ãããŠãã¯ããã«ãããã€ãã®çµ±èšïŒ
- æåã®2é±éã§ãåå è ã¯æœåšçãªè匱æ§ãæã€çŽ500件ã®ã¢ããªã±ãŒã·ã§ã³ãéä¿¡ããŸããã
- çŽ50件ã®ã¢ããªã±ãŒã·ã§ã³ãéè€ããŠããŸããã
- 10åã®ã¢ããªã±ãŒã·ã§ã³ããšã«å®éã®è匱æ§ãå«ãŸããŠããŸããïŒæãå±éºãªãã®ã¯æ°æé以å ã«ä¿®æ£ãããŸããïŒã
- 150以äžã®ã¢ããªã±ãŒã·ã§ã³ã¯ããµã€ãã®ã»ãã¥ãªãã£ã«é¢é£ããªããšã©ãŒã§ããããããã®çŽ10ïŒ ã¯ã競äºã«åå ããªãã£ããã©ãããã©ãŒã ã«é¢é£ããŠããŸãã
- ã»ãšãã©ã®è匱æ§ã¯ãã·ã¹ãã ã®æãéèŠãªã³ã³ããŒãã³ãã§ãããããã¡ã€ã«ïŒç«¶æè ããŠãŒã¶ãŒã¢ã«ãŠã³ããã¢ãã¯ããªãã£ãçŽåŸïŒåçã®åé€ãšã¢ããããŒããã³ã¡ã³ãã®æäœãèå³ãå人ããŒã¿ãé»åã¡ãŒã«ã¢ãã¬ã¹ïŒã«ãããŸããã
- éä¿¡ãããè匱æ§ã®åå以äžã¯ããŸããŸãªCSRFã§ãããäž»ã«ãŠãŒã¶ãŒãã¢ããããŒããŸãã¯æžã蟌ã¿ããã³ã³ãã³ãã«åœ±é¿ãäžããŸãïŒåçãã³ã¡ã³ãã®åé€ãšã¢ããããŒãããã©ãã¯ãªã¹ãã«ç»é²ããããæ°ã«å ¥ãã®æäœãªã©ïŒã
ãµã€ãäžã®ã³ã³ããŒãã³ãããšã®è匱æ§ã¿ã€ããšãã®ååžã®ã°ã©ã
競äºã®æºå...
æ°ãæåããµã€ãå šäœã«ã°ããŒãã«ãªXSSä¿è·ãæ§ç¯ããŸããã ããã«äžèœè¬ã§ã¯ãªããè匱æ§ã®100ïŒ ãã«ããŒããªãããšãäºçŽããŠãã ããã ãã®ç®çã¯ãéçºè ãå¶çºçãªãšã©ãŒãé²æ¢ããããšã§ãã ãã®ã¡ãœããã®æ¬è³ªã¯ãéçºè ãåºåãéã¹ã¯ãªãŒã³åœ¢åŒã§è¡šç€ºããããšãæ確ã«èš±å¯ããŠããå Žåãé€ãã blitzãä»ããŠè¡šç€ºããããã¹ãŠã®å€æ°ãèªåçã«å®å šã«ã¹ã¯ãªãŒãã³ã°ããããšã§ãã
æãèå³æ·±ãããããŠå¯äžã®æ¬æ ŒçãªXSSçºèŠã¯ãäžæ£ãªãããã¡ã€ã«ã§ã®è¿œå ã®SEOã³ã³ãã³ãã®åºåã§èŠã€ãããŸããã ããŸããŸãªSEOããŒãºã®äžéšã®ãããã¡ã€ã«ããŒã¿ïŒã¡ã€ã³ã®[About]ãã£ãŒã«ãïŒãã¡ã¿ã¿ã°ã®1ã€ã«è¿œå ãããŸããã ãã®æç¹ã§ãçããŒã¿ã®åºåãäžåºŠèš±å¯ããããããæ»æãèš±å¯ãããŸããã ãã®è匱æ§ã¯èš±å¯ãããŠããªããŠãŒã¶ãŒã«å¯ŸããŠã®ã¿æ©èœãããããæåã®ïŒæãå±éºãªïŒã«ããŽãªãå²ãåœãŠãŸãããæ©å¯ããŒã¿ãååŸããããšã¯äžå¯èœã§ããã é ã«æµ®ãã¶å¯äžã®åççãªã¢ããªã±ãŒã·ã§ã³ã¯ãã¢ã«ãŠã³ãããŒã¿ããããªããã£ãã·ã³ã°ã®ãªãŒãã³ãªãã€ã¬ã¯ããšããŠäœ¿çšããããšã§ããããã®å Žåã§ãããŠãŒã¶ãŒãçŸåšãµã€ãã«ããªãããšã確èªããå¿ èŠããããŸãã
