æåã«ãæ倧ã®RunetããŒã¿ã«ã®1ã€ã§çºèŠããCSRFã®è匱æ§ã«ã€ããŠæžãã€ããã§ããã ãããããã®ããŒã¿ã«ã ãã§ãªããæ倧ã®ãªãœãŒã¹ã®ã»ãšãã©ããããã®è匱æ§ã®åœ±é¿ãåããããšãå€æããŸããã 1ã¶æååã«åé¡ãããããã®äŒç€Ÿã«å ±åããŸããã ä»ãç§ã¯åã³æéãããããã§ã«éããŠãããã®ãèŠãŸããã 1ãæåã§ããã£ã1ã€ã®è匱æ§ãã¯ããŒãºãããããšãå€æããŸããã
ãªããªã è匱æ§ã¯ãŸã æ©èœããŠããã®ã§ãèŠã€ããå Žæãšãã®äœ¿çšæ¹æ³ã«ã€ããŠã®ã¿èª¬æããŸãã åŠçãšäž»å©Šã掻çšã§ããããã«ã1é±éã§ãããŒã®å®äŸãäœæããããšãçŽæããŸãã é ããªãã£ãã®ã¯ç§ã®ããã§ã¯ãããŸããã
é°è¬ïŒç§ã¯ãYandexãRamblerãMail.ruãVkontakteãLJãããã³ãã®ä»ã®äžè¬çãªãªãœãŒã¹ã®è匱æ§ãæ¢ããŠããŸããã èŠã€ããè匱æ§ã®å Žæãšãã®çš®é¡ãèŠã€ããã®ãåŸ ã¡ãããªãå Žåã¯ããè匱æ§ãªã¹ããã»ã¯ã·ã§ã³ã«é²ãã§ãã ããã
å¿ èŠãªè匱æ§ãç解ããã«ã¯ãå°ãªããšãCSRFãšã¯äœãã«é¢ããåºæ¬çãªç¥èãå¿ èŠã§ãã 圌ããããã«ããªããã°-ãã£ããããªãã§ãã ããã以äžã§ã¯ã¢ã¯ã»ã¹å¯èœãªæ¹æ³ã§ããã説æããããšããŸããïŒç§ã®æèŠã§ã¯ãããŸããããŸããã§ããïŒã ãã§ã«ãããäœã§ãããããŸãã¯ãã®éãç解ããŠããªãå Žåã¯ãè¡šé¢çãªç£æ»ã®çµæã«é²ãã§é²ãã§ãã ããã
ãŸã第äžã«ã ãŠã£ãããã£ã¢ãèªãããšã¯çã«ããªã£ãŠããŸã ã ããªããè±èªã§æ lazãèªãã å ŽåïŒãŠã£ãããã£ã¢ã®ãããã¯ã«ã¯ã»ãšãã©äœããããŸããããããã¯ã¯Habréã§éåžžã«è²§åŒ±ã«ã«ããŒãããŸãïŒãäœããç¥ãããå Žåã¯ããã®è匱æ§ã説æãã
UPD 2ïŒè匱æ§ãå®èšŒãããŠãããäŸã¯ãããŸã§åé€ãããŸããã
UPD 3ïŒé±ãéããŸããã äœæ¥/äœæ¥äŸãåºããŸãã æéã¯çãã®ã§ããŸã äœãæ©èœããŠããŠäœãæ©èœããŠããªããã確èªããŠããŸããã ãã®ããšã«ã€ããŠã³ã¡ã³ãã§æžããŠããã ããã°å¹žãã§ãã ãã¹ãŠã®è³ªåãåžæãææ¡ã¯ã ãã®ã³ã¡ã³ããžã®åçã«ãããŸãã
ã©ã³ãã©ãŒ ã Mail.Ru ã Liveinternet ã Yandex
CSRFãšã¯äœã§ããïŒ
Webã¢ããªã±ãŒã·ã§ã³ã§ã¢ã¯ã·ã§ã³ãå®è¡ããã«ã¯ããŠãŒã¶ãŒã¯HTTPèŠæ±ãéä¿¡ããŸãã ã©ã®ãŠãŒã¶ãŒã«ä»£ãã£ãŠã¢ã¯ã·ã§ã³ãå®è¡ãããããå€æããããã«ãéåžžãããŒã¿ãCookieã«ä¿åãããŠããã»ãã·ã§ã³ã䜿çšãããŸãã ãµãŒããŒã¯ãªã¯ãšã¹ããåä¿¡ããCookieã調ã¹ãCookieããŒã¿ã«é¢é£ä»ããããã»ãã·ã§ã³ãååšããããšã確èªãããã®ã»ãã·ã§ã³ã«é¢é£ä»ãããããŠãŒã¶ãŒã«ä»£ãã£ãŠã¢ã¯ã·ã§ã³ãå®è¡ããŸãã ãŠãŒã¶ãŒããæ°ã«å ¥ãã®ãªãœãŒã¹ã«ãã°ã€ã³ãããŸãŸã«ããããã«ããã©ãŠã¶ã¯ããããã€ã³ã¹ããŒã«ãããµãŒããŒã«èªåçã«ã¯ãããŒãéä¿¡ããŸãã ãããã£ãŠããŠãŒã¶ãŒã®ãã©ãŠã¶ãŒããèŠæ±ãéä¿¡ããããšãCookieãäžç·ã«éä¿¡ãããŸãã ãããŠããµãŒããŒã¯ããªãœãŒã¹ã®ãã°ã€ã³ãŠãŒã¶ãŒãåŠçããŠãããšèãããŠãŒã¶ãŒã«ä»£ãã£ãŠã¢ã¯ã·ã§ã³ãå®è¡ããŸãã ãŸãããã©ãŠã¶ã«ãµãŒãããŒãã£ã®ããŒãžãããªã¯ãšã¹ããéä¿¡ãããããšãã§ããŸãã ãµãŒããŒããã®ãããªãªã¯ãšã¹ãããã®ããŒãžããã®ãªã¯ãšã¹ããšåãæ¹æ³ã§åŠçããå Žå-ãããè匱æ§ã§ãã
