{"id":476481,"date":"2023-08-09T07:29:55","date_gmt":"2023-08-09T07:29:55","guid":{"rendered":""},"modified":"2023-09-05T11:12:51","modified_gmt":"2023-09-05T11:12:51","slug":"cross-site-requested-forgery","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/jp\/wiki\/cross-site-requested-forgery\/","title":{"rendered":"\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea"},"content":{"rendered":"<p>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea (CSRF) \u306f\u3001Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u8a8d\u8a3c\u3055\u308c\u305f\u30e6\u30fc\u30b6\u30fc\u306b\u306a\u308a\u3059\u307e\u3057\u3066\u4e0d\u6b63\u306a\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u5b9f\u884c\u3067\u304d\u308b\u3001Web \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u8106\u5f31\u6027\u306e\u4e00\u7a2e\u3067\u3059\u3002CSRF \u653b\u6483\u306f\u3001Web \u30b5\u30a4\u30c8\u304c\u30e6\u30fc\u30b6\u30fc\u306e\u30d6\u30e9\u30a6\u30b6\u30fc\u306b\u5bfe\u3057\u3066\u6301\u3063\u3066\u3044\u308b\u4fe1\u983c\u3092\u60aa\u7528\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u77e5\u3089\u306a\u3044\u3046\u3061\u306b\u3001\u307e\u305f\u306f\u30e6\u30fc\u30b6\u30fc\u306e\u540c\u610f\u306a\u3057\u306b\u60aa\u610f\u306e\u3042\u308b\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u884c\u3046\u3088\u3046\u306b\u4ed5\u5411\u3051\u307e\u3059\u3002\u3053\u306e\u30bf\u30a4\u30d7\u306e\u653b\u6483\u306f\u3001Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u6574\u5408\u6027\u3068\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306b\u91cd\u5927\u306a\u8105\u5a01\u3092\u3082\u305f\u3089\u3057\u307e\u3059\u3002<\/p>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u8d77\u6e90\u3068\u305d\u306e\u6700\u521d\u306e\u8a00\u53ca\u306e\u6b74\u53f2<\/h2>\n<p>\u300c\u30af\u30ed\u30b9\u30b5\u30a4\u30c8 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u300d\u3068\u3044\u3046\u7528\u8a9e\u306f\u30012001 \u5e74\u306b\u7814\u7a76\u8005 RSnake \u3068 Amit Klein \u304c Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306b\u95a2\u3059\u308b\u8b70\u8ad6\u306e\u4e2d\u3067\u521d\u3081\u3066\u4f5c\u308a\u307e\u3057\u305f\u3002\u305f\u3060\u3057\u3001CSRF \u306e\u3088\u3046\u306a\u653b\u6483\u306e\u6982\u5ff5\u306f 1990 \u5e74\u4ee3\u534a\u3070\u304b\u3089\u77e5\u3089\u308c\u3066\u3044\u307e\u3057\u305f\u3002\u540c\u69d8\u306e\u653b\u6483\u306b\u95a2\u3059\u308b\u6700\u521d\u306e\u8a00\u53ca\u306f\u30011996 \u5e74\u306b Adam Barth \u3068\u3044\u3046\u7814\u7a76\u8005\u304c\u3001\u653b\u6483\u8005\u304c HTTP \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u507d\u9020\u3067\u304d\u308b Netscape Navigator \u30d6\u30e9\u30a6\u30b6\u306e\u8106\u5f31\u6027\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u305f\u3068\u304d\u306b\u3055\u304b\u306e\u307c\u308a\u307e\u3059\u3002<\/p>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306b\u95a2\u3059\u308b\u8a73\u7d30\u60c5\u5831<\/h2>\n<p>CSRF \u653b\u6483\u306f\u3001\u901a\u5e38\u3001\u30a2\u30ab\u30a6\u30f3\u30c8\u8a2d\u5b9a\u306e\u5909\u66f4\u3001\u8cfc\u5165\u3001\u9ad8\u3044\u6a29\u9650\u3067\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u306e\u5b9f\u884c\u306a\u3069\u3001\u72b6\u614b\u3092\u5909\u66f4\u3059\u308b\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u3068\u3057\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u7279\u5225\u306b\u7d30\u5de5\u3055\u308c\u305f URL \u307e\u305f\u306f\u30d5\u30a9\u30fc\u30e0\u3092\u542b\u3080\u60aa\u610f\u306e\u3042\u308b Web \u30b5\u30a4\u30c8\u307e\u305f\u306f\u30e1\u30fc\u30eb\u3092\u4f5c\u6210\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30d6\u30e9\u30a6\u30b6\u30fc\u3092\u30c8\u30ea\u30ac\u30fc\u3057\u3066\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u306e Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3067\u4e0d\u6b63\u306a\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u30d6\u30e9\u30a6\u30b6\u30fc\u304c\u30e6\u30fc\u30b6\u30fc\u306e\u8a8d\u8a3c\u6e08\u307f\u30bb\u30c3\u30b7\u30e7\u30f3\u8cc7\u683c\u60c5\u5831\u3092\u81ea\u52d5\u7684\u306b\u60aa\u610f\u306e\u3042\u308b\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u542b\u3081\u3001\u6b63\u5f53\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u3088\u3046\u306b\u898b\u305b\u304b\u3051\u308b\u305f\u3081\u306b\u767a\u751f\u3057\u307e\u3059\u3002<\/p>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u5185\u90e8\u69cb\u9020\u3068\u305d\u306e\u4ed5\u7d44\u307f<\/h2>\n<p>CSRF \u306e\u80cc\u5f8c\u306b\u3042\u308b\u30e1\u30ab\u30cb\u30ba\u30e0\u306b\u306f\u3001\u6b21\u306e\u624b\u9806\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<ol>\n<li>\u30e6\u30fc\u30b6\u30fc\u306f Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u30ed\u30b0\u30a4\u30f3\u3057\u3001\u901a\u5e38\u306f Cookie \u307e\u305f\u306f\u975e\u8868\u793a\u306e\u30d5\u30a9\u30fc\u30e0 \u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u8a8d\u8a3c\u30c8\u30fc\u30af\u30f3\u3092\u53d7\u3051\u53d6\u308a\u307e\u3059\u3002<\/li>\n<li>\u30e6\u30fc\u30b6\u30fc\u304c\u30ed\u30b0\u30a4\u30f3\u3057\u305f\u307e\u307e\u3001\u60aa\u610f\u306e\u3042\u308b Web \u30b5\u30a4\u30c8\u306b\u30a2\u30af\u30bb\u30b9\u3057\u305f\u308a\u3001\u60aa\u610f\u306e\u3042\u308b\u30ea\u30f3\u30af\u3092\u30af\u30ea\u30c3\u30af\u3057\u305f\u308a\u3057\u307e\u3059\u3002<\/li>\n<li>\u60aa\u610f\u306e\u3042\u308b Web \u30b5\u30a4\u30c8\u306f\u3001\u30d6\u30e9\u30a6\u30b6\u306e Cookie \u307e\u305f\u306f\u30bb\u30c3\u30b7\u30e7\u30f3 \u30c7\u30fc\u30bf\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u30e6\u30fc\u30b6\u30fc\u306e\u8cc7\u683c\u60c5\u5831\u3092\u4f7f\u7528\u3057\u3066\u3001\u7d30\u5de5\u3055\u308c\u305f HTTP \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5bfe\u8c61\u306e Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002<\/li>\n<li>\u30bf\u30fc\u30b2\u30c3\u30c8 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u53d7\u4fe1\u3057\u3001\u305d\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u30e6\u30fc\u30b6\u30fc\u306e\u6709\u52b9\u306a\u8a8d\u8a3c\u30c8\u30fc\u30af\u30f3\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u305f\u3081\u3001\u6b63\u5f53\u306a\u30e6\u30fc\u30b6\u30fc\u304b\u3089\u9001\u4fe1\u3055\u308c\u305f\u3082\u306e\u3068\u3057\u3066\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u51e6\u7406\u3057\u307e\u3059\u3002<\/li>\n<li>\u305d\u306e\u7d50\u679c\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u77e5\u3089\u306a\u3044\u3046\u3061\u306b\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u304c\u30e6\u30fc\u30b6\u30fc\u306b\u4ee3\u308f\u3063\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u4e3b\u306a\u7279\u5fb4\u306e\u5206\u6790<\/h2>\n<p>CSRF \u653b\u6483\u306e\u4e3b\u306a\u7279\u5fb4\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ol>\n<li><strong>\u76ee\u306b\u898b\u3048\u306a\u3044\u643e\u53d6<\/strong>: CSRF \u653b\u6483\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u6c17\u4ed8\u304b\u306a\u3044\u3046\u3061\u306b\u9759\u304b\u306b\u5b9f\u884c\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b\u305f\u3081\u3001\u5371\u967a\u3067\u3042\u308a\u3001\u691c\u51fa\u304c\u56f0\u96e3\u3067\u3059\u3002<\/li>\n<li><strong>\u30e6\u30fc\u30b6\u30fc\u306e\u4fe1\u983c\u3078\u306e\u4f9d\u5b58<\/strong>: CSRF \u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30d6\u30e9\u30a6\u30b6\u3068 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u9593\u306b\u78ba\u7acb\u3055\u308c\u305f\u4fe1\u983c\u3092\u60aa\u7528\u3057\u307e\u3059\u3002<\/li>\n<li><strong>\u30bb\u30c3\u30b7\u30e7\u30f3\u30d9\u30fc\u30b9<\/strong>: CSRF \u653b\u6483\u306f\u591a\u304f\u306e\u5834\u5408\u3001\u30a2\u30af\u30c6\u30a3\u30d6\u306a\u30e6\u30fc\u30b6\u30fc \u30bb\u30c3\u30b7\u30e7\u30f3\u306b\u4f9d\u5b58\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u8a8d\u8a3c\u72b6\u614b\u3092\u5229\u7528\u3057\u3066\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u507d\u9020\u3057\u307e\u3059\u3002<\/li>\n<li><strong>\u5f71\u97ff\u529b\u306e\u3042\u308b\u884c\u52d5<\/strong>: \u653b\u6483\u306f\u72b6\u614b\u3092\u5909\u66f4\u3059\u308b\u64cd\u4f5c\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u3057\u3066\u304a\u308a\u3001\u30c7\u30fc\u30bf\u306e\u5909\u66f4\u3084\u91d1\u92ad\u7684\u640d\u5931\u306a\u3069\u306e\u91cd\u5927\u306a\u7d50\u679c\u3092\u3082\u305f\u3089\u3057\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u7a2e\u985e<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u30bf\u30a4\u30d7<\/th>\n<th>\u8aac\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u30b7\u30f3\u30d7\u30eb\u306aCSRF<\/td>\n<td>\u6700\u3082\u4e00\u822c\u7684\u306a\u30bf\u30a4\u30d7\u3067\u3001\u507d\u9020\u3055\u308c\u305f\u5358\u4e00\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u304c\u5bfe\u8c61\u306e Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30d6\u30e9\u30a4\u30f3\u30c9CSRF<\/td>\n<td>\u653b\u6483\u8005\u306f\u3001\u5fdc\u7b54\u3092\u53d6\u5f97\u305b\u305a\u306b\u7d30\u5de5\u3057\u305f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u9001\u4fe1\u3057\u3001\u305d\u308c\u3092\u300c\u30d6\u30e9\u30a4\u30f3\u30c9\u300d\u306b\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>CSRF \u3068 XSS<\/td>\n<td>\u653b\u6483\u8005\u306f\u3001CSRF \u3068\u30af\u30ed\u30b9\u30b5\u30a4\u30c8 \u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0 (XSS) \u3092\u7d44\u307f\u5408\u308f\u305b\u3066\u3001\u88ab\u5bb3\u8005\u306b\u5bfe\u3057\u3066\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>JSON\u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3067\u306eCSRF<\/td>\n<td>\u653b\u6483\u8005\u306f\u3001JSON \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3092\u4f7f\u7528\u3059\u308b\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u6a19\u7684\u3068\u3057\u3001JSON \u30c7\u30fc\u30bf\u3092\u64cd\u4f5c\u3057\u3066 CSRF \u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306e\u4f7f\u7528\u65b9\u6cd5\u3001\u554f\u984c\u70b9\u3001\u89e3\u6c7a\u7b56<\/h2>\n<h3>\u60aa\u7528\u65b9\u6cd5<\/h3>\n<ol>\n<li>\u4e0d\u6b63\u306a\u30a2\u30ab\u30a6\u30f3\u30c8\u64cd\u4f5c: \u653b\u6483\u8005\u306f\u30e6\u30fc\u30b6\u30fc\u3092\u9a19\u3057\u3066\u30a2\u30ab\u30a6\u30f3\u30c8\u8a2d\u5b9a\u3084\u30d1\u30b9\u30ef\u30fc\u30c9\u3092\u5909\u66f4\u3055\u305b\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li>\u91d1\u878d\u53d6\u5f15: CSRF \u306f\u4e0d\u6b63\u306a\u8cc7\u91d1\u79fb\u52d5\u3084\u8cfc\u5165\u3092\u5bb9\u6613\u306b\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li>\u30c7\u30fc\u30bf\u64cd\u4f5c: \u653b\u6483\u8005\u306f\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u5185\u306e\u30e6\u30fc\u30b6\u30fc\u30c7\u30fc\u30bf\u3092\u5909\u66f4\u307e\u305f\u306f\u524a\u9664\u3057\u307e\u3059\u3002<\/li>\n<\/ol>\n<h3>\u89e3\u6c7a\u7b56\u3068\u4e88\u9632<\/h3>\n<ol>\n<li>CSRF \u30c8\u30fc\u30af\u30f3: \u5404\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u4e00\u610f\u306e\u30c8\u30fc\u30af\u30f3\u3092\u5b9f\u88c5\u3057\u3066\u3001\u305d\u306e\u6b63\u5f53\u6027\u3092\u691c\u8a3c\u3057\u307e\u3059\u3002<\/li>\n<li>SameSite Cookie: SameSite \u5c5e\u6027\u3092\u4f7f\u7528\u3057\u3066 Cookie \u306e\u7bc4\u56f2\u3092\u5236\u9650\u3057\u307e\u3059\u3002<\/li>\n<li>\u30ab\u30b9\u30bf\u30e0 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d8\u30c3\u30c0\u30fc: \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u691c\u8a3c\u3059\u308b\u305f\u3081\u306e\u30ab\u30b9\u30bf\u30e0 \u30d8\u30c3\u30c0\u30fc\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<\/li>\n<li>\u4e8c\u91cd\u9001\u4fe1 Cookie: \u30c8\u30fc\u30af\u30f3\u5024\u306b\u4e00\u81f4\u3059\u308b\u30bb\u30ab\u30f3\u30c0\u30ea Cookie \u3092\u542b\u3081\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u4e3b\u306a\u7279\u5fb4\u3068\u985e\u4f3c\u7528\u8a9e\u3068\u306e\u6bd4\u8f03<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u5b66\u671f<\/th>\n<th>\u8aac\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0 (XSS)<\/td>\n<td>\u4ed6\u306e\u30e6\u30fc\u30b6\u30fc\u304c\u95b2\u89a7\u3059\u308b Web \u30da\u30fc\u30b8\u306b\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u633f\u5165\u3059\u308b\u3053\u3068\u306b\u91cd\u70b9\u3092\u7f6e\u3044\u3066\u3044\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea<\/td>\n<td>\u72b6\u614b\u3092\u5909\u66f4\u3059\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u3068\u3057\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u4fe1\u983c\u3092\u5229\u7528\u3057\u3066\u4e0d\u6b63\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u30a4\u30f3\u30af\u30eb\u30fc\u30c9<\/td>\n<td>\u5916\u90e8\u30c9\u30e1\u30a4\u30f3\u304b\u3089\u306e\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u6a19\u7684\u306e Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u7d44\u307f\u8fbc\u307f\u307e\u3059\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u306b\u95a2\u3059\u308b\u4eca\u5f8c\u306e\u5c55\u671b\u3068\u6280\u8853<\/h2>\n<p>Web \u30c6\u30af\u30ce\u30ed\u30b8\u30fc\u304c\u9032\u5316\u3059\u308b\u306b\u3064\u308c\u3001CSRF \u653b\u6483\u306b\u5bfe\u6297\u3059\u308b\u305f\u3081\u306e\u65b0\u3057\u3044\u9632\u5fa1\u30e1\u30ab\u30cb\u30ba\u30e0\u304c\u767b\u5834\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u751f\u4f53\u8a8d\u8a3c\u3001\u30c8\u30fc\u30af\u30f3\u5316\u3001\u591a\u8981\u7d20\u8a8d\u8a3c\u3092\u7d71\u5408\u3059\u308b\u3053\u3068\u3067\u3001\u30e6\u30fc\u30b6\u30fc\u8a8d\u8a3c\u3092\u5f37\u5316\u3067\u304d\u307e\u3059\u3002\u3055\u3089\u306b\u3001\u30d6\u30e9\u30a6\u30b6\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5f37\u5316\u3068\u3001CSRF \u306e\u8106\u5f31\u6027\u3092\u81ea\u52d5\u7684\u306b\u691c\u51fa\u3057\u3066\u9632\u6b62\u3059\u308b\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u306f\u3001\u5c06\u6765\u306e\u8105\u5a01\u3092\u8efd\u6e1b\u3059\u308b\u4e0a\u3067\u91cd\u8981\u306a\u5f79\u5272\u3092\u679c\u305f\u3057\u307e\u3059\u3002<\/p>\n<h2>\u30d7\u30ed\u30ad\u30b7\u30b5\u30fc\u30d0\u30fc\u304c\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u3068\u3069\u306e\u3088\u3046\u306b\u95a2\u9023\u3059\u308b\u304b<\/h2>\n<p>\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u3068 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u9593\u306e\u4ef2\u4ecb\u5f79\u3068\u3057\u3066\u6a5f\u80fd\u3057\u307e\u3059\u3002CSRF \u306e\u30b3\u30f3\u30c6\u30ad\u30b9\u30c8\u3067\u306f\u3001\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u30e6\u30fc\u30b6\u30fc \u30ea\u30af\u30a8\u30b9\u30c8\u306e\u691c\u8a3c\u3092\u3055\u3089\u306b\u8907\u96d1\u306b\u3057\u3001CSRF \u306e\u8106\u5f31\u6027\u3092\u8efd\u6e1b\u307e\u305f\u306f\u60aa\u5316\u3055\u305b\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u9069\u5207\u306b\u69cb\u6210\u3055\u308c\u305f\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u53d7\u4fe1\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u304a\u3088\u3073\u691c\u8a3c\u3059\u308b\u3053\u3068\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u3055\u3089\u306b\u5f37\u5316\u3057\u3001CSRF \u653b\u6483\u306e\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3067\u304d\u307e\u3059\u3002<\/p>\n<h2>\u95a2\u9023\u30ea\u30f3\u30af<\/h2>\n<p>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u3068 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u6b21\u306e\u30ea\u30bd\u30fc\u30b9\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<ol>\n<li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html\" target=\"_new\" rel=\"noopener nofollow\">OWASP CSRF \u9632\u6b62\u30c1\u30fc\u30c8\u30b7\u30fc\u30c8<\/a><\/li>\n<li><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/CSRF\" target=\"_new\" rel=\"noopener nofollow\">Mozilla \u958b\u767a\u8005\u30cd\u30c3\u30c8\u30ef\u30fc\u30af \u2013 \u30af\u30ed\u30b9\u30b5\u30a4\u30c8 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea (CSRF)<\/a><\/li>\n<li><a href=\"https:\/\/portswigger.net\/web-security\/csrf\" target=\"_new\" rel=\"noopener nofollow\">PortSwigger \u2013 \u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea (CSRF)<\/a><\/li>\n<li><a href=\"https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet\" target=\"_new\" rel=\"noopener nofollow\">\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30ea\u30af\u30a8\u30b9\u30c8\u30d5\u30a9\u30fc\u30b8\u30a7\u30ea\u30d0\u30a4\u30d6\u30eb<\/a><\/li>\n<\/ol>","protected":false},"featured_media":476482,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-476481","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Cross-Site Request Forgery (CSRF) - A Comprehensive Guide<\/mark>","faq_items":[{"question":"What is Cross-Site Request Forgery (CSRF)?","answer":"<p>Cross-Site Request Forgery (CSRF) is a type of web security vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users without their knowledge. It exploits the trust between a user's browser and a web application to trick the application into accepting malicious requests.<\/p>"},{"question":"How did CSRF originate, and when was it first mentioned?","answer":"<p>The term \"Cross-Site Request Forgery\" was coined in 2001, but the concept of similar attacks was known since the mid-1990s. Researchers first mentioned a vulnerability in the Netscape Navigator browser that allowed attackers to forge HTTP requests back in 1996.<\/p>"},{"question":"How does CSRF work?","answer":"<p>CSRF attacks involve the following steps:<\/p><ol><li>The user logs into a web application and receives an authentication token.<\/li><li>While the user is still logged in, they visit a malicious website or click on a malicious link.<\/li><li>The malicious website sends a crafted HTTP request to the target application using the user's credentials.<\/li><li>The target application processes the request as if it came from the legitimate user, performing the malicious action.<\/li><\/ol>"},{"question":"What are the key features of CSRF attacks?","answer":"<p>Key features of CSRF attacks include:<\/p><ol><li>Invisible Exploitation: CSRF attacks occur without the user's awareness.