{"id":477282,"date":"2023-08-09T09:10:23","date_gmt":"2023-08-09T09:10:23","guid":{"rendered":""},"modified":"2023-11-29T15:03:54","modified_gmt":"2023-11-29T15:03:54","slug":"format-string-attack","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/jp\/wiki\/format-string-attack\/","title":{"rendered":"\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483"},"content":{"rendered":"<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u3001\u30b3\u30f3\u30d4\u30e5\u30fc\u30bf \u30d7\u30ed\u30b0\u30e9\u30df\u30f3\u30b0\u3067\u767a\u751f\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8106\u5f31\u6027\u306e\u4e00\u7a2e\u3067\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u304c\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3055\u308c\u305f\u5165\u51fa\u529b\u95a2\u6570\u3092\u51e6\u7406\u3059\u308b\u65b9\u6cd5\u3092\u60aa\u7528\u3067\u304d\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3053\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u3066\u3001\u6a5f\u5bc6\u30c7\u30fc\u30bf\u3092\u8aad\u307f\u53d6\u3063\u305f\u308a\u3001\u30e1\u30e2\u30ea\u306e\u5185\u5bb9\u3092\u5909\u66f4\u3057\u305f\u308a\u3001\u30bf\u30fc\u30b2\u30c3\u30c8 \u30b7\u30b9\u30c6\u30e0\u3067\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3057\u305f\u308a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u306e\u6574\u5408\u6027\u3068\u6a5f\u5bc6\u6027\u3092\u5371\u967a\u306b\u3055\u3089\u3059\u53ef\u80fd\u6027\u304c\u3042\u308b\u305f\u3081\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u8005\u3084\u30b7\u30b9\u30c6\u30e0\u7ba1\u7406\u8005\u306b\u3068\u3063\u3066\u5927\u304d\u306a\u61f8\u5ff5\u4e8b\u9805\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u8d77\u6e90\u3068\u305d\u306e\u6700\u521d\u306e\u8a00\u53ca\u306e\u6b74\u53f2<\/h2>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u3068\u3044\u3046\u6982\u5ff5\u304c\u521d\u3081\u3066\u660e\u3089\u304b\u306b\u306a\u3063\u305f\u306e\u306f\u30011990 \u5e74\u4ee3\u5f8c\u534a\u3067\u3059\u3002\u3053\u306e\u6982\u5ff5\u306f\u30012000 \u5e74\u306b Kostya Kortchinsky \u304c\u767a\u8868\u3057\u305f\u300c\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u306e\u60aa\u7528\u300d\u3068\u3044\u3046\u8ad6\u6587\u306b\u3088\u3063\u3066\u5e83\u304f\u77e5\u3089\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u8ad6\u6587\u3067\u306f\u3001\u3053\u306e\u8106\u5f31\u6027\u306e\u60aa\u7528\u306b\u3064\u3044\u3066\u8a73\u7d30\u306b\u8aac\u660e\u3057\u3001\u30b7\u30b9\u30c6\u30e0\u3078\u306e\u6f5c\u5728\u7684\u306a\u5f71\u97ff\u3092\u793a\u3057\u307e\u3057\u305f\u3002\u305d\u308c\u4ee5\u6765\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u5e83\u304f\u7814\u7a76\u3055\u308c\u3001\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u306b\u304a\u3051\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u306e\u7406\u89e3\u304c\u6df1\u307e\u308a\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3082\u6539\u5584\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<h2>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306b\u95a2\u3059\u308b\u8a73\u7d30\u60c5\u5831<\/h2>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u3001\u653b\u6483\u8005\u304c\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3055\u308c\u305f\u5165\u51fa\u529b\u95a2\u6570\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u5236\u5fa1\u3067\u304d\u308b\u5834\u5408\u306b\u767a\u751f\u3057\u307e\u3059\u3002 <code data-no-translation=\"\">printf()<\/code> \u305d\u3057\u3066 <code data-no-translation=\"\">sprintf()<\/code>\u306f\u3001\u30c7\u30fc\u30bf\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3084\u5370\u5237\u306b\u5e83\u304f\u4f7f\u7528\u3055\u308c\u3066\u3044\u307e\u3059\u3002C\u3084C++\u306a\u3069\u306e\u8a00\u8a9e\u3067\u306f\u3001\u958b\u767a\u8005\u304c\u30d7\u30ec\u30fc\u30b9\u30db\u30eb\u30c0\u30fc\uff08\u4f8b\uff1a <code data-no-translation=\"\">%s<\/code> \u6587\u5b57\u5217\u306e\u5834\u5408\u3001 <code data-no-translation=\"\">%d<\/code> \u8868\u793a\u3055\u308c\u308b\u6587\u5b57\u5217\uff08\u6574\u6570\u306a\u3069\uff09\u3068\u305d\u308c\u306b\u5bfe\u5fdc\u3059\u308b\u5024\u304c\u6b63\u3057\u304f\u306a\u3044\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u8106\u5f31\u6027\u306f\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u304c\u9069\u5207\u306a\u691c\u8a3c\u3092\u884c\u308f\u305a\u306b\u30e6\u30fc\u30b6\u30fc\u304c\u5236\u5fa1\u3059\u308b\u30c7\u30fc\u30bf\u3092\u66f8\u5f0f\u6587\u5b57\u5217\u3068\u3057\u3066\u6e21\u3059\u5834\u5408\u306b\u767a\u751f\u3057\u3001\u610f\u56f3\u3057\u306a\u3044\u7d50\u679c\u306b\u3064\u306a\u304c\u308a\u307e\u3059\u3002<\/p>\n<h2>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u5185\u90e8\u69cb\u9020\u3068\u305d\u306e\u4ed5\u7d44\u307f<\/h2>\n<p>\u66f8\u5f0f\u6587\u5b57\u5217\u653b\u6483\u306e\u4ed5\u7d44\u307f\u3092\u7406\u89e3\u3059\u308b\u306b\u306f\u3001\u66f8\u5f0f\u4ed8\u304d\u5165\u51fa\u529b\u95a2\u6570\u306e\u5185\u90e8\u52d5\u4f5c\u3092\u628a\u63e1\u3059\u308b\u3053\u3068\u304c\u4e0d\u53ef\u6b20\u3067\u3059\u3002C\u306a\u3069\u306e\u8a00\u8a9e\u3067\u306f\u3001\u66f8\u5f0f\u4ed8\u304d\u5370\u5237\u95a2\u6570\u306f\u30b9\u30bf\u30c3\u30af\u3092\u4f7f\u7528\u3057\u3066\u6e21\u3055\u308c\u305f\u5f15\u6570\u306b\u30a2\u30af\u30bb\u30b9\u3057\u307e\u3059\u3002\u958b\u767a\u8005\u304c\u66f8\u5f0f\u6587\u5b57\u5217\u3092\u63d0\u4f9b\u3059\u308b\u3068\u3001\u95a2\u6570\u306f\u305d\u308c\u3092\u53cd\u5fa9\u51e6\u7406\u3057\u3066\u66f8\u5f0f\u6307\u5b9a\u5b50\u3092\u63a2\u3057\u307e\u3059\uff08\u4f8b\uff1a <code data-no-translation=\"\">%s<\/code>, <code data-no-translation=\"\">%d<\/code>)\u3002\u898b\u3064\u304b\u3063\u305f\u6307\u5b9a\u5b50\u3054\u3068\u306b\u3001\u95a2\u6570\u306f\u30b9\u30bf\u30c3\u30af\u4e0a\u306b\u5bfe\u5fdc\u3059\u308b\u5f15\u6570\u3092\u671f\u5f85\u3057\u307e\u3059\u3002<\/p>\n<p>\u8106\u5f31\u306a\u30d7\u30ed\u30b0\u30e9\u30e0\u3067\u306f\u3001\u653b\u6483\u8005\u304c\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u3092\u5236\u5fa1\u3067\u304d\u308b\u5834\u5408\u3001\u6b21\u306e\u3053\u3068\u3092\u60aa\u7528\u3057\u3066\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30e1\u30e2\u30ea\u3092\u64cd\u4f5c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<ol>\n<li><strong>\u8aad\u66f8\u8a18\u61b6<\/strong>: \u6b21\u306e\u3088\u3046\u306a\u66f8\u5f0f\u6307\u5b9a\u5b50\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u3067 <code data-no-translation=\"\">%x<\/code> \u307e\u305f\u306f <code data-no-translation=\"\">%s<\/code>\u653b\u6483\u8005\u306f\u3001\u6a5f\u5bc6\u60c5\u5831\u304c\u542b\u307e\u308c\u3066\u3044\u308b\u53ef\u80fd\u6027\u306e\u3042\u308b\u30b9\u30bf\u30c3\u30af\u3084\u305d\u306e\u4ed6\u306e\u30e1\u30e2\u30ea\u9818\u57df\u306e\u5185\u5bb9\u3092\u6f0f\u6d29\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li><strong>\u30e1\u30e2\u30ea\u306e\u66f8\u304d\u8fbc\u307f<\/strong>: \u66f8\u5f0f\u6307\u5b9a\u5b50 <code data-no-translation=\"\">%n<\/code> \u653b\u6483\u8005\u306f\u3001\u5bfe\u5fdc\u3059\u308b\u5f15\u6570\u304c\u6307\u3059\u30e1\u30e2\u30ea \u30a2\u30c9\u30ec\u30b9\u306b\u30c7\u30fc\u30bf\u3092\u66f8\u304d\u8fbc\u3080\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u5909\u6570\u3001\u95a2\u6570\u30dd\u30a4\u30f3\u30bf\u3001\u3055\u3089\u306b\u306f\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30b3\u30fc\u30c9\u3092\u5909\u66f4\u3059\u308b\u305f\u3081\u306b\u60aa\u7528\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li><strong>\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u306e\u5b9f\u884c<\/strong>: \u653b\u6483\u8005\u304c\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u3092\u5236\u5fa1\u3057\u3001\u9069\u5207\u306a\u5f15\u6570\u3092\u4e0e\u3048\u308b\u3053\u3068\u304c\u3067\u304d\u308c\u3070\u3001\u653b\u6483\u8005\u306f\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002 <code data-no-translation=\"\">%n<\/code> \u95a2\u6570\u30dd\u30a4\u30f3\u30bf\u306b\u66f8\u304d\u8fbc\u307f\u3001\u305d\u306e\u5b9f\u884c\u3092\u30c8\u30ea\u30ac\u30fc\u3057\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u4e3b\u306a\u7279\u5fb4\u306e\u5206\u6790<\/h2>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u4e3b\u306a\u7279\u5fb4\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ol>\n<li><strong>\u66f8\u5f0f\u6587\u5b57\u5217\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb<\/strong>: \u653b\u6483\u8005\u306f\u51fa\u529b\u5f62\u5f0f\u3092\u6c7a\u5b9a\u3059\u308b\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u3092\u5236\u5fa1\u3057\u3001\u30e1\u30e2\u30ea\u30a2\u30af\u30bb\u30b9\u3092\u64cd\u4f5c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/li>\n<li><strong>\u30b9\u30bf\u30c3\u30af\u30d9\u30fc\u30b9\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/strong>: \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u901a\u5e38\u3001\u30b9\u30bf\u30c3\u30af\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u306b\u3057\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u3055\u308c\u305f\u5165\u51fa\u529b\u95a2\u6570\u304c\u30b9\u30bf\u30c3\u30af\u3092\u4f7f\u7528\u3057\u3066\u5f15\u6570\u306b\u30a2\u30af\u30bb\u30b9\u3059\u308b\u305f\u3081\u3067\u3059\u3002<\/li>\n<li><strong>\u30e1\u30e2\u30ea\u64cd\u4f5c<\/strong>: \u653b\u6483\u8005\u306f\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6307\u5b9a\u5b50\u3092\u4ecb\u3057\u3066\u30e1\u30e2\u30ea \u30a2\u30c9\u30ec\u30b9\u3092\u8aad\u307f\u66f8\u304d\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u3001\u60c5\u5831\u6f0f\u6d29\u3084\u30b3\u30fc\u30c9\u5b9f\u884c\u306b\u3064\u306a\u304c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u66f8\u5f0f\u6587\u5b57\u5217\u653b\u6483\u306e\u7a2e\u985e<\/h2>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u3001\u4e3b\u306b\u6b21\u306e 2 \u3064\u306e\u30bf\u30a4\u30d7\u306b\u5206\u985e\u3067\u304d\u307e\u3059\u3002<\/p>\n<ol>\n<li><strong>\u8aad\u66f8\u653b\u6483<\/strong>\u3053\u308c\u3089\u306e\u653b\u6483\u306f\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6307\u5b9a\u5b50\u3092\u60aa\u7528\u3057\u3066\u3001\u30b9\u30bf\u30c3\u30af \u30a2\u30c9\u30ec\u30b9\u3084\u30d1\u30b9\u30ef\u30fc\u30c9 \u30c7\u30fc\u30bf\u306a\u3069\u306e\u6a5f\u5bc6\u60c5\u5831\u3092\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30e1\u30e2\u30ea\u304b\u3089\u8aad\u307f\u53d6\u308b\u3053\u3068\u306b\u91cd\u70b9\u304c\u7f6e\u304b\u308c\u3066\u3044\u307e\u3059\u3002<\/li>\n<li><strong>\u30e9\u30a4\u30c6\u30a3\u30f3\u30b0\u653b\u6483<\/strong>\u3053\u308c\u3089\u306e\u653b\u6483\u306e\u76ee\u7684\u306f\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6307\u5b9a\u5b50\u3092\u4f7f\u7528\u3057\u3066\u7279\u5b9a\u306e\u30e1\u30e2\u30ea \u30a2\u30c9\u30ec\u30b9\u306b\u30c7\u30fc\u30bf\u3092\u66f8\u304d\u8fbc\u3080\u3053\u3068\u3067\u30e1\u30e2\u30ea\u3092\u64cd\u4f5c\u3057\u3001\u653b\u6483\u8005\u304c\u5909\u6570\u307e\u305f\u306f\u95a2\u6570\u30dd\u30a4\u30f3\u30bf\u3092\u5909\u66f4\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308b\u3053\u3068\u3067\u3059\u3002<\/li>\n<\/ol>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u7a2e\u985e\u3092\u307e\u3068\u3081\u305f\u8868\u3092\u4ee5\u4e0b\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u653b\u6483\u306e\u7a2e\u985e<\/th>\n<th>\u8aac\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u8aad\u66f8\u653b\u6483<\/td>\n<td>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6307\u5b9a\u5b50\u3092\u5229\u7528\u3057\u3066\u30e1\u30e2\u30ea\u3092\u8aad\u307f\u53d6\u308b<\/td>\n<\/tr>\n<tr>\n<td>\u30e9\u30a4\u30c6\u30a3\u30f3\u30b0\u653b\u6483<\/td>\n<td>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6307\u5b9a\u5b50\u3092\u5229\u7528\u3057\u3066\u30e1\u30e2\u30ea\u306b\u66f8\u304d\u8fbc\u3080<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>\u66f8\u5f0f\u6587\u5b57\u5217\u653b\u6483\u306e\u4f7f\u7528\u65b9\u6cd5\u3001\u554f\u984c\u70b9\u3001\u89e3\u6c7a\u7b56<\/h2>\n<h3>\u66f8\u5f0f\u6587\u5b57\u5217\u653b\u6483\u306e\u4f7f\u7528\u65b9\u6cd5<\/h3>\n<p>\u653b\u6483\u8005\u306f\u3001\u6b21\u306e\u3088\u3046\u306a\u3055\u307e\u3056\u307e\u306a\u30b7\u30ca\u30ea\u30aa\u3067\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ol>\n<li><strong>\u30a6\u30a7\u30d6\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3<\/strong>: Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u9069\u5207\u306a\u691c\u8a3c\u3092\u884c\u308f\u305a\u306b\u30e6\u30fc\u30