...ãããŠåœŒããæºåããªãã£ãæ¹æ³ã
2013幎ã OWASPãããžã§ã¯ãã¯ããã®äººæ°ã®å€§å¹ ãªå¢å ãšå€ãã®å€§èŠæš¡ãªWebãããžã§ã¯ãã«å¯Ÿããä¿è·ã®æ¬ åŠã«ãããããããCSRFæ»æã®è©äŸ¡ã3ãã€ã³ãäžããŸããã æ»æã®æ¬è³ªã¯ç°¡åã§ããPOSTãŸãã¯GETãªã¯ãšã¹ããå«ããã©ãŒã ã§ç¹å¥ãªããŒãžã«ç§»åãããšããŠãŒã¶ãŒã®ã»ãã·ã§ã³ã§ã¢ã«ãŠã³ãã®ã³ã³ãã³ããŸãã¯èšå®ãå€æŽã§ããŸãã ãã®å Žæã§ã¯ããã¹ãŠãç§ãã¡ãæãã»ã©è¯ããããŸããã§ããã ãµã€ãã®æ©èœã®äžéšïŒæ¿èªããã°ã¢ãŠããå人æ å ±ã®å€æŽãªã©ïŒã®ã¿ãäžæã®ã»ãã·ã§ã³ããŒã¯ã³ã«ãã£ãŠä¿è·ãããŠããŸããã ãã®ãã°ã«é¢ããæåã®10件ã®ã¬ããŒããå±ããšããã«ãåé¡ãå šäœãšããŠè§£æ±ºããå¿ èŠãããããšãæããã«ãªããŸããã ã³ã³ãã¹ãã®éå§ããæ°æ¥åŸãå¥ã®ã°ããŒãã«é²åŸ¡ãæçš¿ããŸããããµã€ãã®èš±å¯ãããéšåã®ãã¹ãŠã®WebãµãŒãã¹ã¯ãPOSTãŸãã¯GETãªã¯ãšã¹ãã§ããŒã¯ã³ã®ãã§ãã¯ãéå§ããŸããã ãã®ä¿®æ£ã«ãããCSRFã¢ããªã±ãŒã·ã§ã³ã®ã»ãšãã©ãéããŸããã
次ã«ãæãèå³æ·±ãè匱æ§ã®ããã€ããèŠãŠãããããçºèŠããåå è ã«ã³ã¡ã³ããããŸã ã
賌å
¥æã®ããŒã³åŠçã®è匱æ§ïŒBSI-13ïŒ
æçš¿è
ïŒ ãã³ã©ã€ã»ãšã«ãã·ãã³ ïŒ Asd ïŒ
ã«ããŽãªïŒ5
ãªããã®è匱æ§ã5çªç®ã«é«ãéèŠåºŠã«å²ãåœãŠãã®ã§ããïŒ ãªããªãããã©ãŠã¶ãšãããã°ã³ã³ãœãŒã«ãé€ããŠãç¹å¥ãªã¹ãã«ãšããŒã«ãå¿ èŠãšããªãã»ã©æäœãç°¡åã ã£ãããã§ãã HTMLã³ãŒãã§ã¯ãããŒã³ã®æ°ãéžæããããã®ãã©ãŒã ã¯æ¬¡ã®ããã«ãªããŸããã
... <option data-ga-ev="100 - 45,00." value="100"> <option data-ga-ev="550 (50 !) - 200,00." value="550" selected="selected"> <option data-ga-ev="1250 (250 !) - 450,00." value="1250"> <option data-ga-ev="2750 (750 !) - 900,00." value="2750"> ...