<\/li><li>Reliance on User Trust: The attacks rely on the trust between the user's browser and the application.<\/li><li>Session-Based: CSRF attacks depend on active user sessions.<\/li><li>Impactful Actions: The attacks target state-changing operations with significant consequences.<\/li><\/ol>"},{"question":"What types of CSRF attacks exist?","answer":"<p>There are several types of CSRF attacks, including:<\/p><ol><li>Simple CSRF: A single forged request is sent to the target application.<\/li><li>Blind CSRF: The attacker sends a crafted request without obtaining the response.<\/li><li>CSRF with XSS: Attackers combine CSRF with Cross-Site Scripting to execute malicious scripts.<\/li><li>CSRF with JSON endpoints: Targeting applications using JSON endpoints, attackers manipulate JSON data for CSRF.<\/li><\/ol>"},{"question":"How can CSRF be prevented and mitigated?","answer":"<p>Preventing and mitigating CSRF attacks involve implementing various techniques, such as:<\/p><ol><li>CSRF Tokens: Use unique tokens in each request to validate its legitimacy.<\/li><li>SameSite Cookies: Utilize SameSite attributes in cookies to restrict their scope.<\/li><li>Custom Request Headers: Add custom headers to validate requests.<\/li><li>Double Submit Cookies: Include a secondary cookie that matches the token value.<\/li><\/ol>"},{"question":"How does CSRF compare to other web vulnerabilities?","answer":"<p>CSRF differs from other web vulnerabilities like Cross-Site Scripting (XSS) and Cross-Site Script Inclusion (XSSI). While XSS focuses on injecting malicious scripts into web pages, CSRF targets state-changing actions by exploiting user trust.<\/p>"},{"question":"What does the future hold for CSRF defense?","answer":"<p>As web technologies evolve, new defense mechanisms, including biometrics, tokenization, and multi-factor authentication, will emerge to counter CSRF attacks. Browser security enhancements and frameworks detecting and preventing CSRF vulnerabilities will play vital roles in mitigating future threats.<\/p>"},{"question":"How are proxy servers associated with CSRF?","answer":"<p>Proxy servers act as intermediaries between users and web applications. In the context of CSRF, they can add an extra layer of security by filtering and validating incoming requests, reducing the risk of CSRF attacks. Properly configured proxy servers can enhance web application security.<\/p>"},{"question":"Where can I find more information about CSRF?","answer":"<p>For more in-depth knowledge about CSRF and web application security, refer to the following resources:<\/p><ol><li><a href=\"https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html\" target=\"_new\">OWASP CSRF Prevention Cheat Sheet<\/a><\/li><li><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/CSRF\" target=\"_new\">Mozilla Developer Network - Cross-Site Request Forgery (CSRF)<\/a><\/li><li><a href=\"https:\/\/portswigger.net\/web-security\/csrf\" target=\"_new\">PortSwigger - Cross-Site Request Forgery (CSRF)<\/a><\/li><li><a href=\"https:\/\/www.owasp.org\/index.php\/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet\" target=\"_new\">The Cross-Site Request Forgery Bible<\/a><\/li><\/ol>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki\/476481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki\/476481\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/media\/476482"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/media?parent=476481"}],"curies":[{"name":"\u3046\u30fc\u3093","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}