䜿ãæ¹ã¯ïŒ
ãã¡ããå°ããããã«ããã®ã§ãç°¡åãªäŸã§ãã å šäœã®èª¬æããã圌ã ããèªãããšãå¯èœã§ãã
人æ°ã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ãããããã¡ã€ã«ãåé€ããã«ã¯ãVasyaã[ãããã¡ã€ã«ã®åé€]ãªã³ã¯ãã¯ãªãã¯ããå¿ èŠããããŸããããã«ãããhttpïŒ//vulnerable.site/delete_profile.phpïŒsure = yesããŒãžã衚瀺ãããŸãã Petyaã¯ããã®ã¢ãã¬ã¹ã«ã¢ããããŒãããåçãèªåã®ããŒãžã«é 眮ããŸãïŒãã®ã¢ãã¬ã¹ã«åçããªãããšã¯æããã§ããããã©ãŠã¶ã¯äºåã«ãããç¥ããŸããïŒã VasyaãPetyaã®ããŒãžã«ã¢ã¯ã»ã¹ãããšãVasyaã®ãã©ãŠã¶ã¯ãã®åçãããŠã³ããŒãããããšããŸãã 圌ã¯åçãèŠã€ãããããèœã¡çããŸãã ãããã人æ°ã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ã¯ãVasyaã«ä»£ãã£ãŠãããã¡ã€ã«ãåé€ããã³ãã³ããåãåããŸããã ãããŠãVasyaã®ãããã¡ã€ã«ã¯å®å šã«åé€ãããŸããã ããããããªãã¯ãŸã ç解ããŠããªã-VasyaãšPetyaãAliceãšBobãšäº€æããŠããäžåºŠèªãã§ãã ããã ãããã®VasyaãšPetyaããã¯åžžã«å€§ããªæ··ä¹±ããããŸãã
ãã®ããã䜿çšããã«ã¯ããŠãŒã¶ãŒãèªåã§äœæããããŒãžïŒãŸãã¯ãXSSãä»ããŠã³ãŒããæçš¿ãããŠããXSSã®ããããŒãžã«èªå°ããå¿ èŠããããŸã-ãã ãããã®èšäºã«éãã¯ãããŸããïŒã ãã®ããŒãžã«ã¯ããªã¯ãšã¹ããéä¿¡ãããã®ãããã¯ãã§ãã æãç°¡åãªæ¹æ³ã¯ãåçãé 眮ããããšã§ãã
<img src="http://vulnerable.site/delete_profile.php?sure=yes"/>
人æ°ã®ããã°ãããã¯ããŠãããã«é衚瀺ã®iframeãæçš¿ããããšãã§ããŸã-çµæã¯é©ãã¹ããã®ã«ãªããŸãã
ãããŠãç§ã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ããã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯POSTãªã¯ãšã¹ããä»ããŠå®è¡ãããŸã
äœããã®çç±ã§ãå€ãã®éçºè ã¯ãPOSTãªã¯ãšã¹ãã®éä¿¡ãå¿ èŠãšããCSRFã®è匱æ§ãæªçšããããšã¯äžå¯èœã§ãããšç¢ºä¿¡ããŠããŸãã éåžžãJSãä»ããŠå¥ã®ãã¡ã€ã³ã«POSTèŠæ±ãéä¿¡ããããšãã§ããªããšããäºå®ã«ãã£ãŠã圌ãã¯ãããåæ©ä»ããŸãã ããã¯äºå®ã§ãïŒå°ãªããšãéåžžã®æ¡ä»¶äžã§ã¯ïŒã ããããäœããã®çç±ã§ã圌ãã¯åžžã«
ç§ã¯ãŠãŒã¶ãŒã§ã-ã©ãããã°èªåãå®ãããšãã§ããŸããïŒ