å€ãã£ãŒã«ãã®å€ãçŽæ¥äœ¿çšãããããšãå€æããŸããïŒ ãããã»ãŒä»»æã®æ°ã«çœ®ãæãããšã220ã«ãŒãã«ã®éé¡ã§æ¯æããè¡ãããã®éé¡ã®ããŒã³ãå£åº§ã«å ¥ããããšãã§ããŸããã è匱æ§ã¯æ°æé以å ã«ä¿®æ£ãããAsdãšããããã¯ããŒã ãæã€ãŠãŒã¶ãŒã¯ãæãéèŠåºŠã®é«ãè匱æ§ãæåã«æ€åºãã瀟å ãããã®1äœã«ãªããŸããã
Asdã«ããã³ã¡ã³ã
ãæåã¯ããµã€ãã®ããŸããŸãªã»ã¯ã·ã§ã³ã«è¡ãããªã¯ãšã¹ãã®ãã©ã¡ãŒã¿ãŒå€ãå€æŽããããšããŸãããããã®ã¬ãã«ã®ãããžã§ã¯ãã§ã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã®ãããªæ·±å»ãªè匱æ§ãèŠã€ããããšã¯ã§ããªããšäºæ³ãããŸããã èè ããµã€ãã«çŽæ¥ãªãè匱æ§ãæ€çŽ¢ããhabrahabr.ru/post/117039ã®ç 究ãæãåºããŸãããAmazonã§ããããµãŒãããŒãã£ã®ãµãŒãã¹ãšã®ããåãã«æµæã§ããŸããã§ããã badooã§åæ§ã®ããåããæå³çã«æ€çŽ¢ãããšãããé£çµ¡å ã®ã€ã³ããŒããã¢ã«ãŠã³ãã®ç¢ºèªãããŒã³ãè¶ å€§åœã®æ¯æããªã©ãããã€ãã®å Žæã§ããããèŠã€ããŸããã ã¯ã¬ãžããè³Œå ¥ããŒãžã蚪ããŠãç§ã¯ããã€ãã®æ¹æ³ã§æ¯æãå¯èœæ§ãçºèŠããæ¯æãã·ã¹ãã ãšã®çžäºäœçšã¹ããŒã ã¯éåžžã«ç°ãªã£ãŠããŸããã
ãã®ãã¡ã®1ã€ã§ééããç¯ãããšã¯å®å šã«å¯èœã§ãããšå€æãããã詳现ãªèª¿æ»ãéå§ããŸããã ç§ã¯ææã¡ã®å°é¡ã®è²¡åžãæã£ãŠããã®ã§ãæåã«ãŠã§ããããŒãéžã³ãŸããã ç§ã¯ãããç解ããŠããã®ã§ãè³Œå ¥ã¯æ¬¡ã®ããã«è¡ãããŸãïŒãŠãŒã¶ãŒã¯å¯èœãªãªãã·ã§ã³ïŒ100ã550ã1250ã2750ïŒã®ãããããéžæãã圌ã®éžæã¯ãµã€ãã®å éšã¢ã«ãŠã³ãã®ã©ããã«ä¿åããããã®åŸãŠãŒã¶ãŒã¯webmoneyãŠã§ããµã€ãã§æ¯æãããã®åŸè«æ±æžãæ¯æãããŸãä¿åããããã®ãšæ¯èŒãããããããäžèŽããæ¯æããæåããå ŽåããŠãŒã¶ãŒã¯ããŒã³ãåãåããŸãã ã¢ã«ãŠã³ãã®ä¿åäžã«ã©ã®ãã©ã¡ãŒã¿ãŒã転éãããããèŠãŠãæ¯æã£ãããŒã³ã®æ°ãçŽæ¥ã§ã¯ãªããããã€ãã®å€ã§ã¯ãªãã4ã€ã®å¯èœãªãªãã·ã§ã³ã®1ã€ã瀺ããŠããããšã«æ°ä»ããŸããã