Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
0802徳丸.pdf
Search
tanakata
August 02, 2017
0
50
0802徳丸.pdf
tanakata
August 02, 2017
Tweet
Share
More Decks by tanakata
See All by tanakata
20171201
tanakata
0
37
20171110
tanakata
0
47
1013
tanakata
0
50
徳丸0922
tanakata
0
75
0901
tanakata
0
42
2017/08/25
tanakata
0
46
徳丸20170721.pdf
tanakata
0
39
Featured
See All Featured
Git: the NoSQL Database
bkeepers
PRO
432
66k
Public Speaking Without Barfing On Your Shoes - THAT 2023
reverentgeek
1
300
Skip the Path - Find Your Career Trail
mkilby
0
54
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
659
61k
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
2
240
What’s in a name? Adding method to the madness
productmarketing
PRO
24
3.9k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
9.9k
Prompt Engineering for Job Search
mfonobong
0
160
Have SEOs Ruined the Internet? - User Awareness of SEO in 2025
akashhashmi
0
270
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.6k
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
0
320
svc-hook: hooking system calls on ARM64 by binary rewriting
retrage
1
99
Transcript
2017/08/02 ಙؙຊྠಡձ ηογϣϯϋΠδϟοΫ
͜Ε·ͰͷྲྀΕ ΫϩεαΠτεΫϦϓςΟϯά(ాɾߥʣ SQLΠϯδΣΫγϣϯʢখʣ CSRFʢຢʣ
͜Ε·ͰͷྲྀΕ ΫϩεαΠτεΫϦϓςΟϯά(ాɾߥʣ SQLΠϯδΣΫγϣϯʢখʣ CSRFʢຢʣ NEW!→ηογϣϯϋΠδϟοΫʢాʣ
ηογϣϯͷ͓͞Β͍
ηογϣϯͱ ϩάΠϯ͔ͯ͠ΒϩάΞτ͢Δ·ͰͷΑ͏ͳҰ࿈ͷखଓ͖ͷ͜ͱɻ ηογϣϯཧΛߦ͏͜ͱͰɺ௨ৗεςʔτϨεͳHTTPʹ͓͍ͯɺϩάΠϯ ใΦϯϥΠϯγϣοϐϯάγεςϜͷΧʔτͳͲͷใΛอଘͯ͠ɺඞཁ ͳ࣌ʹऔΓग़͢͜ͱ͕Ͱ͖Δɻ
ηογϣϯϋΠδϟοΫͱ ౪ɾਪଌͳͲͷํ๏ͰηογϣϯIDΛಛఆ͠ ΞΧϯτΛͬऔΔ߈ܸ
ηογϣϯϋΠδϟοΫͷྨ ֮͑Α͏ ਪଌɹ౪ɹڧ੍
ηογϣϯϋΠδϟοΫͷྨ ֮͑Α͏ ਪଌɹ౪ɹڧ੍
ਪଌՄೳͳηογϣϯID ʢཁ͢ΔʹɺצͰͯΕͦ͏ͳจࣈྻʣ
ਪଌՄೳͳηογϣϯID ਪଌՄೳͳηογϣϯʹର͢Δ߈ܸख๏ 1.ରΞϓϦέʔγϣϯ͔ΒηογϣϯID ΛूΊΔ 2.ηογϣϯIDͷنଇੑͷԾઆΛཱͯΔ 3.ਪଌͨ͠ηογϣϯIDͰରΞϓϦέʔγϣϯΛ߈ܸ ରࡦˠWEBΞϓϦέʔγϣϯ։ൃπʔϧͷηογϣϯػߏΛ͏
ηογϣϯϋΠδϟοΫͷྨ ֮͑Α͏ ਪଌɹ౪ɹڧ੍
౪ՄೳͳηογϣϯID URLʹηογϣϯIDؚ͕·Ε͍ͯΔ߹ ηογϣϯ ID ͕ URL ʹؚ·Ε ͍ͯΔͱɺͲͷϖʔδ͔Β ભҠ͖͔ͯͨ͠ϒϥβ͕ ૹ৴ͯ͘͠Δ
REFERER ʹΑͬ ͯηογϣϯ ID ͕࿙Ӯ͢Δ ͜ͱ͕͋Γ·͢ɻηογϣ ϯ ID COOKIE ʹ֨ೲ͠ɺ COOKIE ʹ֨ೲͰ͖ͳ͍߹ʹ URL ʹηογϣϯ ID ؚ͕· Εͳ͍Α͏ʹઃఆ͓͖ͯ͠ ·͢ɻ
ηογϣϯϋΠδϟοΫͷྨ ֮͑Α͏ ਪଌɹ౪ɹڧ੍
ηογϣϯIDͷݻఆԽ ηογϣϯIDͷݻఆԽ߈ܸɺਖ਼نͷαΠτ͔ΒѱҙΛ࣋ͬͨϢʔβ͕ηογϣϯID Λऔಘ͠ɺͦͷηογϣϯIDΛଞͷϢʔβʹڧ੍͢Δɻ ڧ੍͞ΕͨηογϣϯIDͰϢʔβ͕ϩάΠϯΛߦͬͨ߹ɺͦͷηογϣϯIDΛݩʑ ͍ͬͯΔѱҙΛ࣋ͬͨϢʔβϩάΠϯͨ͠ϢʔβʹΓΘͬͯૢ࡞Λߦ͏͜ͱ ͕Ͱ͖Δɻ
ηογϣϯIDͷݻఆԽ ରࡦˠϩάΠϯޙʹηογϣϯΛ৽نʹ࡞ΔʢηογϣϯIDͷ࠶ൃߦʣ ରࡦ̎ˠϩάΠϯޙʹηογϣϯIDͱผʹೝՄ͞Εͨ͜ͱΛূ໌͢ΔใΛՃ͢Δɻ
·ͱΊ
·ͱΊ ɾηογϣϯཧػߏΛࣗ࡞͠ͳ͍ʢਪଌରࡦʣ →WEBΞϓϦέʔγϣϯ։ൃπʔϧΛ͏ ɾURLʹηογϣϯIDΛຒΊࠐ·ͳ͍ʢ౪ରࡦʣ →ΫοΩʔͰηογϣϯIDΛཧ͢Δ ɾೝূޭ࣌ʹηογϣϯIDΛมߋ͢Δ(ڧ੍ରࡦʣ
͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