ããã§ç§ã¯ããªããæ··ä¹±ãããå¿ èŠããããŸãã èªåãå®ãå¯äžã®æ¹æ³ã¯ãã€ã³ã¿ãŒãããã䜿çšããªãããšã§ãã ãŸãã¯ãå°ãªããšãã©ããã§ãã°ã€ã³ããå¿ èŠãããéšåïŒãœãŒã·ã£ã«ãããã¯ãŒã¯ãTwitterãé»åã¡ãŒã«ããã©ãŒã©ã ãªã©ïŒã ãããããã¡ããããªãœãŒã¹ã䜿çšããçŽåŸã«ã»ãã·ã§ã³ãéãããŸãŸã«ãããåžžã«çµäºãã¿ã³ãæŒãããšã¯ã§ããŸããã ãã°ã€ã³ããŠããé-ããªãã¯è匱ã§ãã éåžžã®ãŠãŒã¶ãŒã¯ãéçºè ã®ããæèãšããŠãŒã¶ãŒã®é¢åãèŠããšããäºå®ã«ã®ã¿é Œãããšãã§ããŸãã ãããŠãåžæã¯ã»ãšãã©ãããŸããã
UPDïŒ FFã«ã¯ã¢ããªã³ããããŸã-RequestPolicy ã Vanavã«æè¬
ç§ã¯éçºè ã§ã-ãŠãŒã¶ãŒã®äžè©±ãããæ¹æ³ã¯ïŒ
ãŠãŒã¶ãŒã®äžè©±ãããããšã§ã-CSRFãµãŒããŒã䜿çšããŠãç¡å¹ã«ãªãããSSHã¯ã¢ã¯ã»ã¹ãèš±å¯ããŸããã ãŠãŒã¶ãŒã«ä»£ãã£ãŠããã€ãã®ã¢ã¯ã·ã§ã³ãå®è¡ãããŸãã ãŸãããŠãŒã¶ãŒèªèº«ãããããæºããããšãã§ããŸãã ãããã£ãŠãäžéšã®éçºè ã¯ãããè匱æ§ãšã¯èŠãªããŠããŸããã ãããŠãç§ã¯ãã®æ 床ãé²éªšãªéãããã§ãã·ã§ããªãºã ã§ãããèªåã®ãŠãŒã¶ãŒã«åãåºããŠãããšèããŠããŸãã è·æ¥ããæãåºãã ããã«ããã®è匱æ§ã¯æ±ºããŠæ°ãããã®ã§ã¯ãããŸããã
ä¿è·æ¹æ³ã«ã€ããŠè©³ããã¯ãããã説æããŸãã-æ¹æ³ããªã¹ãããå°ããªã³ã¡ã³ããä»ããã ãã§ã-ãªããªã ããªããéçºè ã§ããã°ãããªãèªèº«
ç§ã¯ããã«è±èªçãŠã£ãããã£ã¢ããã¡ãœãããååŸãããšèšããªããã°ãªãããç§ã®æèŠã§ã¯ããããã®å€ãã¯ä¿è·ãããŠããŸããã
- åã¢ã¯ã·ã§ã³ã®ã¯ã³ã¿ã€ã ããŒã¯ã³ãæãä¿¡é Œæ§ã®é«ãæ¹æ³ã§ããå人çã«éžæããŸã
- åãªã¯ãšã¹ãã§ã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®èŠæ±ãä¿¡é Œã§ããŸãããHTTPSã䜿çšããªãå Žåã¯ãã¹ããã¡ãŒã䜿çšããŠãªã¯ãšã¹ããããã¹ã¯ãŒããçãããšãã§ããŸã
- ã»ãã·ã§ã³ã®åç¶æéãå¶éãã- äœã«å¯ŸããŠãä¿è·ãããæªçšãããå¯èœæ§ã®ããæéãåã«ççž®ãã
- RefererããããŒã確èªããã®ã¯æªããããŸãããããã®ããããŒã¯åžžã«èšå®ãããŠããããã§ã¯ãããŸãããæåã®æ¹æ³ããå§ãããŸã
- clientaccesspolicy.xmlããã³crossdomain.xmlïŒããããSilverlightããã³Flashã®å ŽåïŒãæªæ€èšŒã®ãœãŒã¹ããã®ãªã¯ãšã¹ããèš±å¯ããªãããšã確èªããŠãã ãã- ããã¯æåã«ãã¢ããããã¯ã解é€ãã誰ã§ãæ©ããŠããä¿è·ããããã«ãããæããæ¹æ³ã§ã
- X-Requested-Withã確èªããŸã-AJAXãªã¯ãšã¹ãã«åœ¹ç«ã¡ãŸãããããã§ãåžžã«ã§ã¯ãããŸãã
ç·Žç¿ãã
