{"id":14885,"date":"2017-12-10T09:00:18","date_gmt":"2017-12-10T00:00:18","guid":{"rendered":"http:\/\/www.techscore.com\/blog\/?p=14885"},"modified":"2018-11-14T16:33:42","modified_gmt":"2018-11-14T07:33:42","slug":"phishing","status":"publish","type":"post","link":"https:\/\/www.techscore.com\/blog\/2017\/12\/10\/phishing\/","title":{"rendered":"\u91e3\u308a\u304b\u3088 !!\uff08\u30d5\u30a3\u30c3\u30b7\u30f3\u30b0\u8a50\u6b3a\u3042\u308c\u3053\u308c\uff09"},"content":{"rendered":"<p><img loading=\"lazy\" width=\"600\" height=\"301\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/phishing-shutterstock.jpg\" alt=\"\" xwidth=\"300\" xheight=\"151\" xclass=\"alignnone size-medium wp-image-14889\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/phishing-shutterstock.jpg 600w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/phishing-shutterstock-300x151.jpg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><br \/>\n<span style=\"color: gray;\">\uff08Yanik Chauvin \/ Shutterstock.com\uff09<\/span><\/p>\n<p>\u3053\u3093\u306b\u3061\u306f\u3001\u4e2d\u5c71\u3067\u3059\uff08\u5199\u771f\u306f\u79c1\u3067\u306f\u3042\u308a\u307e\u305b\u3093\uff09\u3002<br \/>\n\u3053\u308c\u306f <a href=\"https:\/\/www.techscore.com\/blog\/2017\/11\/28\/techscore-advent-calendar-2017\/\" target=\"_blank\">TECHSCORE Advent Calendar 2017<\/a> \u306e 10 \u65e5\u76ee\u306e\u8a18\u4e8b\u3067\u3059\u3002<\/p>\n<p>\u4ee5\u524d\u3001\u3042\u308f\u3088\u304f\u3070\u3068 Google \u306e\u8106\u5f31\u6027\u5831\u511f\u91d1\u30d7\u30ed\u30b0\u30e9\u30e0\u306b\u5fdc\u52df\u3057\u305f\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\n\u3053\u3061\u3089\u304c\u5f53\u6642 Google \u306b\u5831\u544a\u3057\u305f\u5185\u5bb9\u3067\u3059\u3002<\/p>\n<blockquote><p>\nGoogle ad serviece has a security issue.<br \/>\n(open-redirection)<\/p>\n<p>Steps to reproduce the vulnerability:<br \/>\n1. http:\/\/pagead2.googlesyndication.com\/pagead\/imgad?id=CICAgIDQp961eBDYBRhaMggPIKH46gXDKg&clickTAG=https:\/\/evil.com\/<br \/>\n2. click ad<br \/>\n3. move to https:\/\/evil.com\/\n<\/p><\/blockquote>\n<p>\u78ba\u8a8d\u3057\u305f\u3068\u3053\u308d 2017\/11\/26 \u6642\u70b9\u3067\u3082\u4e0a\u8a18\u624b\u9806\u306f\u518d\u73fe\u53ef\u80fd\uff08Flash \u3092\u6709\u52b9\u306b\u3057\u3066\u3044\u308b\u5834\u5408\uff09\u3067\u3057\u305f\u3002<\/p>\n<p><img src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/phishing.png\" alt=\"\" width=\"400\" xheight=\"190\" xclass=\"alignnone size-medium wp-image-14888\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/phishing.png 599w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/phishing-300x190.png 300w\" sizes=\"(max-width: 599px) 100vw, 599px\" \/><\/p>\n<p>Google \u306e\u4fdd\u6301\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3068 Google \u306e\u81ea\u793e\u7a3f\u306e\u4fe1\u983c\u6027\u306b\u4fbf\u4e57\u3057\u3001\u60aa\u610f\u3042\u308b\u30da\u30fc\u30b8\u306b\u8a98\u5c0e\uff08\u3044\u308f\u3086\u308b Phishing\uff09\u53ef\u80fd\u3067\u3042\u308b\u3001\u3068\u3044\u3046\u6307\u6458\u3067\u3059\u3002<br \/>\n\u3053\u308c\u306b\u5bfe\u3059\u308b\u56de\u7b54\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3057\u305f\u3002<\/p>\n<blockquote><p>\nThanks for your email.