{"description":"\u5c11\u3057\u524d\u306b\u516c\u958b\u3055\u308c\u305f\u3082\u306e\u3060\u304c\u3001Portswigger\u306eDaily swig\u7d4c\u7531\u3067\u898b\u3064\u3051\u305f\u3001MS\u306e\u5c0f\u52dd\u3055\u3093\u304c\u5831\u544a\u3057\u305fChrome\u306eCSP bypass\u30d0\u30b0\u306b\u3064\u3044\u3066\u3002\u3084\u3089\u308c\u308b\u5074\u306f\u4f8b\u3048\u3070\u4e0b\u8a18\u306e\u3088\u3046\u306a\u30da\u30fc\u30b8\u3002nonce\u306eCSP\u3092\u4f7f\u3063\u3066\u3044\u308b\u3002 <meta http-equiv=\"content-security-policy\" content=\"script-src 'nonce-testrandom'\"> <body> <?= $_GET['param'] ?> \u2190 \u30a8\u30b9\u30b1\u30fc\u30d7\u7121\u3057 </body> \u653b\u6483\u8005\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306biframe\u3092\u633f\u5165\u3057\u3066\u3084\u308b\uff08\u3053\u3053\u3067\u306f\u7c21\u5358\u306e\u305f\u3081srcdoc\u3092\u4f7f\u3063\u3066\u3044\u308b\uff09\u3002 <meta\u2026","image_url":null,"published":"2021-07-08 16:48:29","provider_url":"https://hatena.blog","categories":[],"type":"rich","provider_name":"Hatena Blog","author_url":"https://blog.hatena.ne.jp/teracc/","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fblog.ts5.me%2Fentry%2F2021%2F07%2F08%2F164829\" title=\"CSP bypass - teracc\u2019s blog\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","title":"CSP bypass","version":"1.0","width":"100%","url":"https://blog.ts5.me/entry/2021/07/08/164829","blog_url":"https://blog.ts5.me/","author_name":"teracc","height":"190","blog_title":"teracc\u2019s blog"}