åºæ¬çã«ãCSRFãèŠã€ããããšã¯éåžžã«ç°¡åãªäœæ¥ã§ãã é¢å¿ã®ãããªãœãŒã¹ã«ã¢ã«ãŠã³ããèšå®ããFirebug / Chrome Developer Toolsããªã³ã«ããŠãéåžžã®ãŠãŒã¶ãŒãè¡ãããšãã¹ãŠãè¡ããŸã-ã¡ãŒã«ããã¯ã¹ã®èšå®ãèªã¿åããæžã蟌ã¿ãæçŽã®åé€ãããã°ãžã®æžã蟌ã¿ãªã©ã åæã«ãéä¿¡ããããªã¯ãšã¹ãã確èªããããšãå¿ããªãã§ãã ããã èŠæ±ã«çæãããããŒã¿ïŒããŸããŸãªã¯ã³ã¿ã€ã ããŒã¯ã³ïŒãæœåšçãªè匱æ§ã§ããæ¹æ³ãäžå¯è§£ã«å«ãŸããŠããªãå Žåã ããŒã«ã«ããŒãžãããã®ãªã¯ãšã¹ããç¹°ãè¿ããçµæã確èªããŸãã ã¢ã¯ã·ã§ã³ãçºçããå Žåãè匱æ§ãçºèŠãããŸããã ãã©ãŒã ã䜿çšããŠããŒãžãäœæãããµãŒããŒã«ã¢ããããŒãããŠããã®ããŒãžãä»ã®ããŒãžããé衚瀺ã®iframeã«èªã¿èŸŒã¿ãŸã-äœæ¥ãå®æŒããããã«ïŒãŸãã¯å·¥æ¥çšã«ïŒã ããªãã¯ãŸã ããªãã®å人ã®äœäººããèŠããŠã圌ãããã§ãã¯ããããšãã§ããŸãã è匱æ§ãšå人ãšã®é¢ä¿ãå·éã«è©äŸ¡ããã ãã§ãã¢ã«ãŠã³ããã30äžãã«ãééãããå Žåã«ã¯ã©ã¹ã¡ãŒãã®Petyaãæºè¶³ããããšã¯ã»ãšãã©ãããŸããã
äžéšã®ãªã¯ãšã¹ãã¯ãFirebugãŸãã¯Chrome Developer Toolsã®ãããã§ã远跡ã§ããŸããã§ãããæåã«AJAXãªã¯ãšã¹ããéä¿¡ãããJSã䜿çšããŠã¬ã¹ãã³ã¹ãåä¿¡ãããšã次ã®ããŒãžãéããŸãã ãã®å Žåãé¢å¿ã®ãããªã¯ãšã¹ãã¯æ°ç§éãã衚瀺ãããŸããã ããããã ããWiresharkããé ãããšã¯ã§ããŸããã
UPDïŒã³ã¡ã³ãã®è³¢ã人ã¯ãFireBugã«ã¯ãã¯ãªã¢ããªãããã¿ã³ããããChromeéçºè ããŒã«ã«ã¯ãããã²ãŒã·ã§ã³æã«ãã°ãä¿åããããããããšã瀺åããŠããŸã
è匱æ§ãæ€çŽ¢ããå Žåãè¿œå ã®ãµãŒãã¹ïŒYandexã«ã¬ã³ããŒãªã©ïŒãšã¢ãã€ã«ããŒãžã§ã³ãå¿ããŠã¯ãªããŸããã
è匱æ§ã®ãªã¹ã
ç¹å®ã®ããŒã¿ã«ã§ãã¹ãŠã®CSRFå¯èŠæ§ãèŠã€ããã¿ã¹ã¯ãèªåã§èšå®ããŸããã§ããã åãªãœãŒã¹ã¯2æé以å ã«å²ãåœãŠãããŸããã ç§ã¯ãã·ã¢ã®ããŒã¿ã«ã®ã¿ããã§ãã¯ããŸãã-Google.ruãFacebook.comãªã©ã¯ããŸã æ®ã£ãŠããŸãã äžéšã®ããŒã¿ã«ã§ã¯ãå²ãåœãŠãããæéãäœãèŠã€ãããŸããã§ããããä¿è·æ¹æ³ã«é¢ããäžè¬çãªã¬ãã¥ãŒãæ®ãããã«ãªã¹ãã«è¿œå ããŸããã ãªã¹ãã®äžéšã®ããŒã¿ã«ã§ã¯ãRunetã§æ倧ã®ãã®ãæ€èšããŠããŸãããã䜿çšããè©äŸ¡ãèããŠããŸãã
Liveinternet.ru
CSRFã«å¯Ÿããä¿è·ã¯ãŸã£ãããããŸããã ãã©ã€ããŒãã¡ãã»ãŒãžã®éä¿¡ãããã°ãžã®æçš¿ãã³ã¡ã³ãã®äœæãã¢ã«ãŠã³ãã®åæ§æãªã©ãäžè¬çã«ã¯ãªãœãŒã¹ã§èš±å¯ãããŠããããšãªãäœã§ãã§ããŸãã ãããã£ãŠãè匱æ§ã®ãªã¹ããã³ã³ãã€ã«ããŸããã§ããã ãã®ãªãœãŒã¹ã¯ãç§ãæåŸã«å°éãããã®ã§ãããæ倧ã®ãã®ã®1ã€ãšã¯èããŠããŸããã 圌ã®åŸãç§ã®æã¯èœã¡ãŸãã-ãã¹ãŠããã§ã«æããã«ãªããŸããã
Rambler.ru
æ¹æ³1ã«åºã¥ãCSRFä¿è·-ã¯ã³ã¿ã€ã ããŒã¯ã³ã CSRFã¯ååšããªãããã«æãããŸãã ãããã第äžã«ããã®ä¿è·ã¯ã©ãã«ããããŸããã ãããŠã第äºã«ãããŒã¯ã³ã¯ãã§ãã¯ãããŸãã-ä»»æã®ããŒã¯ã³ïŒããã³ç©ºã®ããŒã¯ã³ãïŒãéä¿¡ã§ãããšã«ããã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸãã ãã©ãŒã ã®1ã€ã«è¿œå ã®ä¿è·ãšããŠãçŸåšã®ããŒãžã®ã¢ãã¬ã¹ãæã€é衚瀺ãã£ãŒã«ãããªãã¡ã©ãŒããèŠã€ããŸããã ç§ãå°ãæ³£ããŸããã