ãããå€æ°ã«çœ®ãæãããšã7.5wmzïŒ550ã¯ã¬ãžããã®æšæºäŸ¡æ ŒïŒã®è«æ±æžãšç§ã瀺ããã¯ã¬ãžããæ°ã§ããµãŒããŒããæ£ããçããåãåããŸããã ç§ã¯ãããæ¯æããŸãã-ãããŠãããŒã³ã¯ç§ã®ã¢ã«ãŠã³ãã«ãããŸãããããããã«åãæšãŠããã圢ã§-2147483647 "ã ãã§ããã
ãããã¡ã€ã«ããŒã¿ãå€æŽãããšãã®èšå®ãã¹ïŒBSI-12ïŒ
æçš¿è
ïŒ whitebureau
ã«ããŽãªïŒ5
åãæ¥ã«ãå¥ã®é倧ãªã®ã£ãããwhitebureauãŠãŒã¶ãŒã«ãã£ãŠçºèŠãããŸããã ä»ã®ãŠãŒã¶ãŒã®ãããã¡ã€ã«ãšå¯Ÿè©±ãããšãïŒè¿œå æ å ±ã®è¡šç€ºãã¢ã¯ã·ã§ã³ã®å®è¡ïŒãèŠæ±ãã©ã¡ãŒã¿ãŒã§cuidãã©ã¡ãŒã¿ãŒïŒçŸåšã®ãŠãŒã¶ãŒIDïŒãæž¡ããããã®ãŠãŒã¶ãŒã®IDã瀺ãããŸããã
GET http://badoo.com/ws/profile-ws.phtml?section=pimore&cuid=31337
ãããã®çžäºäœçšã¯ããããã¡ã€ã«ã®ç·šéãæ åœããåãã³ã³ãããŒã©ãŒãä»ããŠå®è¡ãããéãã¯ã¢ã¯ã·ã§ã³ã¢ã¯ã·ã§ã³ã®ã¿ã§ãããwhitebureauã¯ãŠãŒã¶ãŒã®ç·šéèŠæ±ã«ä»»æã®å€ãæã€ãã®useridãã©ã¡ãŒã¿ãŒãè¿œå ããããšããŸããã
POST http://badoo.com/ws/profile-ws.phtml ... section=interested_in&interested_in_text=cats&cuid=31337
ãããã¡ã€ã«ã®ç·šéæã«ããã®ãã©ã¡ãŒã¿ãŒãçŸåšã®ãŠãŒã¶ãŒIDã«æºæ ããŠãããã©ããã®ç¢ºèªãã¹ããããããããšãå€æããŸããã ãã®ããã2çªç®ã®é倧ãªè匱æ§ããããŸããã
ã³ã¡ã³ãwhitebureau
ãã®ãããªãšã©ãŒã¯ã倧èŠæš¡ãªãããžã§ã¯ãã§ããèŠãããŸãã ç¹ã«ãajaxãç©æ¥µçã«äœ¿çšããŠãããããžã§ã¯ãã§ã¯ã ã¹ãŒããŒã°ããŒãã«phpå€æ°ã«ã¯æ··ä¹±ããããŸããéçºè ã¯ãããæ£ç¢ºãª$ _GETã$ _POSTããŸãã¯$ _COOKIEã®ä»£ããã«ãhttpãªã¯ãšã¹ãã®ãã¹ãŠã®å€æ°ã§$ _REQUESTã䜿çšããŸãã ãã®çµæãæ»æè ã¯postãŸãã¯getãªã¯ãšã¹ãã§ç®çã®å€æ°ã眮ãæããããšã«ãããéåžžã«ç°¡åã«ã³ãŒããæ··ä¹±ãããããšãã§ããŸãã ã¹ã¯ãªããã¯çœ®æãèªèããŸããã
