¡Ö¥¯¥í¥¹¥µ¥¤¥È¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê¡×¤¬¤Ë¤ï¤«¤ËÃíÌܤò½¸¤á¤Æ¤¤¤ë¡£¸Å¤¯ ¤«¤é¸ºß¤·¤¿¤³¤ÎÌäÂ꤬¤Ê¤¼º£¤Þ¤Ç¤¢¤Þ¤êÃíÌܤµ¤ì¤Æ¤³¤Ê¤«¤Ã¤¿¤«¤Ë¤Ä¤¤¤Æ¹Í ¤¨¤Æ¤¤¤ë¤È¤³¤í¤À¤¬¡¢°ú±Û¤·¤ä¤éž¶Ð¤ä¤é¤Ç¤¤¤Þ¤Ò¤È¤ÄÆüµ¤ò½ñ¤¯»þ´Ö¤¬¤Ê¤¤¡£ ¤·¤«¤·¡¢ @IT¤Îµ»ö¤Ê¤É¤Î¤è¤¦¤Ëº®Í𤵤»¤ë²òÀâ¤â»¶¸«¤µ¤ì¤ë¤Î¤Ç¡¢°ìÅÀ¤À¤±Âкö ÊýË¡¤Ë¤Ä¤¤¤Æ½ñ¤¤¤Æ¤ª¤¯¤È¤¹¤ë¡£
¥¯¥í¥¹¥µ¥¤¥È¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê¡½¡½Cross-Site Request Forgeries (CSRF)¤òËɻߤ¹¤ë´Ê·é¤Ç¼«Á³¤Ê²ò·èºö¤Ï°Ê²¼¤Î¤È¤ª¤ê¤Ç¤¢¤ë¡£
¥í¥°¥¤¥ó¤·¤Æ¤¤¤Ê¤¤Web±ÜÍ÷¼Ô¤ËÂФ¹¤ëCSRF¹¶·â¡Ê·Ç¼¨ÈĹӤ餷¤ä¡¢¥æ¡¼¥¶ÅÐ Ï¿¤ò¾¿Í¤Ë¤µ¤»¤ëÅù¡¢¥µ¥¤¥È±¿±Ä¼Ô¤ËÂФ¹¤ë¶È̳˸³²¹Ô°Ù¡Ë¤Ï¤³¤³¤Ç¤ÏÂÐ¾Ý¤È ¤·¤Ê¤¤¡£
¥í¥°¥¤¥óµ¡Ç½¤ò»ý¤ÄWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¾ì¹ç¡¢²¿¤é¤«¤ÎÊýË¡¤Ç¥»¥Ã¥·¥ç¥ó ÄÉÀסʥ»¥Ã¥·¥ç¥ó´ÉÍý¡Ë¤ò¹Ô¤Ã¤Æ¤¤¤ë¤Ï¤º¤Ç¤¢¤ê¡¢¤½¤ì¤òcookie¤ÎÃͤòÍê¤ê¤Ë ¹Ô¤Ã¤Æ¤¤¤ë¾ì¹ç¡¢¤½¤Îcookie¤ÎÃͤÏÂè»°¼Ô¤Ë¤Ïͽ¬ÉÔǽ¤ÊÃͤ¬Áª¤Ð¤ì¤Æ¤¤¤ë¤Ï ¤º¤Ç¤¢¤ë¡£¡Ê¤Ç¤Ê¤±¤ì¤Ð¡¢¥»¥Ã¥·¥ç¥ó¥Ï¥¤¥¸¥ã¥Ã¥¯¤µ¤ì¤¿¤ê¡¢¤Ê¤ê¤¹¤Þ¤·¥í¥° ¥¤¥ó¤µ¤ì¤Æ¤·¤Þ¤¦¤Î¤À¤«¤é¡¢CSRF°ÊÁ°¤Î½ÅÂç¤Ê·ç´Ù¤¬¤¢¤ë¤³¤È¤Ë¤Ê¤ë¡£¡Ë