<br \/>\nIn this particular case, we believe the usability and security benefits of a well-implemented and carefully monitored URL redirector tend to outweigh the perceived risks.<br \/>\nFor a more detailed explanation, check the URL redirection section here: http:\/\/www.google.com\/about\/appsecurity\/reward-program\/#notavuln\n<\/p><\/blockquote>\n<p>\u3068\u3044\u3046\u308f\u3051\u3067\u3001\u6b8b\u5ff5\u306a\u304c\u3089\u5831\u916c\u91d1\u306f\u30b2\u30c3\u30c8\u3067\u304d\u307e\u305b\u3093\u3067\u3057\u305f\uff08\u7b11\uff09\u3002<br \/>\n\u79c1\u306e\u6307\u6458\u306f\u3001\u3042\u308a\u304c\u3061\u306a\u4f4e\u30ea\u30b9\u30af\u554f\u984c\u3068\u306e\u3053\u3068\u3067\u3059\u3002<\/p>\n<p>\u9077\u79fb\u5148\u3092\u4f5c\u308a\u8fbc\u3093\u3060 Google \u306e\u507d\u30da\u30fc\u30b8\u306b\u3059\u308b\u3053\u3068\u3067\u3001\u9a19\u3055\u308c\u308b\u30b1\u30fc\u30b9\u304c\u3042\u308b\u306e\u3067\u306f\u3068\u8003\u3048\u307e\u3057\u305f\u304c\u3001\u5e83\u544a\u30d7\u30ed\u30c0\u30af\u30c8\u306b\u4f7f\u308f\u308c\u308b pagead2.googlesyndication.com \u30c9\u30e1\u30a4\u30f3\u3067\u306f\u78ba\u304b\u306b\u4f4e\u30ea\u30b9\u30af\u3067\u3059\u306d\u3002<br \/>\n\u305d\u3093\u306a\u308f\u3051\u3067\u3001\u4eca\u56de\u306f Phishing \u306b\u95a2\u3059\u308b\u8003\u5bdf\u3092\u8ff0\u3079\u305f\u3044\u3068\u601d\u3044\u307e\u3059\u3002<\/p>\n<h2>Phishing x pushState<\/h2>\n<p>\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30da\u30fc\u30b8\u9077\u79fb\u306e\u5834\u5408\u3001\u591a\u304f\u306e\u4eba\u306f\u4fe1\u983c\u3067\u304d\u308b\u30da\u30fc\u30b8\u306b\u623b\u308b\u3053\u3068\u3092\u671f\u5f85\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<style type='text\/css'>\nol.subno {\n    counter-reset: section;\n    list-style-type: none;\n}\nli.subno:before {\n    counter-increment: section;\n    content: counters(section, \".\") \" \";\n}\n<\/style>\n<ol class='subno'>\n<li class='subno'>\u4fe1\u983c\u3067\u304d\u308b\u30da\u30fc\u30b8\uff21\uff08trust.com\uff09\u3092\u95b2\u89a7<\/li>\n<li class='subno'>\u30ea\u30f3\u30af\u304b\u3089\u30da\u30fc\u30b8\uff22\uff08decoy.com\uff09\u306b\u9077\u79fb<\/li>\n<li class='subno'>\u30d2\u30b9\u30c8\u30ea\u30d0\u30c3\u30af<\/li>\n<li class='subno'><span style=\"color: red;\">\uff08 ... \u30da\u30fc\u30b8\uff21\u306e\u306f\u305a !?\uff09<\/span><\/li>\n<\/ol>\n<p>\u3067\u3059\u304c\u3001\u5b9f\u969b\u306b\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u9077\u79fb\u3068\u306a\u3063\u3066\u3044\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ol class='subno'>\n<li class='subno'>\u4fe1\u983c\u3067\u304d\u308b\u30da\u30fc\u30b8\uff21\uff08trust.com\uff09\u3092\u95b2\u89a7<\/li>\n<li class='subno'>\u30ea\u30f3\u30af\u304b\u3089\u30da\u30fc\u30b8\uff22\uff08decoy.com\uff09\u306b\u9077\u79fb\n<ol class='subno'>\n<li class='subno'>\u3053\u306e\u6642\uff22\u306f\u30c0\u30df\u30fc\u306e