Ramblerã®éçºè ã¯ãããæ¥ããã®ãããªCSRFã®è匱æ§ããããããã«å¯ŸããŠä¿è·ããã«ã¯ããªã¯ãšã¹ãããšã«äžæã®ããŒã¯ã³ãéä¿¡ããå¿ èŠããããšèšããããšããå°è±¡ãåããŸãã ãããã圌ãã¯ããããã§ãã¯ããå¿ èŠããããšèšãã®ãå¿ããŠããŸããã
ã§ããããš
- RamblerãFriendsïŒèª°ããããã䜿çšããŸããïŒïŒã§ã¯ãä»»æã®ååã§å人ã®ã°ã«ãŒããäœæããããä»»æã®å人ãè¿œå ãŸãã¯åé€ããããå人ã®è¡åã«é¢ããéç¥ã®èšå®ãå€æŽããããå人ã«è¿œå ãããã§ããŸã
- ã¢ã«ãŠã³ãèšå®ã§ã¯ããŠãŒã¶ãŒããã©ãã¯ãªã¹ãã«è¿œå ãŸãã¯åé€ãããã眲åãå€æŽããããå Žæãå€æŽããããèå³ã®ãããªã¹ããå€æŽããããåéãªã¹ããšååã®è¡šç€ºãæå¹/ç¡å¹ã«ãããã§ããŸã
- ã¡ãŒã«ã§ã¯ããŠãŒã¶ãŒã«ä»£ãã£ãŠä»»æã®æåãéä¿¡ããä»»æã®é»åã¡ãŒã«ãžã®ç¡æ¡ä»¶è»¢éãæå¹ã«ãïŒä¿åããïŒãã¡ãŒã«èšå®ãå€æŽãïŒãµãŒãããŒãã£ãµãŒããŒããã®ç»åã®è¡šç€ºãæå¹ã«ããããšãç¹ã«éèŠã§ãïŒããã©ã«ããŒãããã¹ãŠã®æåãåé€ããŸãïŒå®éããããã¯ãŽãç®±ã«ç§»åããŸãïŒ ïŒãã¹ã±ããã空ã«ããŸã
- ãŸããã¡ãŒã«ã§æçŽãåé€ããæçŽã«æ¢èªã®ããŒã¯ãä»ããä»»æã®ã¡ãŒã«ããã¯ã¹ã«æçŽã転éã§ããŸãã 確ãã«ããã®ããã«ã¯ãã¬ã¿ãŒã®IDãšãã¬ã¿ãŒãä¿åãããŠãããã©ã«ããŒã®ååãç¥ãå¿ èŠããããŸãã ãInboxããšãSentãã®2ã€ã®ãã©ã«ããŒãç¥ãããŠããŸãã letter id-çŸåšã®ãã©ã«ããŒå ã®æåçªå·ãã ãã誰ããã«ãŒããã©ãŒã¹ããã£ã³ã»ã«ããŸããã§ãã
äžè¬çã«ãã¡ãŒã«ã«ããã¹ãã ãšè©æ¬ºã®å·šå€§ãªç¯å²ã æœåšçãªãŠãŒã¹ã±ãŒã¹ã«ã€ããŠãèããŠããŸããã§ãã-ãŠãŒã¶ãŒã®ç¥ããªããã¡ã«ã§ããªãããšãèšãæ¹ãç°¡åã§ãã
ããã¯å®å šãªãªã¹ãã§ã¯ãããŸããããªããªãã ä¿è·ã¯ãããŸããïŒãããä¿è·ãããŠããŸãããæ©èœããŸãããããã¯åçã§ãïŒã
Mail.ru
ã¡ãŒã«ã§ã¯ãæ¹æ³2ã«ããCSRFã«å¯Ÿããä¿è·-ãã¹ã¯ãŒãå ¥åã ã€ãŸã ããã¯æåã¯CSRFä¿è·ã§ã¯ãããŸãããããã¹ã¯ãŒãã®å ¥åãå¿ èŠãªå ŽåãCSRFãæ©èœããŸããã ä»ã®ãµãŒãã¹ã«ã¯éåžžã®ä¿è·ããããŸãã
ã ãããCISã®æã人æ°ã®ããéµäŸ¿ãµãŒãã¹ã«èŠããã匷迫芳念ã¯äœã§ãã
- ãŠãŒã¶ãŒã«ä»£ãã£ãŠãã¡ãŒã«ããã¯ã¹ã«ããã¹ããšä»¶åãä»ããŠæçŽãéä¿¡ããŸãã æ»æè ã®ã¡ãŒã«ããã¯ã¹ã«äžæã®ã³ãŒããèšèŒãããæçŽãéä¿¡ãããšã蚪åè ã®é»åã¡ãŒã«ã¢ãã¬ã¹ãèªèãããŸãã AJAXãä»ãããã®é»åã¡ãŒã«ã¯ããŠãŒã¶ãŒãæ¢ã«ååšããããŒãžã«å°éããŸã-ããã¯ãè匱æ§No. 2ãNoã7ãæªçšããã®ã«åœ¹ç«ã¡ãŸã