ãµã€ãã®ãã¹ãŠã®ããŒãžã®ã¯ãªãã¯ãžã£ããã³ã°ïŒBSI-9ïŒ
æçš¿è
ïŒãŠãŒãžã³ã»ãã¡ãŒãã§ã«
ã«ããŽãªïŒ1
ãŸããéèŠã§ã¯ãªããèå³æ·±ãè匱æ§ã®ã¬ããŒããåãåããŸããã ãããã®1ã€ã¯ããµã€ãã®ãã¹ãŠã®ããŒãžã§ããããã¯ãªãã¯ãžã£ããã³ã°ïŒè±èªã®ã¯ãªãã¯ãžã£ããã³ã°ïŒãå®è¡ããæ©èœã§ããã
ãã®çšèªã¯ã2008幎ã«ãžã§ã¬ãã€ã¢ã°ãã¹ãã³ã«ãã£ãŠæåã«äœ¿çšãããŸãããããããŸã§ã®ãšããããã®è匱æ§ã®éèŠæ§ãšçµæã«ã€ããŠèãã人ã¯ã»ãšãã©ããŸããã ã¯ãªãã¯ãžã£ããã³ã°ãšã¯äœã§ããïŒ OWASPãèšãããã«ããã¯ãªãã¯ãžã£ãã¯ããUIææžæ»æããšãåŒã°ããŸãïŒã¯ãæ»æè ãè€æ°ã®éæãŸãã¯äžéæãªã¬ã€ã€ãŒã䜿çšããŠããŠãŒã¶ãŒãå¥ã®ããŒãžã®ãã¿ã³ãŸãã¯ãªã³ã¯ãã¯ãªãã¯ããããã«èªå°ããå Žåã§ãããããã¬ãã«ããŒãžãã
ç°¡åã«èšãã°ãã¯ãªãã¯ãã³ãã©ãŒãå«ãéæãªdivã¿ã°ã§äžéšã®èŠçŽ ããªãŒããŒã©ã€ãããããšã«ãããiframeå ã«ãµã€ãã衚瀺ã§ããŸãã ãããã£ãŠãçããæããªãèš±å¯ãŠãŒã¶ãŒã«åŒ·å¶çã«ä»»æã®ã¢ã¯ã·ã§ã³ãå®è¡ãããããšãã§ããŸãã
æãããç¥ãããŠããä¿è·æ¹æ³ã®1ã€ã¯ãã¬ãŒã ãã¹ãã£ã³ã°ãšåŒã°ããŸãã Javascriptã䜿çšããŠãiframeå ã§ããŒãžãéããŠããããšã確èªããŸãã çŸåšã®ããŒãžã®ã¢ãã¬ã¹ããã©ãŠã¶ã®ã¢ãã¬ã¹ããŒã«æžã蟌ãŸããŠãããã®ãšç°ãªãå Žåããªãã€ã¬ã¯ããå®è¡ãããŸãã
var frameBusted = (top != self); if (frameBusted) top.location.href = '/index.htm';
åŸã§å€æããããã«ããã®æ¹æ³ã¯ã»ãšãã©ã®ææ°ã®ãã©ãŠã¶ãŒã§ãã€ãã¹ã§ããŸãã
<iframe sandbox src="http://badoo.com/></iframe>
ãã®ããã2009幎以éããã¹ãŠã®ææ°ã®ãã©ãŠã¶ãŒïŒIEãå«ãïŒã¯X-Frame-OptionsããããŒããµããŒãããŠãããiframeå ãžã®ãµã€ãã®åã蟌ã¿ãå®å šã«çŠæ¢ããããç¹å®ã®ãã¡ã€ã³ãªã¹ãã«å¯ŸããŠã®ã¿ãã®æ©èœãæå¹ã«ãããã§ããŸãã
ããªãã®ãµã€ãã¯ã¯ãªãã¯ãžã£ããã³ã°ããä¿è·ãããŠããŸããïŒ