ºÇ¤â¼«Á³¤ÊÊý¼°¤Ç¤Ï¡¢¥í¥°¥¤¥ó¤´¤È¤Ëȯ¹Ô¤¹¤ë¥é¥ó¥À¥à¤Ê¼õÉÕÈֹ桢¤Ä¤Þ¤ê ¡Ö¥»¥Ã¥·¥ç¥óID¡×¤ò1¸Ä¡Ê¤Ê¤¤¤· https:// ÀìÍѤò´Þ¤à2¸Ä¡ËÍѤ¤¤Æ¡¢¤É¤Î¥æ¡¼ ¥¶¤«¤é¤Î¥¢¥¯¥»¥¹¤Ê¤Î¤«¤ò¸¡º÷¤·¤ÆÆÃÄꤹ¤ë¡½¡½(A)¡£¤³¤ÎÃͤò½½¿ô·å°Ê¾å¤Î Íð¿ô¤È¤¹¤ë¤³¤È¤Ç¡¢¶öÁ³¤ËŪÃ椹¤ë³ÎΨ¤ò²¿²¯Ê¬¤Î1¤Þ¤Ç¤Ë¾®¤µ¤¯¤·¤Æ¤¤¤ë¡£
¤¢¤Þ¤êŬÀڤǤϤʤ¤¤¬²¿¤é¤«¤ÎÅÔ¹ç¤Ç¥»¥Ã¥·¥ç¥óID¤ò»È¤ï¤º¤Ë¡¢cookie¤Ë¥æ¡¼ ¥¶ID¤òÆþ¤ì¤ëÊý¼°¤È¤Ê¤Ã¤Æ¤¤¤ë¾ì¹ç¤â¤¢¤ë¤¬¡¢¤½¤ì¤À¤±¤Ç¤Ïͽ¬ÉÔǽ¤È¤Ï¤Ê¤é ¤Ê¤¤¤Î¤Ç¡¢¤½¤¦¤·¤¿¾ì¹ç¤Ï¤½¤Î¥æ¡¼¥¶¤Î¥Ñ¥¹¥ï¡¼¥É¤Î¥Ï¥Ã¥·¥åÃͤʤɤâcookie ¤Ë³ÊǼ¤·¤Æ¡¢¥Ú¡¼¥¸Ëè¤ËξÊý¤ò³Îǧ¤¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ¡¢¤Ê¤ê¤¹¤Þ¤·¤µ¤ì¤Ê¤¤¥»¥Ã ¥·¥ç¥óÄÉÀפò¼Â¸½¤¹¤ë¤³¤È¤Ë¤Ê¤ë¡½¡½(B)¡£¤³¤Î¾ì¹ç¤Îͽ¬ÉÔǽÀ¤Ï¡¢¥Ñ¥¹¥ï¡¼ ¥É¤¬Í½Â¬ÉÔǽ¤Ê¤Ï¤º¤Ç¤¢¤ë¤³¤È¤ËΩµÓ¤·¤Æ¤¤¤ë¡£
CSRF¤òËɤ°É¬Íפ¬¤¢¤ë¤Î¤Ï¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ²¿¤é¤«¤Î¹±µ×Ū¤Ê ¥Ç¡¼¥¿Êѹ¹¤òȯÀ¸¤µ¤»¤ë¥¢¥¯¥»¥¹¤È¤Ê¤ë¥Ú¡¼¥¸¡ÊÅÐÏ¿¾ðÊóÊѹ¹¡¢ÀßÄêÊѹ¹¡¢Âà ²ñ½èÍý¡¢Ãíʸ¼Â¹Ô¡¢¼è¤ê¾Ã¤·¤Ê¤É¡Ë¤Ç¤¢¤ë¡£¤¿¤È¤¨¤Ð¡¢¾ðÊó¤òɽ¼¨¤¹¤ë¤À¤±¤Î ¥Ú¡¼¥¸¤Ë¤ÏÂкö¤¬ÉÔÍס¢¤â¤·¤¯¤Ï½ÅÍ×À¤¬Ä㤤¡Ê¸å½Ò¤Î¡Ö2¥Ú¡¼¥¸Ìܡפʤɡˡ£ ¥·¥ç¥Ã¥Ô¥ó¥°¥«¡¼¥È¤Ø¤Î¾¦ÉÊÄɲäʤɤΤ褦¤Ë¡¢°ì»þŪ¤Ê¾õÂÖÊѹ¹¤ò²Ã¤¨¤ë¤À ¤±¤Î¥Ú¡¼¥¸¤ËÂФ¹¤ëCSRFÂкö¤Î½ÅÍ×À¤ÏÄã¤á¤È¤Ê¤ë*1¡£
¤¿¤È¤¨¤Ð½»½êÊѹ¹¤Îµ¡Ç½¤òÁÛÄꤹ¤ë¤È¡¢1¥Ú¡¼¥¸ÌܤǸ½ºß¤ÎÅÐÏ¿¾ðÊó¤¬ÆþÎÏÍó ¤ËËä¤á¹þ¤Þ¤ì¤Æɽ¼¨¤µ¤ì¡¢¤½¤ÎÆþÎÏÍó¤ÎɬÍפÊÉôʬ¤ò½ñ¤´¹¤¨¤Æ¥Ü¥¿¥ó¤ò²¡¤¹ ¤È 2¥Ú¡¼¥¸ÌܤdzÎǧ²èÌ̤Ȥʤꡢ¡ÖÊѹ¹¡×¥Ü¥¿¥ó¤ò²¡¤¹¤ÈÊѹ¹¤¬½èÍý¤µ¤ì¤Æ 3 ¥Ú¡¼¥¸Ìܤ¬É½¼¨¤µ¤ì¤ë¤È¤¤¤¦¹½À®¤¬Â¿¤¤¡£¤³¤³¤Ç¡¢3¥Ú¡¼¥¸ÌܤËľÀܳ°Éô¤«¤é ¥¸¥ã¥ó¥×¤µ¤»¤é¤ì¤ë¤È¡¢½»½ê¤ò¾¡¼ê¤ËÊѹ¹¤µ¤ì¤Æ¤·¤Þ¤¦¤³¤È¤¬µ¯¤¤ë¡£
Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ¥Ç¡¼¥¿Êѹ¹¤ò½èÍý¤µ¤»¤ë¥Ú¡¼¥¸¡ÊÁ°½Ò¤Î¡Ö3¥Ú¡¼ ¥¸ÌܡסˤÎÁ°¤Î¥Ú¡¼¥¸¡ÊÁ°½Ò¤Î¡Ö2¥Ú¡¼¥¸Ìܡסˤ˰ʲ¼¤ÎHTMLÍ×ÁǤò´Þ¤Þ¤»¤ë¡£
<input type="hidden" name="sessionid" value="¥»¥Ã¥·¥ç¥óÄÉÀ×ÍÑcookie¤ÎÃÍ">
¤½¤·¤Æ¡¢¡Ö3¥Ú¡¼¥¸Ìܡפǡ¢¤½¤³¤ËÁ÷¿®¤µ¤ì¤Æ¤¯¤ë¤³¤ÎÃͤ¬¡¢cookie¤Î¤½¤ÎÃÍ ¤È°ìÃפ·¤Æ¤¤¤ë¤«¤òÄ´¤Ù¤Æ¡¢°ìÃפ·¤Æ¤¤¤ë¤È¤¤À¤±½èÍý¤ò¼Â¹Ô¤¹¤ë¡£