- ã¬ã¿ãŒã®ã³ããŒãä»»æã®ã¢ãã¬ã¹ã«éä¿¡ããŸãïŒã¬ã¿ãŒã¯éä¿¡ãããã¢ãã¬ã¹ã«ä¿åãããªãããããŠãŒã¶ãŒã¯ããã«ã€ããŠç¥ãããšãã§ããŸããïŒã ãã®è匱æ§ãæªçšããã«ã¯ãã¡ãã»ãŒãžIDïŒ20æ¡ïŒãç¥ãå¿ èŠããããŸãããæåã®10ã¯ã¿ã€ã ã¹ã¿ã³ãã§ã2çªç®ã®10ã¯ãã®2çªç®ã«ãµãŒããŒã«ãã£ãŠåŠçãããã¡ãã»ãŒãžã®æ°ã§ãïŒããã¯ãã¡ããå人çãªä»®å®ã§ãïŒã ç§ã®èŠ³å¯ã«ããã°ããã®æ°ã¯1000ãè¶ ããŸããããµãŒããŒã«äžåºŠã«1000æåãéä¿¡ããããã«èŠæ±ãããšãpro.mail.ruã€ã³ã¿ãŒãã§ãŒã¹ïŒã€ãŸãããã®è匱æ§ã¯ããã«ãããŸãïŒãã¡ãŒã«ããã¯ã¹ã«å®éã«æã£ãŠããæåãéä¿¡ããŸã3æå以äžãåæã«è»¢éããããšã¯äžå¯èœã§ããããšã ãã«ãŒããã©ãŒã¹ã䜿çšã§ããŸã-10ç§ã§åä¿¡ããæåãéä¿¡ããæ¯å1000åãã€è»¢éãèŠæ±ããŸãã è©æ¬ºã«ã¯1æ¥ããã2.5 GBã®çºä¿¡ãã©ãã£ãã¯ãå¿ èŠã§ããããã¹ã¯ãŒãã§æçŽãçãã®ã«ããã¯å¿ èŠãããŸãã-ãã¹ã¯ãŒãã¯ãŠãŒã¶ãŒã®ã¡ãŒã«ããã¯ã¹ã®ãµãŒãããŒãã£ãªãœãŒã¹ã«åŸ©å ããïŒ1çªããæ¢ã«ããã£ãŠããå¯èœæ§ããããŸãïŒãã¡ãã»ãŒãžã®å°çæå»ã¯ãã§ã«ã»ãŒããã£ãŠããŸã è匱æ§3ãšäœµçšã§ããŸã
- æçŽã®åé€-åã³IDã«ããã åã³ç·åœããã ãã¹ã¯ãŒãã®å埩ãéå§ãããã¹ã¯ãŒãä»ãã®ã¡ãŒã«ãçã¿ãåé€ããŸã
- SMSéç¥ã®æ¥ç¶ãšåæ-ããã§ã¯ãã¹ãŠãç°¡åã§ãã äžéšã®ã¡ãŒã«ããã¯ã¹èšå®ã¯ããã¹ã¯ãŒããå ¥åããã«å€æŽã§ããŸãã éç¥ããªãã«ããããšããæºåž¯é»è©±ã§éç¥ããªã³ã«ããããšãã§ããŸãïŒæ®µèœ7ã§çµã°ããŠããŸãïŒ
- éä¿¡ãããé»åã¡ãŒã«ã®ä¿åãç¡å¹ã«ããã¡ãŒã«ããŒãžã§Webã¡ãŒã«ãšãŒãžã§ã³ããæå¹ã«ããŸã-ãããã®ãã§ãã¯ããã¯ã¹ã¯èšå®ã®åãããŒãžã«ããã以åã®è匱æ§ãç¶æ ãå€æŽããããã«ãã¹ã¯ãŒããå¿ èŠãšããªãã£ãããã«ã éä¿¡ãããä¿åãç¡å¹ã«ããã®ã¯ç解ã§ããçç±ã§ãã ãŸããCSRFãããå Žåã¯ãWebã¡ãŒã«ãšãŒãžã§ã³ããæå¹ã«ããããšã¯çã«ããªã£ãŠããŸã
- ã¡ãŒã«ããã¯ã¹ã®ãµã€ãºå¶éã®ã¢ãããŒãã«é¢ããéç¥ããªãã«ããŸã-æ¬è³ªã¯åã®2ãšåãã§ãã éç¥ããªãã«ããŠã倧ããªæåã§ããã¯ã¹ãåããŸã
- é»è©±çªå·ããã€ã³ã/åé€ãã-ããã§ããã¹ãŠãããå°ãé¢çœãã§ãã ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã«ã¯ããŠãŒã¶ãŒã®é»åã¡ãŒã«ïŒãŸãã¯ãŠãŒã¶ãŒåãšãã¡ã€ã³ïŒãå¿ èŠã§ããããã¯ããã€ã³ãçªå·1ããååŸã§ããŸãã ãŸããé»è©±çªå·ãæå®ããå¿ èŠãããããããŠãŒã¶ãŒèªèº«ã®é»è©±çªå·ãåé€ããŠãæ©èœããŸããïŒå°ãªããšãäºåã«ç¥ããªãå Žå-ããšãã°ãã¡ãŒã«ãšãŒãžã§ã³ãã®èš±å¯ãããé£çµ¡å ã«è¡šç€ºãããŸã-ãã°ã€ã³æ¹æ³ã¯å¥ã®è³ªåã§ãïŒã é»è©±çªå·ããã€ã³ãããã«ã¯ããªã¯ãšã¹ããéä¿¡ããå¿ èŠããããŸãã ãã®åŸãã³ãŒãä»ãã®SMSãé»è©±ã«å±ããŸãã ãã®æ®µéã§ã¯ãSMSããã³ãŒããååŸããŠAJAXãªã¯ãšã¹ãã§ã¬ããŒããããœãããŠã§ã¢ãå¿ èŠã«ãªããŸãã ãã®ã³ãŒããåãåã£ãããŒãžã®JSã¯ãé»è©±çªå·ã®ãã€ã³ãã確èªããå¥ã®iframeãäœæããŸãã åãæ¹æ³ã§ãã®é»è©±çªå·ãåé€ã§ããŸãã æ¬åœã«äžã€ã®æ©èœããããŸã-é»è©±çªå·ãå¯äžã®ãã®ã§ããå Žåãããã¯15æ¥åŸã«ã®ã¿åé€ãããããã«ã¯åé€ãããŸããã SMSã®ã³ãŒããç¥ã£ãŠããå Žåã«ã®ã¿ãããã«åé€ã§ããŸãïŒãã€ã³ãã®å Žåãšåãã§ãïŒ
ã€ã³ããã¯ã¹
CSRFã«å¯Ÿããä¿è·ã¯ã ããããä»¥æ¥ Yandexã¯æ€çŽ¢ãã¡ãŒã«ã ãã§ãªããä¿è·ã¯ã©ãã§ãç°ãªããŸãã ãããŠã©ããã«ãäœããæ¬ ããŠããŸãã 3æ¥ä»¥å ã«Yandexãç§ã®æçŽã«åçããæ å ±ã確èªããããšãçŽæããŸããã ãããŠãå°ãªããšã1ã€ã®è匱æ§ãä¿®æ£ããã®ã¯åœŒãã ãã§ãã
ã§ããããš
- æ€çŽ¢ãåæ§æããããšãå¯èœã§ãã-ãæ€çŽ¢ããµãŒãã¹ã§æ€çŽ¢ã¯ãšãªãšçµæã®ä¿åãå¯èœã«ããæ€çŽ¢ã®ãã£ã«ã¿ãªã³ã°ã¬ãã«ãå€æŽããŸãïŒããšãã°ã害ã®ããã«ååããã«ããæ€çŽ¢ããããšãçŠæ¢ããŸãïŒã ãã®äžå¯èŠæ§ã¯çŸåšééãããŠããŸãã
- ãŠãŒã¶ãŒã®å Žæãå€æŽããããšãã§ããŸã-圌ã¯ãµã³ã¯ãããã«ãã«ã¯ã®ä»£ããã«ãã«ãœã³ã§æ€çŽ¢çµæãåºåã亀éæžæ»ã衚瀺ãããŸãã ãããŠãããªãã¯ãã¹ãŠã®èšªåè ã®å Žæãããã€ãã®ããŸã人æ°ã®ãªãå Žæã«å€æŽããã¢ã¹ã¯ã¯ãããã¯ããã«äœãäŸ¡æ Œã§ãã€ã¬ã¯ãããåºåãåºãããšãã§ããŸã
- ãŠãŒã¶ãŒã®ã«ã¬ã³ããŒã«ä»»æã®ååã§ToDoãªã¹ããäœæããããã«ä»»æã®ã±ãŒã¹ãè¿œå ã§ããŸãã ã±ãŒã¹ãè¿œå ããã«ã¯ããªã¹ãIDãç¥ã£ãŠããå¿ èŠããããŸãããæåã«èªå® ã§ãªã¹ããäœæãã次ã«ãŠãŒã¶ãŒã§ã次ã«èªå® ã§å床äœæãã2ã€ã®ãªã¹ãéã§IDãå埩åŠçã§ããŸãã Yandex.Calendarã®ã¢ãã€ã«ããŒãžã§ã³ã®è匱æ§
- Yandex.Passportããé»è©±ãåé€ã§ããŸãã ããªãã¯ãã®IDãç¥ãå¿ èŠããããŸãããè¿œå ã®ããããã®æ¥ä»ãç¥ã£ãŠããã®ã§ããããæŸã£ãŠãã«ãŒããã©ãŒã¹ããããšãã§ããŸã
- Yandex.Marketã§ã¯ãä»»æã®è£œåãæ¯èŒãªã¹ãã«è¿œå ã§ããŸãã ãŸãã¯ããããåé€ããŸãã
- Yandex.Marketã§ã¯ãç¹å®ã®ã¬ãã«ä»¥äžã®ç¹å®ã®è£œåã®å€äžãã«é¢ããéç¥ããŠãŒã¶ãŒã«ãµãã¹ã¯ã©ã€ãã§ããŸãã ãŸãã¯ãéç¥ãããŠãŒã¶ãŒããµãã¹ã¯ã©ã€ã解é€ããŸãã ããšãã°ãæªæã®ãããªã³ã©ã€ã³ã¹ãã¢ãç°è²ã®iPhoneã®ããããè³Œå ¥ãããããã販売ããã¢ã¯ã·ã§ã³ãèšç»ããŠããŸãã ã¢ã¯ã·ã§ã³ã®åã«ã圌ã¯ããçš®ã®PRãã£ã³ããŒã³ãæé ãã8000ã«ãŒãã«ä»¥äžã®å€äžãã«ã€ããŠã®éç¥ã§ãã¹ãŠã®èšªåè ã«çœ²åããŸãã ãããŠãiPhoneã¯7999ã«ãŒãã«ã®äŸ¡æ Œã§Yandex.Marketã«ãšã¯ã¹ããŒãããããã¹ãŠã®ãŠãŒã¶ãŒã¯Yandexãããã®iPhoneãè³Œå ¥ãããªãã¡ãŒãšãšãã«ã¹ãã ãåãåããŸã