ãŠãŒãžã³ã»ãã¡ãŒãã§ã«ã«ããã³ã¡ã³ã
ä»æ¥ãã»ãšãã©ãã¹ãŠã®ã€ã³ã¿ãŒããããªãœãŒã¹ã¯ãåæ§ã®ã¯ãªãã¯ãžã£ãã¯ã®è匱æ§ã®åœ±é¿ãåãããããªã£ãŠããŸãã ããããèŠã€ããããã»ã¹ã¯ç¹ã«è€éã§ã¯ãããŸãããäžè¬çãªã«ãŒã«ããããŸã-ãªãœãŒã¹ããã®å¿çã§X-Frame-OptionsããããŒã䜿çšããªãå Žåããã¬ãŒã ã«åã蟌ãæ©èœã®ååšã¯ããã®åŸã®ããŸããŸãªçš®é¡ã®ãã£ãã·ã³ã°ããŒãžã®äœæã§ã»ãŒä¿èšŒãããŸãã ãããã£ãŠããã®è匱æ§ã¯ãHTTPããããŒã衚瀺ããçµæã«ãã£ãŠãã§ã«èŠã€ãã£ãŠãããšèŠãªãããšãã§ããŸãã
Badooã䜿çšãã.jsãã¡ã€ã«ã調ã¹ããšãwindow.top.locationããããã£ã眮ãæããäžè¬çã§èª€ã£ãæ¹æ³ããã¬ãŒã ãçµäºããããã«äœ¿çšãããŠããããšãããããŸããã ãã®ã¡ãœããã䜿çšãããšããã¬ãŒã ã«Badooãåã蟌ãããŒãžãonloadã€ãã³ããåãåãã察çãè¬ããããšãã§ããŸãã ãã®ãããªæ段ã®1ã€ã¯ããã©ãŠã¶ãŒãå¿çã³ãŒã204ã§è¿ãããã¢ãã¬ã¹ã«ãªãã€ã¬ã¯ãããããšã§ãããã®ãããªURLãžã®èŠæ±ã¯ããã©ãŠã¶ãŒå ã®ããã²ãŒã·ã§ã³ã«ã€ãªãããŸããïŒãã¬ãŒã ã®ããããŒãžã¯éãããŸãŸã§ãïŒããå Žæã眮ãæããBadooã³ãŒãã®è©Šè¡ããã£ã³ã»ã«ããŸãã
Badooã«ãã£ãŠå°å ¥ãããæåã®ä¿®æ£ã¯ããã¬ãŒã å ã®ããŒãžã®æ¬æã空ã®æååã§çœ®ãæããããšã«ããããã®ã³ãŒããè£è¶³ããŸããã ãã®ä¿®æ£ã«ããããã¬ãŒã ãžã®åã蟌ã¿ã®åé¡ã¯è§£æ±ºããŸããã§ãããããã¬ãŒã ãããã¹ãŠã®ã³ã³ãã³ããåé€ããããã£ãã·ã³ã°ããŒãžãäœæã§ããªããªããŸããã ãã®ä¿®æ£ã¯ãiframeã¿ã°ã®sandboxå±æ§ã䜿çšããŠç°¡åã«ãã€ãã¹ããããã¬ãŒã å ã®JavaScriptãç¡å¹ã«ãªããŸãã
ååãšããŠãã¯ãªãã¯ãžã£ãã¯æ»æããä¿è·ããå¯äžã®æ¹æ³ã¯ããã¬ãŒã ã«åã蟌ãŸããããšãæå³ããŠããªããã¹ãŠã®ããŒãžã«X-Frame-OptionsããããŒã䜿çšãããã¬ãŒã ã«åã蟌ã¿ãå«ãããŒãžã§ã·ã¹ãã ã®ç¶æ ãå€æŽãããã¹ãŠã®ã¢ã¯ã·ã§ã³ã確èªããããšã§ãã
CSRFããã³ã«ã¹ã¿ã é»åã¡ãŒã«ã®å€æŽïŒBSI-38ïŒ