¡Ö¥»¥Ã¥·¥ç¥óÄÉÀ×ÍÑcookie¤ÎÃ͡פˤϡ¢Á°½Ò¤Î(A)Êý¼°¤Ê¤é¤Ð¥»¥Ã¥·¥ç¥óID¤Î ÃÍ¡¢(B)Êý¼°¤Ê¤é¤Ð¥æ¡¼¥¶ID¤È¥Ñ¥¹¥ï¡¼¥É¡Ê¤Î¥Ï¥Ã¥·¥åÃͤʤɡˤÎξÊý¤ò³ÊǼ ¤·¡¢¡Ö3¥Ú¡¼¥¸ÌܡפǤ½¤ì¤¾¤ì¤Î°ìÃפò³Î¤«¤á¤ë¡£
Âè»°¼Ô¥µ¥¤¥È¤«¤é¡Ö3¥Ú¡¼¥¸ÌܡפؤΥϥ¤¥Ñ¡¼¥ê¥ó¥¯¡ÊJavaScript¤Ë¤è¤ë¼«Æ° POST¤ò´Þ¤à¡Ë¤¬ºî¤é¤ì¤Æ¤â¡¢°ìÃפµ¤»¤ëÃͤòͽ¬¤¹¤ë¤³¤È¤ÏÉÔǽ¤Ç¤¢¤ë¤Ï¤º¤Ê ¤Î¤Ç¡¢CSRF¹¶·â¤ÏÀ®¸ù¤·¤Ê¤¤¡£
°ìÃפ¹¤ë¤«¤ò³Îǧ¤¹¤ë¤Î¤Ï¡Ö3¥Ú¡¼¥¸ÌܡפÀ¤±¤Ç¤è¤¤¤Î¤«¡£¤½¤Î¤Þ¤Þ¤Ç¤Ï¡¢ ¡Ö2¥Ú¡¼¥¸ÌܡפؤΥϥ¤¥Ñ¡¼¥ê¥ó¥¯¤òºî¤ë¤³¤È¤Ï¤Ç¤¤Æ¤·¤Þ¤¦¡£¤·¤«¤·¤½¤Î¾ì ¹ç¡¢Èï³²¼Ô¤Ï¡Ö2¥Ú¡¼¥¸Ìܡפ¬¸½¤ì¤¿¤È¤³¤í¤Ç¼«È¯Åª¤Ë¡Ö3¥Ú¡¼¥¸ÌÜ¡×¤Ø¿Ê¤à ¥Ü¥¿¥ó¤ò²¡¤µ¤Ê¤¤¸Â¤êÈï³²¤ËÁø¤ï¤Ê¤¤¡ÊXSSÀȼåÀ¤Ê¤É¾¤ÎÀȼåÀ¤¬¤Ê¤±¤ì¤Ð¡Ë¡£
¤½¤³¤Ç¥Ü¥¿¥ó¤ò²¡¤·¤Æ¤·¤Þ¤¤¤ä¤¹¤¤¤«¤É¤¦¤«¤Ï¡¢¡Ö2¥Ú¡¼¥¸ÌܡפβèÌÌÆâÍÆ¤Ë °Í¸¤¹¤ë¡£¤¿¤È¤¨¤Ð¡¢¡ÖËÜÅö¤Ë¼Â¹Ô¤·¤Þ¤¹¤«¡©¡×°Ê³°¤Ë²¿¤â½ñ¤«¤ì¤Æ¤¤¤Ê¤¤ ¡Ö2¥Ú¡¼¥¸ÌܡפǤ¢¤ë¾ì¹ç¤Ë¤Ï¡¢¥Ü¥¿¥ó¤ò²¡¤·¤Æ¤·¤Þ¤¦¤«¤â¤·¤ì¤Ê¤¤¤Î¤Ç¡¢ ¤µ¤é¤ËÁ°¤Î¥Ú¡¼¥¸¤«¤éƱÍͤÎÂкö¤¬É¬ÍפȤʤ롣¤â¤Ã¤È¤â¡¢¥Ü¥¿¥ó¤ò²¡¤¹¤È²¿ ¤¬µ¯¤¤ë¤Î¤«¤òŬÀÚ¤ËÀâÌÀ¤·¤Æ¤ª¤¯¤³¤È¤Ï¡¢¤â¤È¤è¤êÍ׵ᤵ¤ì¤ë¤È¤³¤í¤Ç¤¢¤ë¡£
¡Ê³¤¯¡Ë