URL \u3092 history.pushState<\/li>\n<li class='subno'>\u30a2\u30c9\u30ec\u30b9\u30d0\u30fc\u306b\u306f\u30c0\u30df\u30fc\u306e URL \u3092\u8868\u793a\u3055\u308c\u308b<\/li>\n<\/ol>\n<\/li>\n<li class='subno'>\u30d2\u30b9\u30c8\u30ea\u30d0\u30c3\u30af\n<ol class='subno'>\n<li class='subno'>\u5143\u3005\u306e\uff22\u306e URL \u306b\u623b\u308b<\/li>\n<li class='subno'>\u3053\u306e\u6642\uff22\u306f onpopstate \u30a4\u30d9\u30f3\u30c8\u3092\u5b9f\u884c<\/li>\n<li class='subno'>\u30da\u30fc\u30b8\uff21\u3092\u5de7\u5999\u306b\u6a21\u3057\u305f\u30da\u30fc\u30b8\uff23\uff08evil.com\uff09\u306b\u5f37\u5236\u7684\u306b\u9077\u79fb<\/li>\n<\/ol>\n<\/li>\n<li class='subno'><span style=\"color: red;\">\u30e6\u30fc\u30b6\u30fc\u306f\u671f\u305b\u305a\u3057\u3066\u30da\u30fc\u30b8\uff23\uff08evil.com\uff09\u3092\u95b2\u89a7<\/span><br \/><span style=\"color: red; margin-left: 2em;\">\uff08URL \u3092\u78ba\u8a8d\u3057\u306a\u3044\u3068\u30da\u30fc\u30b8\uff21\u3060\u3068\u4fe1\u3058\u3066\u3057\u307e\u3046\u304b\u3082\u3057\u308c\u306a\u3044 !!\uff09<\/span><\/li>\n<\/ol>\n<p>\u3061\u306a\u307f\u306b\u30da\u30fc\u30b8\uff22\u306f\u3053\u3093\u306a\u611f\u3058\u3067\u3059\u3002<\/p>\n<pre class=\"lang:javascript\">\r\n<html>\r\n\r\n...\r\n\r\n<p> contents (decoy.com) <\/p>\r\n\r\n...\r\n\r\n<script>\r\nhistory.pushState({}, '', 'dummy-name.html');\r\nwindow.onpopstate = function (e) {\r\n    \/\/ history back ---> evil.com (looks like trust.com)\r\n    location.href = 'https:\/\/evil.com\/';\r\n}\r\n<\/script>\r\n<\/html>\r\n<\/pre>\n<p>\u30da\u30fc\u30b8\uff21\u306b UGC\uff08\u30e6\u30fc\u30b6\u30fc\u751f\u6210\u30b3\u30f3\u30c6\u30f3\u30c4\uff09\u3068\u3057\u3066\u5916\u90e8\u30ea\u30f3\u30af\u3092\u66f8\u304d\u8fbc\u3080\u3053\u3068\u304c\u51fa\u6765\u305f\u308a\u3001\u30da\u30fc\u30b8\uff21\u306b\u63b2\u8f09\u3055\u308c\u305f\u5e83\u544a\u304b\u3089\u30da\u30fc\u30b8\uff22\u306b\u8a98\u5c0e\u3059\u308b\u3053\u3068\u304c\u51fa\u6765\u305f\u5834\u5408\u3001\u3053\u306e\u3088\u3046\u306a\u9077\u79fb\u3082\u53ef\u80fd\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\uff08\u30da\u30fc\u30b8\uff21\u3092\u5de7\u5999\u306b\u6a21\u3057\u305f\uff09\u30da\u30fc\u30b8\uff23\u306e\u30bf\u30a4\u30df\u30f3\u30b0\u3067\u300c\u30bb\u30c3\u30b7\u30e7\u30f3\u5207\u308c\u3067\u30ed\u30b0\u30a2\u30a6\u30c8\u3057\u307e\u3057\u305f\u3002\u518d\u5ea6\u30ed\u30b0\u30a4\u30f3\u3057\u3066\u304f\u3060\u3055\u3044\u300d\u3068\u30ed\u30b0\u30a4\u30f3\u60c5\u5831\u306e\u518d\u5165\u529b\u3092\u4fc3\u3057\u305f\u5834\u5408\u3001\u4fc3\u3055\u308c\u308b\u307e\u307e\u306b\u5165\u529b\u3057\u3066\u3057\u307e\u3046\u4eba\u3082\u3044\u308b\u304b\u3082\u3057\u308c\u307e\u305b\u3093\u3002<\/p>\n<h2>Phishing x iframe<\/h2>\n<p>\u5168\u3066\u3092\u507d\u9020\u3057\u305f\u30da\u30fc\u30b8\u3068\u6bd4\u8f03\u3057\u3066\u3001\u672c\u7269\u306e\u30da\u30fc\u30b8\uff08\u306e\u4e00\u90e8\uff09\u304c\u66f8\u304d\u63db\u3048\u3089\u308c\u305f\u30b1\u30fc\u30b9\u3067\u306f\u3001\u507d\u9020\u306b\u6c17\u4ed8\u3051\u306a\u3044\u30ea\u30b9\u30af\u304c\u9ad8\u307e\u308a\u307e\u3059\u3002<br \/>\n\u4f8b\u3048\u3070\u30da\u30fc\u30b8\uff21\uff08trust.com\uff09\u304c\u4ee5\u4e0b\u306e\u6761\u4ef6<\/p>\n<ul>\n<li>\uff21\u306f iframe \u5185\u306b\u8868\u793a\u3055\u308c\u308b\u3053\u3068\u3092\u62d2\u5426\uff08X-Frame-Options: DENY\uff09\u3057\u3066\u3044\u306a\u3044<\/li>\n<li>\uff21\u306f\u30b3\u30f3\u30c6\u30f3\u30c4\u5185\u306b name \u5c5e\u6027\u306e\u5b9a\u7fa9\u3055\u308c\u305f iframe \u8981\u7d20\uff08\uff46\uff09\u3092\u6301\u3064<\/li>\n<\/ul>\n<p>\u3092\u6e80\u305f\u3059\u5834\u5408\uff46\u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u5dee\u3057\u66ff\u3048\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002<br \/>\n\u5177\u4f53\u7684\u306b\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30b3\u30f3\u30c6\u30f3\u30c4\u3092\u7528\u3044\u308b\u3053\u3068\u3067<\/p>\n<pre class=\"lang:javascript\">\r\n<body>\r\n<iframe src='https:\/\/trust.com\/'><\/iframe>\r\n<style type='text\/css'>\r\nBODY {\r\n    margin: 0px;\r\n    padding: 0px;\r\n}\r\nIFRAME {\r\n    margin: 0px;\r\n    padding: 0px;\r\n    border-style: none;\r\n    width: 100%;\r\n    height: 100%;\r\n}\r\n<\/style>\r\n<script>\r\nwindow.setTimeout(function() {\r\n    \/\/ REPLACE_TARGET \u306f\uff46\u306e name \u5c5e\u6027\u5024\r\n    window.open('https:\/\/evil.com\/', 'REPLACE_TARGET');\r\n}, 1000);\r\n<\/script>\r\n<\/body>\r\n<\/pre>\n<p>\u898b\u305f\u76ee\u306f\u30da\u30fc\u30b8\uff21\uff08trust.com\uff09\u306e\u307e\u307e\u3001\u4e00\u90e8\uff08\uff46\uff09\u3092 evil.com \u306e\u30b3\u30f3\u30c6\u30f3\u30c4\u306b\u5dee\u3057\u66ff\u3048\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<br \/>\n\u3055\u3089\u306b\u30ed\u30b0\u30a4\u30f3\u6a5f\u80fd\u3092\u6709\u3059\u308b\u30b5\u30fc\u30d3\u30b9\u306e\u5834\u5408\u3001\u30da\u30fc\u30b8\uff21\uff08\u30ed\u30b0\u30a4\u30f3\u4e2d\uff09\u306f\u30a2\u30ab\u30a6\u30f3\u30c8\u60c5\u5831\u306a\u3069\u304c\u8868\u793a\u3055\u308c\u308b\u305f\u3081\u3001\u81ea\u5206\u304c\u9a19\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u306b\u6c17\u4ed8\u3051\u306a\u304f\u306a\u308b\u30ea\u30b9\u30af\u3082\u9ad8\u307e\u308a\u307e\u3059\u3002<\/p>\n<p>\u5b9f\u969b\u306b\u3001\u4e0a\u8a18\u6761\u4ef6\u3092\u6e80\u305f\u3059\u30b5\u30fc\u30d3\u30b9\u3092\u898b\u3064\u3051\u308b\u3053\u3068\u306f\u96e3\u3057\u304f\u3042\u308a\u307e\u305b\u3093\u3002<br \/>\n\u3068\u3042\u308b\u5b9f\u5728\u3059\u308b\u30da\u30fc\u30b8\uff08\u30e2\u30b6\u30a4\u30af\u30d5\u30a3\u30eb\u30bf\u3092\u9069\u7528\u3057\u3066\u307e\u3059\uff09\u3067<\/p>\n<p><img src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/toyo11.png\" alt=\"\" width=\"250\" style=\"border: solid 1px gray;\" xclass=\"alignnone size-medium wp-image-14890\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/toyo11.png 506w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/toyo11-194x300.png 194w\" sizes=\"(max-width: 506px) 100vw, 506px\" \/><\/p>\n<p>\u4e0b\u65b9\u306e iframe \u3067\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u30d7\u30ec\u30b9\u30ea\u30ea\u30fc\u30b9\u90e8\u5206\u3092\u5dee\u3057\u66ff\u3048\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3057\u305f\u3002<\/p>\n<p><img src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/toyo22.png\" alt=\"\" width=\"250\" style=\"border: solid 1px gray;\" xclass=\"alignnone size-medium wp-image-14887\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/toyo22.png 506w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/toyo22-195x300.png 195w\" sizes=\"(max-width: 506px) 100vw, 506px\" \/><\/p>\n<p>\u3053\u306e\u30b5\u30fc\u30d3\u30b9\u306b\u306f\u30ed\u30b0\u30a4\u30f3\u6a5f\u80fd\u3082\u3042\u308b\u305f\u3081\u3001\u30ed\u30b0\u30a4\u30f3\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u7dad\u6301\u3057\u305f\u307e\u307e\u7f60\u30da\u30fc\u30b8\u306b\u8a98\u5c0e\u3055\u308c\u305f\u5834\u5408\u3001\u591a\u304f\u306e\u30e6\u30fc\u30b6\u30fc\u304c\u9a19\u3055\u308c\u3066\u3057\u307e\u3046\u5371\u967a\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u86c7\u8db3\u3067\u3059\u304c\u3001\u30d6\u30e9\u30a6\u30b6\u306e\u30a6\u30a4\u30f3\u30c9\u30a6\u64cd\u4f5c\uff08\u4e0a\u8ff0 window.open \u306a\u3069\uff09\u306b\u95a2\u3059\u308b\u4ed5\u69d8\u306f HTML5 \u306e 5.1 Browsing contexts \u3084 <a href=\"https:\/\/www.w3.org\/TR\/html5\/browsers.html#security-nav\" target=\"_blank\">5.1.4 Security<\/a> \u3092\u53c2\u8003\u306b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<h2 id=\"ssl\">Phishing x SSL\/EVSSL<\/h2>\n<p><img loading=\"lazy\" width=\"400\" height=\"270\" src=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/https.png\" alt=\"\" xwidth=\"300\" xheight=\"203\" xclass=\"alignnone size-medium wp-image-14912\" srcset=\"https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/https.png 400w, https:\/\/www.techscore.com\/blog\/wp\/wp-content\/uploads\/2017\/12\/https-300x203.png 300w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><br \/>\n\uff08https:\/\/news.netcraft.com\/archives\/2017\/05\/17\/phishing-sites-react-promptly-to-new-browser-changes.html\uff09<\/p>\n<p>2017\/05\/19 \u306b <a href=\"https:\/\/news.netcraft.com\/archives\/2017\/05\/17\/phishing-sites-react-promptly-to-new-browser-changes.html\" target=\"_blank\">NETCRAFT \u3067\u516c\u958b\u3055\u308c\u305f\u8cc7\u6599<\/a> \u304b\u3089 HTTPS \u3092\u7528\u3044\u305f Phishing \u30b5\u30a4\u30c8\u306e\u5272\u5408\u304c\u5897\u52a0\u50be\u5411\u306b\u3042\u308b\u3053\u3068\u304c\u5206\u304b\u308a\u307e\u3059\u3002<br \/>\n\u3053\u308c\u3092\u53d7\u3051\u3001\u8eab\u5143\u4fdd\u8a3c\u3092\u5f37\u5316\u3057\u305f EVSSL \u3092\u63a1\u7528\u3059\u308b\u30b5\u30fc\u30d3\u30b9\u3082\u5897\u3048\u3066\u304f\u308b\u3067\u3057\u3087\u3046\u3002<\/p>\n<p>\u4e00\u65b9\u3067 HTTPS \u5171\u7528\u30b5\u30fc\u30d3\u30b9\uff08\u5f0a\u793e\u306e <a href=\"https:\/\/www.synergy-marketing.co.jp\/cloud\/synergy\/function\/form.html\" target=\"_blank\">Synergy! FORM<\/a> \u6a5f\u80fd\u3082\u8a72\u5f53\u3057\u307e\u3059\uff09\u306b\u304a\u3044\u3066\u306f EVSSL \u306e\u63a1\u7528\u306b\u3088\u3063\u3066\u30ea\u30b9\u30af\u3092\u9ad8\u3081\u3066\u3057\u307e\u3046\u61f8\u5ff5\u304c\u3042\u308a\u307e\u3059\u3002<br \/>\n\u60aa\u610f\u3042\u308b\u4e8b\u696d\u8005\u304c HTTPS\uff08EVSSL\uff09\u5171\u7528\u30b5\u30fc\u30d3\u30b9\u3092\u5229\u7528\u3057\u3001\u7dd1\u8272\u306e\u30a2\u30c9\u30ec\u30b9\u30d0\u30fc\u3067\u30a8\u30f3\u30c9\u30e6\u30fc\u30b6\u30fc\u306e\u30df\u30b9\u30ea\u30fc\u30c9\u3092\u72d9\u3046\u53ef\u80fd\u6027\u304c\u3042\u308b\u304b\u3089\u3067\u3059\u3002<\/p>\n<p>\u8907\u6570\u30b5\u30fc\u30d3\u30b9\uff08\u4e8b\u696d\u8005\uff09\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u6a2a\u65ad\u3057\u305f\u4fe1\u983c\u95a2\u4fc2\u3092\u660e\u793a\u3059\u308b\u30d7\u30ed\u30c8\u30b3\u30eb\u306a\u308a UI \u306a\u308a\u3092\u4f5c\u308c\u308b\u3068\u3044\u3044\u306e\u3067\u3059\u304c\uff08\u2192 \u3053\u308c\u306b\u3064\u3044\u3066\u306f\u5225\u9014\u8003\u5bdf\u3057\u3066\u307f\u305f\u3044\u3068\u601d\u3044\u307e\u3059\uff09\u3002<\/p>\n<h2>\u307e\u3068\u3081<\/h2>\n<ul>\n<li>\u7279\u5225\u306a\u7406\u7531\u304c\u306a\u3051\u308c\u3070 X-Frame-Options \u306f\u4f7f\u3044\u307e\u3057\u3087\u3046<\/li>\n<li>\u30da\u30fc\u30b8\uff21\uff08trust.com\uff09\u3067\u3042\u308b\u306f\u305a\u3001\u3068\u3044\u3046\u601d\u3044\u8fbc\u307f\u306f\u6368\u3066\u307e\u3057\u3087\u3046<\/li>\n<li>\u9375\u30de\u30fc\u30af\u3067\u3082\uff08\u30b5\u30fc\u30d3\u30b9\u306b\u3088\u3063\u3066\u306f\u7dd1\u8272\u306e\u30a2\u30c9\u30ec\u30b9\u30d0\u30fc\u3067\u3082\uff09\u30ea\u30b9\u30af\u304c\u3042\u308b\u3053\u3068\u3092\u7406\u89e3\u3057\u307e\u3057\u3087\u3046<\/li>\n<li>\u514e\u306b\u3082\u89d2\u306b\u3082\u3001\u307e\u305a\u306f URL \u3092\u78ba\u8a8d\u3057\u307e\u3057\u3087\u3046 !!<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\uff08Yanik Chauvin \/ Shutterstock.com\uff09<\/p>\n<p>\u3053\u3093\u306b\u3061\u306f\u3001\u4e2d\u5c71\u3067\u3059\uff08\u5199\u771f\u306f\u79c1\u3067\u306f\u3042\u308a\u307e\u305b\u3093\uff09\u3002<br \/>\n\u3053\u308c\u306f TECHSCORE Advent Calendar 2017 \u306e 10 \u65e5\u76ee\u306e\u8a18\u4e8b\u3067\u3059\u3002<br \/><a href=\"https:\/\/www.techscore.com\/blog\/2017\/12\/10\/phishing\/\">\u7d9a\u304d\u3092\u8aad\u3080...<\/a><\/p>\n","protected":false},"author":19,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[276,18],"tags":[141,292,191,158],"_links":{"self":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts\/14885"}],"collection":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/comments?post=14885"}],"version-history":[{"count":29,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts\/14885\/revisions"}],"predecessor-version":[{"id":16850,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/posts\/14885\/revisions\/16850"}],"wp:attachment":[{"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/media?parent=14885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/categories?post=14885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.techscore.com\/blog\/wp-json\/wp\/v2\/tags?post=14885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}