Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
XSSのない最高の夏を過ごそう
Search
Sota Sugiura
June 02, 2016
Technology
0
1k
XSSのない最高の夏を過ごそう
社内勉強会発表資料
Sota Sugiura
June 02, 2016
Tweet
Share
More Decks by Sota Sugiura
See All by Sota Sugiura
内製したSlack Appで頑張るIncident Response@Waroom Meetup #1 / Incident Response with Slack App in 10X
sota1235
0
1.7k
20220926_セキュリティチームの今_for_Drs._Prime_公開用.pdf
sota1235
0
150
再発防止策を考える技術 / #phpconsen
sota1235
10
3.9k
How to choose the best npm module for your team?
sota1235
9
610
Realtime Database for high traffic production application
sota1235
7
4.1k
Road to migrate JP Web as a microservice
sota1235
4
1.7k
インターフェース再入門 / Think Interface again
sota1235
6
11k
再発防止策を考える技術 #phpconfuk_rej
sota1235
1
1.3k
Update around Firebase #io18
sota1235
3
4.4k
Other Decks in Technology
See All in Technology
OCIjp_Oracle AI World_Recap
shinpy
1
180
Behind Postgres 18: The People, the Code, & the Invisible Work | Claire Giordano | PGConfEU 2025
clairegiordano
0
120
あなたの知らない Linuxカーネル脆弱性の世界
recruitengineers
PRO
3
150
ソースを読むプロセスの例
sat
PRO
15
9.9k
ソフトウェアエンジニアの生成AI活用と、これから
lycorptech_jp
PRO
0
890
FinOps について (ちょっと) 本気出して考えてみた
skmkzyk
0
210
Linux カーネルが支えるコンテナの仕組み / LF Japan Community Days 2025 Osaka
tenforward
1
120
SQLAlchemy の select(User).where(User.id =="123") を理解してみる/sqlalchemy deep dive
3l4l5
3
340
Zephyr(RTOS)にEdge AIを組み込んでみた話
iotengineer22
1
330
Copilot Studio ハンズオン - 生成オーケストレーションモード
tomoyasasakimskk
0
220
MCP ✖️ Apps SDKを触ってみた
hisuzuya
0
350
事業開発におけるDify活用事例
kentarofujii
5
1.4k
Featured
See All Featured
[RailsConf 2023] Rails as a piece of cake
palkan
57
5.9k
The Pragmatic Product Professional
lauravandoore
36
7k
The Power of CSS Pseudo Elements
geoffreycrofte
80
6k
Testing 201, or: Great Expectations
jmmastey
45
7.7k
Rebuilding a faster, lazier Slack
samanthasiow
84
9.2k
Building a Modern Day E-commerce SEO Strategy
aleyda
44
7.8k
The World Runs on Bad Software
bkeepers
PRO
72
11k
Evolution of real-time – Irina Nazarova, EuRuKo, 2024
irinanazarova