*1 Ãíʸ¼Â¹Ô»þ¤Ë¥«¡¼ ¥È¤ÎÆâÍƤò³Îǧ¤¹¤ë¤è¤¦¤Ëºî¤é¤ì¤Æ¤¤¤ë¤Ù¤¤Ê¤Î¤Ç¡¢¤½¤¦¤Ê¤Ã¤Æ¤¤¤ì¤Ð¡¢µ¤ÉÕ ¤«¤Ê¤¤¥æ¡¼¥¶¤ÎÀÕǤ¤È¤Ê¤ë¡£
*2 JavaScript¤Ç¼«Æ°POST¤µ¤»¤é¤ì¤ë¡£
*3 ³Îǧ²èÌ̤μ¡¤Î¼Â¹Ô²èÌ̤ËľÀÜ¥¸¥ã ¥ó¥×¤µ¤»¤é¤ì¤ë¡£
*4 Âкö¤Ë¤Ê¤é¤Ê¤¤Íýͳ ¤Ï¡¢Referer:¤òÁ÷¿®¤·¤Ê¤¤ÀßÄê¤Ë¤·¤Æ¤¤¤ë¥æ¡¼¥¶¤¬¤¤¤ë¤¿¤á¡£Referer:µ¶Áõ¤¬ ÌäÂê¤È¤Ê¤ë¤Î¤Ï¡¢¥»¥Ã¥·¥ç¥ó¥Ï¥¤¥¸¥ã¥Ã¥¯Ëɻߤ䡢¤Ê¤ê¤¹¤Þ¤·¥¢¥¯¥»¥¹ËɻߤΠ¤¿¤á¤ËReferer:¥Á¥§¥Ã¥¯¤ò¤¹¤ëÏäξì¹ç¡£¹¶·â¼Ô¤¬Èï³²¼Ô¤ÎÁ÷¿®¤¹¤ëReferer: ¤ò½ñ¤´¹¤¨¤ë¤³¤È¤Ï¤Ç¤¤Ê¤¤¤Î¤À¤«¤é¡¢CSRF¤ËReferer:µ¶Áõ¤Ï´Ø·¸¤Ê¤¤¡£
*5 ¸µ¡¹¤¢¤ë¥»¥Ã¥·¥ç ¥óÄÉÀ×ÍѤÎÈëÌ©¾ðÊó¤ò»È¤¨¤Ð¤è¤¤¡£
*6 Session Fixation¹¶·â¤Ë¤è¤Ã¤Æ²óÈò¤µ¤ì¤ë¡£
*7 ¡Ö2¥Ú¡¼¥¸Ìܡסʰú ¿ô¤ò»ý¤Ä¡Ë¤ËÂФ·¤ÆCSRF¹¶·â¤µ¤ì¡¢Â³¤¤¤Æ¡Ö3¥Ú¡¼¥¸ÌܡפËCSRF¹¶·â¤µ¤ì¤ë²Ä ǽÀ¤¬¤¢¤ë¤Î¤Ç¡¢Âкö¤Ë¤Ê¤é¤Ê¤¤¡£
ºòÆü¤Î¡Ö¥³¥é¥à¤¬¸¡±Ü°ú¤Ã¤«¤«¤ê¤Þ¤¯¤ê¡×¤Ç¿¨¤ì¤¿¡÷IT¡§¡Ö¤Ü¤¯¤Ï¤Þ¤Á¤Á¤ã¤ó¡× ¡½¡½ÃΤé¤ì¤¶¤ëCSRF¹¶·â¤¬ËÜÆü¤è¤ê¸ø³«¤·¤Æ¤¤¤Þ¤¹¡£ Äɵ:2005/4/27 ²¼µ¤ÇÊ䤷¤Æ夤¤Æ¤¤¤Þ¤¹¡£ ¡¦hoshikuzu | star_dust ¤Î½ñºØ - CSRFÂкö¤ÈCAPTCHA ¡¦yoggy¡Çs diary¡Á¤»¤«¤¤¤Î¤¹¤ß¤Ã¤³..