- ã°ããŒãã«ãã°ã¢ãŠãã ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã§ãã¹ãŠã®ãŠãŒã¶ãŒã»ãã·ã§ã³ãçµäºã§ããŸãã ãããã®æ±ãããªãã¯ãšããŠäœ¿çšã§ããŸãã 競åä»ç€Ÿã¯ãã¹ãŠã®Yandexã»ãã·ã§ã³ãçµäºããiframeããµã€ãã«é 眮ã§ããŸããããŠãŒã¶ãŒã¯ã€ã©ã€ã©ããŸãã äžè¬ã«ããã®ãããªåé¡ããªãå¯äžã®ãµã€ãã¯Vkontakteã§ãã ééã£ãããŒã¯ã³ã§ã¢ã«ãŠã³ãããæãåºãããšããã§ããŸããã ãããè匱æ§ãšã¿ãªããããã©ããã¯ããããŸããããVkontakteã¯
æãæ·±å»ãªè匱æ§ã§ã¯ãããŸããã æãå¯èœæ§ãé«ãã®ã¯ãYandexãå€æ°ã®ãµãŒãã¹ã§ãããããããã«ç¬èªã®éçºããŒã ããããä¿è·ã®æ§æãã©ãã§ãç°ãªãããã§ãã ãããŠã©ããèŠèœãšãããŠããã
ããããVkontakteãšLJã¯ã©ãã§ããïŒ
ãã¡ããããããã®ãªãœãŒã¹ãç¡èŠããããšã¯ã§ããŸããã§ããã ããããè匱æ§ã¯èŠã€ãããŸããã§ããããããã¯ããããååšããªãããšãæå³ããŸããã ãããã«ãããCSRFã«å¯ŸããŠã©ã®ããã«ä¿è·ãããŠããããäŒãã䟡å€ã¯ãããŸãã
ãŽã³ã³ã¿ã¯ã
ãŠãŒã¶ãŒã¢ã¯ã·ã§ã³ã®ããŒã¯ã³ã èªåçã«è¿œå ãããããã§ãå¿ããããŸããã ã¢ãã€ã«çãšãŸã£ããåãä¿è·ã 1ã€ã®ãµãŒãã¹ã1ã€ã®éçºããŒã ã«ã¯ãYandexãªã©ã®åé¡ã¯ãããŸããã ç§ãæ··ä¹±ãããã®ã¯1ã€ã ãã§ããç¹å®ã®ã¢ã¯ã·ã§ã³ã®ããŒã¯ã³ã¯ãç¹å®ã®ãŠãŒã¶ãŒã«å¯ŸããŠåžžã«åãã§ãã ã€ãŸã ããã¯ãä¿è·æ¹æ³1ãš2ã®ç¹å®ã®çµã¿åããã§ããããŒã¯ã³ã¯äœ¿ãæšãŠã§ã¯ãªãããŠãŒã¶ãŒã®ã¿ãç¥ã£ãŠããŸãã ã¢ã¯ã·ã§ã³ãå®è¡ããããã®ãã¹ã¯ãŒããšèŠãªãããšãã§ããŸã-åã¢ã¯ã·ã§ã³ã«ã¯ç¬èªã®ãã¹ã¯ãŒãããããŸãã ç§ã¯ãã®ãããªçµç¹ã§äœãã奜ãã§ã¯ãããŸããããããã§ãæ£ç¢ºã«ç解ããŠããŸããã
LJ
æ¹æ³1ã«ããä¿è·-ã¯ã³ã¿ã€ã ããŒã¯ã³ã ã¢ãã€ã«çã§ã¯ãä¿è·ã¯å°ãç°¡åã§ããããŸã ãããŸãã 以äžã«äŸã瀺ããŸãã ãã®ãµãŒãã¹ã¯ãã·ã¢èªã§ã¯ãªãããšã«æ³šæããŠãã ããã ãã®ããã圌ã¯ç«¶äºçžæã§ã¯ãããŸããã
åçŽç
ç§ã¯æ¬åœã«ãããããã§ãã¯ã¢ãŠããããã£ãã ãã ãããã®ããã«ã¯ããããã䜿çšã§ããå¿ èŠããããŸãã ãããŠãç§ã¯åœŒãã®ãã¶ã€ã³ã«ç¥çµè³ªãªã«ãã«ãããããŸãã ãã®ãããããŸããããŸããã§ããã ç¡å¹ãªç»åã§ãããä¿®æ£ããããã«ãããå€è©ŠããŠã¿ãŸãã
ãããã«
äžè¬çã«ãåçã¯å®å šã«åã³ã®ãªããã®ã§ãã ãã®ãããªã¢ã³ã¹ã¿ãŒããããžã§ã¯ãã§ãã®ãããªééããç¯ããå Žåãä»ã®ãã¹ãŠã®éçºè ã¯ãªãœãŒã¹ãå床確èªããå¿ èŠããããŸãã Yandexã¯ã1ãæåã§è匱æ§ééçã§1äœã®è匱æ§çã§1äœã«ãªããŸãã æ®ãã®ãªãœãŒã¹ã¯ãåèªãã2äœãå ããŠããŸãã