æçš¿è
ïŒ ã°ã©ãã¡ã€ã
ã«ããŽãªãŒïŒ3
ïŒãã®è匱æ§ã®äžéšã¯BSI-21ã«ãããèè
ã®ã€ãªã€ãã«ïŒ
ããã¯ç§ãã¡ãäºæããŠããªãã£ããã®ãªã®ã§ããããã¯ä»»æã®ãŠãŒã¶ãŒã®ã¡ãŒã«ã¢ãã¬ã¹ãå€æŽããæ¹æ³ã®èª¬æã§ãã ããããããæ¥ããã¹ã¯ãŒãã®åéä¿¡ã³ã³ããŒãã³ãã«é¢é£ããããŸããŸãªè匱æ§ã«é¢ãã3ã€ã®èª¬æããã¹ãŠéä¿¡ããããŠãŒã¶ãŒã®ã¡ãŒã«ããã¯ã¹ãå€æŽãããã€ãŸãã¢ã«ãŠã³ãããä¹ã£åããããšãã§ããŸããã
ç»é²æã«ãã¹ã¯ãŒããåéä¿¡ããããã®ãã©ãŒã ããããŸãããã®ãã©ãŒã ã§ã¯ãã¿ã€ããã¹ãäŸµå ¥ããå Žåã«ã¡ãŒã«ãå€æŽã§ããŸãã ãŠãŒã¶ãŒã¯ãCSRFã䜿çšããŠæ¢ã«ç¢ºèªæžã¿ã®äœæãå€æŽããããšããã§ããããšãå€æããŸããã
<form action=http://eu1.badoo.com/not_confirmed/" method="post" id="form"> <input type="hidden" name="post" value="1" /> <input type="hidden" name="newemail" value="attacker@somemail.com" /> <input type="submit" /> </form> <script>$('#form').submit();</script>
ãã®è匱æ§ãä¿®æ£ããæ¹æ³ã¯ããã€ããããŸããã
1.確èªã®ããã«ãã§ãã¯ãè¿œå ããŸãã
2. CSRFããŒã¯ã³ãè¿œå ããŸãã
3. CAPTCHAãè¿œå ããŸãã
ãã®ã¢ãžã¥ãŒã«ã¯éåžžã«éèŠã§ããããã3ã€ã®æ¹æ³ãã¹ãŠãé©çšãããè匱æ§ãçºèŠãããŠãŒã¶ãŒã¯å ±ãããŸããã
ã°ã©ãã¡ã€ãã«ããã³ã¡ã³ã
ãªããªã ç§ã¯ä»¥åã«Badooã«ç²ŸéããŠããŸããã§ããããŸããããã§äžè¬çã«äœãã§ããããç¥ãããšã«ããŸããã ããã«ãããŸããŸãªé»åã¡ãŒã«ãµãŒãã¹ããé£çµ¡å ãã€ã³ããŒãããå¯èœæ§ã«æ³šæãåããããŸããããã®ãããªã¢ãã¬ã¹ããã¹ã¯ãŒãå埩çšã®è¿œå ã®é»åã¡ãŒã«ã®ãªã¹ãã«è¿œå ãããŠãããã©ããã確èªãããã£ãã®ã§ãã æ²ããããªã玹ä»ãããŠããŸããã ããããç§ã®èãã¯ãã§ã«ãã®ããã«ãªã£ãŠããããã°ããããŠãééã£ãã¡ãŒã«ã§ã¯ãªããå¥ã®ã¡ãŒã«ãå ¥åããæ©èœãåããç»é²ã確èªããããã«ãã¡ãŒã«ãåéä¿¡ãããã©ãŒã