mixi ¤Ë¤ÏÆþ¤Ã¤Æ¤Ê¤¤¤Î¤Ç¾ÜºÙ¤â¤ï¤«¤é¤Ê¤¤¤·¡¢¤¤¤Á¤¤¤Á¤Ï¤ä¤ê¤â¤Î¤ËÈ¿±þ ¤·¤Æ¤¤¤ë¤È¤¤ê¤¬¤Ê¤¤¤Î¤ÇÀŴѤ·¤Æ¤¤¤¿¤¬¹âÌÚ¤µ¤ó¤ÎÆüµ¤Ë¼è¤ê¾å¤²¤é¤ì¤Æ¤¤¤ë¤Î¤Ç¡¢ CSRF¹¶·â¤Î¤³¤È¤ò¤Á¤È½ñ¤¤¤Æ¤ß¤ë¡£ http://takagi-hiromitsu.jp/diary/20050427.html#p01 Á´ÂÎŪ¤Ë¡¢¤ï¤«¤ê¤ä¤¹..
http://takagi-hiromitsu.jp/diary/20050427.html http://www.atmarkit.co.jp/fsecurity/column/ueno/33.html http://www.google.com/search?hl=ja&q=CSRF&btnG=Google+%E6%A4%9C%E7%B4%A2&lr=lang_ja ¥¯¥í¥¹¥µ¥¤¥È¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê ( CSRF ) ´ØÏ¢¤Î¤ª..
-[http://takagi-hiromitsu.jp/diary/:title] --¡ÖÌܼ¡¡×¤Î¥ê¥ó¥¯¤À¤±¡¢¤Ï¤Æ¤Ê¥À¥¤¥¢¥ê¤Î¤Þ¤Þ¤Ç¤¹¡£°Ü¹Ô´ü´ÖÃæ¤Ï¡¢Í°ÕµÁ¤À¤Ã¤¿¤â¤Î¤òľ¤·Ëº¤ì¤Æ¤¤¤ë¤Î¤Ç¤Ï?
CSRF(¥¯¥í¥¹¥µ¥¤¥È¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê)¤ÎÂкö¤ò¼«Ê¬¤ÎÃæ¤Ç·è¤á¤Æ¤ß¤Þ¤·¤¿¤¬...
CSRF¤Ë¤Ä¤¤¤Æ¡£
¡ÖCSRF¤Ã¤Æ²¿¡©¡×¤Ã¤ÆÏäÏGoogle¤Ë¾ù¤ë¤È¤·¤Æ¡¢CSRF¤ÎÂкö¤Ë¤Ä¤¤¤Æ¸í²ò¤ò¤·¤Æ¤¤¤¿¤ê¡¢Àµ¤·¤¯¤Ê¤¤Âнè¤ò¿ä¾©¤·¤Æ¤¤¤ë¥µ¥¤¥È¤¬Â¿¤¤µ¤¤¬¤·¤Þ¤¹¡£
¤È¤ê¤¢¤¨¤º
google¤Ç¡ÖCSRF¡×¤Ç°ú¤Ã¤«¤«¤ë¥µ¥¤¥È¤Î¾å°Ì¤Ë1¤Ä¤º¤Ä¥Ä¥Ã¥³¥ßÆþ¤ì¤Æ¤ß¤Þ¤¹¡£
http://www.s...
¥¯¥í¥¹ ¥µ¥¤¥È ¥ê¥¯¥¨¥¹¥È ¥Õ¥©¡¼¥¸¥§¥ê¤£Èï³²¼Ô¡©¡©
PHP¥µ¥¤¥Ð¡¼¥Æ¥í¤Îµ»Ë¡¡½¹¶·â¤ÈËɸæ¤Î¼ÂºÝ¥½¥·¥à(2005-11)(Ãø)GIJO...
³«È¯¼Ô¤Î¤¿¤á¤ÎÀµ¤·¤¤CSRFÂкö ¹âÌÚ¹À¸÷¡÷¼«Âð¤ÎÆüµ - ¥¯¥í¥¹¥µ¥¤¥È¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê¡ÊCSRF¡Ë¤ÎÀµ¤·¤¤ÂкöÊýË¡ ¤³¤á¤ó¤È(2006-03-30) ºÇ¶áWeb¥¢¥×¥ê¼«ÂÎÁȤޤʤ¤¤ó¤Ç¤¹¤±¤É¡Ä ...