Hack Patch!

Stories of hacking, patching, and hacking.

2017年12月31日日曜日

ブラウザ セキュリティの近状

›
7月中旬からEdgeのセキュリティの仕事を始めて、各ブラウザごとに面白いセキュリティの対策をしていることを学んだのでまとめてみる。ちなみに、僕が担当しているのはSOPバイパスなどのデザインレベルのバグですが、最近のブラウザ セキュリティで各社アツいのは「メモリ破壊を使った攻撃を設...
2017年10月7日土曜日

PWA - Progressive Web Attack

›
Today, I'm going to blog about PWA (Progressive Web Apps)🙂 These days, web is getting bit secure by the help of CSP, which turns X...
2017年5月16日火曜日

Is your ePub reader secure enough?

›
Hi, this is my first (and last?) blog post in English. Sorry if there's any grammatical mistake, I'm not too fluent in English. To...
4 件のコメント:
2016年12月20日火曜日

iframe sandboxの真実

›
「 脆弱性"&'<<>\ Advent Calendar 2016 」20日目の記事です。 今回はiframe sandboxの仕様から漏れた脆弱性とは言えないものの話です。 1. ダウンロード iframe sandboxで...
2016年12月9日金曜日

Edgeのアドレスバー偽装

›
「 脆弱性"&'<<>\ Advent Calendar 2016 」9日目の記事です。 追記 ------------------------------------------------------------- MSRC...
2016年12月8日木曜日

セキュリティ製品のお話

›
「 脆弱性"&'<<>\ Advent Calendar 2016 」8日目の記事です。 「このまま黙って見てればキヌガワさんの隠しテクバンバン公開されるんじゃね?」と思ってしまったあなた、今すぐ 脆弱性"&...
2016年12月3日土曜日

CyVDB-1118関連

›
「 脆弱性"&'<<>\ Advent Calendar 2016 」3日目の記事です。 今回は CyVDB-1118 関連の話です。CyVDB-1118はアップロード型の RFD で、会社のプロファイル画像にScriptタグが入っ...
‹
›
ホーム
ウェブ バージョンを表示
Powered by Blogger.