ã«åºäŒããŸããã ãã®ãã©ãŒã ã«ã¯CSRFããããŸããããæãé©ãã¹ãããšã¯ãèªèšŒããããŠãŒã¶ãŒããã®ãã©ãŒã ã«èšå ¥ãããšããããã¡ã€ã«ã®ã¡ãŒã«ã¢ãã¬ã¹ãå€æŽãããããšã§ãã æããã«ããã®ã·ããªãªã§ã¯ããŠãŒã¶ãŒãæ¢ã«é»åã¡ãŒã«ã確èªãããã©ããã®ãã§ãã¯ã¯ãããŸããã§ããã
CSRFããã³å€éšãœãŒã·ã£ã«ãããã¯ãŒã¯ã¢ã«ãŠã³ãã®ãªã³ã¯ïŒBSI-44ïŒ
æçš¿è
ïŒchipik
ã«ããŽãªãŒïŒ4
ãŸãããµã€ããšå€éšãªãœãŒã¹ãšã®çžäºäœçšã®è匱æ§ãæããã«ããŸããã ãµã€ãã®ãããã¡ã€ã«ãå€éšã®FacebookãVKããŸãã¯Google+ã¢ã«ãŠã³ãã«é¢é£ä»ããããšãã§ããæ©èœããããŸãã ããããä»ããŠããŠãŒã¶ãŒã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããèŠããŠããªããŠããµã€ãã«ãã°ã€ã³ã§ããŸãã chipikã®åå è ã¯ããã®ã¢ã«ãŽãªãºã ã®åŒ·åºŠããã¹ããããããã ãŸãæ¹æ³ãèŠã€ããŸããã
Firefoxã®ã¿ã³ããŒããŒã¿ãã©ã°ã€ã³ã䜿çšãããšãå€éšã¢ã«ãŠã³ãããã€ã³ãããŠOAuthèªèšŒããŒã¯ã³ãååŸãããªã¯ãšã¹ããã€ã³ã¿ãŒã»ããã§ããŸãã CSRFã䜿çšããŠãæ»æè ãèš±å¯ããããŠãŒã¶ãŒã«ãã®ããŒã¯ã³ã®ãªã³ã¯ãã¯ãªãã¯ãããå Žåã圌ã®ã¢ã«ãŠã³ãã¯æ»æè ã®å€éšã¢ã«ãŠã³ãã«é¢é£ä»ããããåŸè ããã®ãŠãŒã¶ãŒãšããŠãã°ã€ã³ã§ããããã«ãªããŸãã æã確å®ãªè§£æ±ºçã¯ãã¢ã«ãŠã³ãã«ãªã³ã¯ããããã¹ãŠã®æäœã«ã»ãã·ã§ã³åºæã®CSRFããŒã¯ã³ãè¿œå ããããšã§ããã
chipikã«ããã³ã¡ã³ã
E.Khã«æè¬ããŸãã ãã¯ãã«ããšã«:)
å¿åã¯4æ19æ¥ãŸã§åãä»ããããŸãããã³ã³ãã¹ãã«åå ããå ±é ¬ãåãåãããã©ãããã©ãŒã ãããå®å šã«ãããã£ã³ã¹ããããŸãã
ã³ã³ãã¹ãçµäºåŸãæãã¢ã¯ãã£ããª3人ã®åå è ãéžæããããã«1,000ãã³ããæäŸããŸãã
ãŸããã³ã³ãã¹ãã®ã·ã³ãã«ãšå¯©æ»å¡ã«ãã£ãŠçœ²åãããæè¬ç¶ãèšèŒããã50æã®ã¯ãŒã«ãªTã·ã£ãããããæãã¢ã¯ãã£ããªåå è ã«é åžãããŸãã
匷床ããã¹ãããŠãã ããïŒ
ã¹ã¿ãã¹ã©ãã»ãšã¬ãã³ãšBadooéçºããŒã