前の投稿 次の投稿

脆弱性の見つけ方(初心者向け脆弱性検査入門)


EC-CUBEmixi





HTTPHTTPHTTP



HTTPAHTTPB

(A)(B)-WEB使

使FiddlerBurp Suite使

Fiddler使

Fiddler - digital matter
Web > Fiddler 使
Web > Fiddler 

FiddlerFiddler

Fiddler



PCWEBXAMPPFiddler

FiddlerFiddlerURLHTTPHTTP

InspectorsRawSSLSSL


FiddlerFiddlerFiddler

Fiddler
 Fiddler

Fiddler
FiddlerRun to CompletionFiddler



example.comGET

GET

GET http://example.com/?q=a HTTP/1.1
Host: example.com
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: ja,en-us;q=0.7,en;q=0.3
Referer: http://example.com/ref
Cookie: uid=12345
Connection: keep-alive

GETq
Cookieuid



GETq
xxxxxyyyyyzzzzz

"'<」﹁>HTMLXSS

HTMLHTMLXSS
*XSS

Cookieuid
IDSQL'SQL1234512344

'ID




GET





WEB

WEB



XSS"<」や﹁>HTMLXSSXSS"<」や﹁>




IPA

(IPA)  ()
http://www.ipa.go.jp/security/vuln/vuln_contents/index.html
(IPA) 
https://www.ipa.go.jp/security/vuln/websecurity.html









/
ockeghem() 2008-11-17 SQL
SQL




WEB




Leave a Reply

Powered by Blogger.
© WEB系情報セキュリティ学習メモ Suffusion theme by Sayontan Sinha. Converted by tmwwtw for LiteThemes.com.