9
990
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
658
61k
Git: the NoSQL Database
bkeepers
PRO
431
66k
How To Stay Up To Date on Web Technology
chriscoyier
791
250k
Raft: Consensus for Rubyists
vanstee
140
7.2k
Transcript
944ͷͳ͍࠷ߴͷՆΛ աͦ͝͏ !TPUB
ͱ͜ΖͰօ͞Μ
͏͙͢ՆͰ͢ΑͶ
Նָ͍͜͠ͱ͕͍ͬͺ͍
Ͱສ͕Ұ944Λग़͢ͱʜ
োใࠂͨ͠Γ
ۀͯ͠ରԠͨ͠Γ
্࢘ʹౖΒΕͨΓ
͖ͬΓݴͬͯπϥΠ
ͯ͜ͱͰ ࠓͷత
944ʹ͍ͭͯվΊͯݟΛਂΊɺ 944ͱແԑͷ࠷ߴͷՆΛաͦ͝͏ʂ
"HFOEB w "CPVU944 w 5IFSJTLPG944 w 5SZ944 w 944$PVOUFSNFBTVSFT
"CPVU944
944$SPTT4JUF4DSJQUJOH w ҙͷεΫϦϓτ࣮ߦΛڐ༰ͯ͠͠·͏੬ऑੑ w ओઓओʹ8FCϒϥβ w ಈత8FCαΠτͷൟӫʹ͍ٸ૿ͨ͠੬ऑੑ
944ͷछྨ w ࣹܕ944 3FqFDUJPO944 w ੵܕ944 4UPSFE944 w
%PN#BTFE944
4DFOBSJPPG944ᶃ 944੬ऑੑͷଘࡏ͢Δ αʔό ίϫΠਓ ߈ܸର ᶃ᠘63-Λࡌͤͨ ϝʔϧΛૹ৴ ᶄ᠘63-ʹΞΫηε ᶅ߈ܸεΫϦϓτͷؚ·Εͨ ϦιʔεΛฦ͢
4DFOBSJPPG944ᶄ 944੬ऑੑͷଘࡏ͢Δ αʔό ίϫΠਓ ߈ܸର %# ᶃ߈ܸεΫϦϓτΛؚΜͩ σʔλΛૹ৴ ᶅϖʔδʹΞΫηε ᶆ߈ܸεΫϦϓτͷؚ·Εͨ
ϦιʔεΛฦ͢ ᶄσʔλΛߋ৽
4DFOBSJPTPG944 w 944ͷදతͳγφϦΦΛհ͠·ͨ͠ w ଞʹ͍Ζ͍Ζ͋Δ͚Ͳ͍͍ͩͨ͜ͷύλʔϯ w ৄ͘͠ʮࠓ͞Βฉ͚ͳ͍944ʯΛͲ͏ͧ
5IFSJTLPG944
944ͷϦεΫ 944ͷϦεΫͱ +BWB4DSJQUͰͰ͖Δ͜ͱͳΜͰͰ͖Δ͜ͱ
+BWB4DSJQUͰͰ͖Δ͜ͱ w $PPLJFͷಡΈࠐΈ w ηογϣϯϋΠδϟοΫ w ϖʔδվ᜵ w "KBY௨৴
+BWB4DSJQUͰͰ͖ͳ͍͜ͱ w 1$্ͷϦιʔεͷΞΫηε w αϯυϘοΫε w ྲྀߦΓͷ&MFDUSPO͜͜ΒΜ͕࠷ۙݴٴ͞Ε͡Ίͨ w ҟͳΔΦϦδϯ্ͷϦιʔεͷΞΫηε w
4BNF0SJHJO1PMJDZ w ଞλϒͷଞαΠτͷใΛ౪·ΕͨΓ͠ͳ͍ ϒϥβʹ ੬ऑੑ͕ͳ͚Ε
$BTF4UVEZϖʔδվ᜵ w σβΠφʔͷࣗݾհϖʔδͷ৭Λ࠷ѱͷηϯ εʹվ᜵
·͡Ίͳ w ͠944͕ൃੜ͢Δͱ͋ΒΏΔҙͷίʔυ͕ Ϣʔβʹૹ৴͞ΕΔ͜ͱʹͳΔ w έʔεʹΑͬͯαʔόଆͷϩάʹΒͣɺ ෆՄೳͳ944ଘࡏ͢Δ w 42-ΠϯδΣΫγϣϯͱൺΔͱܰΜ͡ΒΕ ͍ͯΔҹ
ओ؍ ͚ͩͲܾͯ͠ແࢹͰ͖ͳ͍
5SZ944
ࠓͷϝΠϯίϯςϯπ
࣮ࡍʹ944Λ୳ͯ͠ΈΑ͏ʂʂ
5SZ944 w ࣮ࡍʹ944Λ୳ͯ͠ΈΔ w ॳΊͯͷϋϯζΦϯܗࣜͳͷͰ͙ͩͬͨΒεΠ Ϛηϯ w ࣮ࡍʹͳ͔ͳ͔ى͖ͳ͍944͋Γ·͕͢ɺ +BWB4DSJQUͷڍಈͷษڧ݉ͶͯͨΓ͢ΔͷͰ ؾʹͤͣύζϧײ֮Ͱ୳͍ͯͩ͘͠͞
IUUQTHJUIVCDPNTPUBYTT@UPVS
944$PVOUFSNFBTVSFT
)5.-Τεέʔϓ w ಈతʹग़ྗ͢ΔจࣈશͯΤεέʔϓ͠·͠ΐ͏ w 63-ͱ͔Կߟ͑ͣʹͦͷ··ల։͕ͪ͠ w ຊʹͦΕ҆શͰ͔͢ʁޙ͔Βݟͨਓ944Λٙ ΘͣʹࡁΉ࣮ʹͳͬͯ·͔͢ʁ w αχλΠζͱ͍͏બΛऔΔͳΒςετέʔεΛॆ
࣮ͤ͞Α͏
ϑϩϯτ+4 w ϑϩϯτ+4جຊΤεέʔϓ w ΤεέʔϓͤͣʹؤுΒͳ͖Ό͍͚ͳ͍ͷͰ͋ΕԿ ͔͠Βͷ7JFXϥΠϒϥϦͷಋೖΛݕ౼͖͢ w K2VFSZͰେྔʹ%0.ૢ࡞͞ΕͯΔίʔυͰ944͕ ઈରʹͳ͍ͱݴ͍Δࣗ৴͕͋ΔͳΒ͍͍͚Ͳɻɻɻ
ΫοΩʔΛकΔ w ສ͕Ұɺ944͕ൃੜͯ͠ΫοΩʔΛकΔ͜ͱ ͕Ͱ͖Δ w $PPLJFϔομʹIUUQ0OMZΛ͚ͭΔͱ EPDVNFOUDPPLJF͕͑ͳ͘ͳΔ w ͜ͷϔομ͜Ε͔Βઌڧ੍ͰϚετʹ͍ͨ͠ Ϩϕϧ
)551ϔομΛۦ͢Δ w ϞμϯϒϥβͰ͋Ε$41ϔομͷ༻Λਪ w ΠϯϥΠϯεΫϦϓτͷ࣮ߦΛ੍ w େͷ944͜ΕͰ͚Δ w *&944'JMUFSΛ༗ޮʹ͢Δ w
ڍಈ͕͍·͍ͪΦʔϓϯͰͳ͍͚Ͳେͷ944 ͚ͦ͏ͳงғؾʁ
944ͷͳ͍࠷ߴͷՆΛա͝͠·͠ΐ͏