é度ã»ã³ãµã¼ã§æä½ ã¨ãããã¤ã¹ãªããã¯ããã£ã¦ã¿ãããã§ãããã¡ãã£ã¨æè¡çãªé¨åã解説ã ã¾ã ThinkPad ã®å é度ãèªãé¨åã¯ãGoogle ã§æ¤ç´¢ããã¨ã http://www.hirax.net/misc/AccelerometerThinkpad/AccelerometerThinkpad.h http://blog.netswitch.jp/files/leap-frog.zip ãããã®ã³ã¼ããè¦ã¤ããã¾ããC ã§æ¸ãã¨ã if( !DeviceIoControl( hFile, 0x733fc, NULL, 0, // via IOCTL(0x733fc) (void *)&AccelerometerData, 0x24, &ulRead, N
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}