{"provider_url":"https://hatena.blog","author_name":"megane_bomb","width":"100%","published":"2010-06-10 09:52:35","height":"190","author_url":"https://blog.hatena.ne.jp/megane_bomb/","title":"CSRF\u30fbXSS\u8106\u5f31\u6027\u5bfe\u7b56","blog_title":"\u30e1\u30ac\u30cd\u5973\u5b50(21)\u306e\u30e1\u30e2\u30d6\u30ed\u30b0","categories":["memo","PHP"],"version":"1.0","url":"https://megane-bomb.hatenadiary.org/entry/20100610/1276217555","type":"rich","description":"\u25a0CSRF\u8106\u5f31\u6027\u5bfe\u7b56\u30ef\u30f3\u30bf\u30a4\u30e0\u30c8\u30fc\u30af\u30f3\u3092\u4f7f\u7528\u3057\u305f\u5bfe\u7b56 \u753b\u9762\uff11\u3067\u30c8\u30fc\u30af\u30f3\u3092\u4f5c\u6210\u3057\u3066\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u306b\u66f8\u304d\u8fbc\u3080 \u2193 \u753b\u9762\uff12\u306b\u9077\u79fb\u3059\u308b\u3068\u304d\u306b\u3001POST\u306a\u3069\u3067\u5024\u3092\u3082\u3063\u3066\u884c\u304f \u305d\u306e\u3068\u304d\u306b\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u5185\u306e\u5024\u3092POST\u306e\u6301\u3063\u3066\u3044\u308b\u5024\u3092\u6bd4\u8f03\u3057\u3066\u3001\u4e00\u81f4\u3059\u308c\u3070\u6b63\u3057\u3044\u3068\u8a00\u3048\u308b \u203b\u540c\u6642\u306b\uff12\u753b\u9762\u3092\u3042\u3051\u308b\u5834\u5408\u306a\u3069\u3082\u3042\u308b\u306e\u3067\u3001\u30c8\u30fc\u30af\u30f3\u306f\u914d\u5217\u3068\u3057\u3066\u30bb\u30c3\u30b7\u30e7\u30f3\u767b\u9332\u3059\u308b\u3002 \u2192in array\u3092\u4f7f\u7528\u3057\u3066\u3001\u4e00\u81f4\u3059\u308b\u304b\u3057\u306a\u3044\u304b\u3059\u3050\u308f\u304b\u308b \u25a0XSS(\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0)\u5bfe\u7b56 \u51fa\u529b\u6642\u306b \u300chtmlspecialchars()\u300d \u3067\u5fc5\u305a\u30a8\u30b9\u30b1\u30fc\u30d7\u3057\u306a\u3044\u3068\u3044\u3051\u306a\u3044\u3002\u30b5\u30cb\u30bf\u30a4\u30ba\u3068\u306f\uff1f \u5165\u529b\u5024\u3092DB\u306a\u3069\u306b\u767b\u9332\u3059\u308b\u524d\u306b\u30a8\u30b9\u30b1\u30fc\u30d7\u3057\u305f\u308a\u3057\u3066\u7121\u6bd2\u2026","image_url":null,"html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fmegane-bomb.hatenadiary.org%2Fentry%2F20100610%2F1276217555\" title=\"CSRF\u30fbXSS\u8106\u5f31\u6027\u5bfe\u7b56 - \u30e1\u30ac\u30cd\u5973\u5b50(21)\u306e\u30e1\u30e2\u30d6\u30ed\u30b0\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","provider_name":"Hatena Blog","blog_url":"https://megane-bomb.hatenadiary.org/"}