b6\u30fc\u63d0\u4f9b\u306e\u30c7\u30fc\u30bf\u3092\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u3068\u3057\u3066\u4f7f\u7528\u3059\u308b\u3068\u3001\u653b\u6483\u8005\u304c\u3053\u308c\u3092\u60aa\u7528\u3057\u3066\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u307e\u305f\u306f\u57fa\u76e4\u3068\u306a\u308b\u30b5\u30fc\u30d0\u30fc\u3092\u4fb5\u5bb3\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li><strong>\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u30a4\u30f3\u30bf\u30fc\u30d5\u30a7\u30fc\u30b9<\/strong>: \u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u5f15\u6570\u3092\u4f7f\u7528\u3057\u3066\u66f8\u5f0f\u6587\u5b57\u5217\u3092\u69cb\u7bc9\u3059\u308b\u30d7\u30ed\u30b0\u30e9\u30e0\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u5165\u529b\u3092\u691c\u8a3c\u3057\u306a\u3044\u3068\u653b\u6483\u3092\u53d7\u3051\u3084\u3059\u304f\u306a\u308a\u307e\u3059\u3002<\/li>\n<li><strong>\u30ed\u30b0\u8a18\u9332\u30e1\u30ab\u30cb\u30ba\u30e0<\/strong>: \u30ed\u30b0\u8a18\u9332\u30e1\u30ab\u30cb\u30ba\u30e0\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u653b\u6483\u8005\u306b\u30b7\u30b9\u30c6\u30e0\u306b\u95a2\u3059\u308b\u8cb4\u91cd\u306a\u60c5\u5831\u304c\u63d0\u4f9b\u3055\u308c\u3001\u3055\u3089\u306a\u308b\u653b\u6483\u304c\u5bb9\u6613\u306b\u306a\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<\/ol>\n<h3>\u554f\u984c\u3068\u89e3\u6c7a\u7b56<\/h3>\n<ol>\n<li><strong>\u4e0d\u5341\u5206\u306a\u5165\u529b\u691c\u8a3c<\/strong>: \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u306e\u4e3b\u306a\u539f\u56e0\u306f\u3001\u4e0d\u9069\u5207\u306a\u5165\u529b\u691c\u8a3c\u3067\u3059\u3002\u958b\u767a\u8005\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u5236\u5fa1\u3059\u308b\u5165\u529b\u3092\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u3068\u3057\u3066\u4f7f\u7528\u3059\u308b\u524d\u306b\u691c\u8a3c\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li><strong>\u66f8\u5f0f\u6587\u5b57\u5217\u306e\u9650\u5b9a\u7684\u306a\u4f7f\u7528<\/strong>: \u958b\u767a\u8005\u306f\u3001\u53ef\u80fd\u306a\u9650\u308a\u3001\u30e6\u30fc\u30b6\u30fc\u304c\u5236\u5fa1\u3059\u308b\u30c7\u30fc\u30bf\u3067\u66f8\u5f0f\u6587\u5b57\u5217\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u306f\u907f\u3051\u3066\u304f\u3060\u3055\u3044\u3002\u4ee3\u308f\u308a\u306b\u3001\u6587\u5b57\u5217\u306e\u9023\u7d50\u3084\u53b3\u5bc6\u306a\u5165\u529b\u30c1\u30a7\u30c3\u30af\u3092\u5099\u3048\u305f\u66f8\u5f0f\u8a2d\u5b9a\u30e9\u30a4\u30d6\u30e9\u30ea\u306a\u3069\u306e\u3088\u308a\u5b89\u5168\u306a\u4ee3\u66ff\u624b\u6bb5\u306e\u4f7f\u7528\u3092\u691c\u8a0e\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/li>\n<li><strong>\u30b3\u30f3\u30d1\u30a4\u30e9\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6a5f\u80fd<\/strong>: \u73fe\u4ee3\u306e\u30b3\u30f3\u30d1\u30a4\u30e9\u306f\u3001\u6b21\u306e\u3088\u3046\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30e1\u30ab\u30cb\u30ba\u30e0\u3092\u63d0\u4f9b\u3057\u3066\u3044\u307e\u3059\u3002 <code data-no-translation=\"\">-fstack-protector<\/code> GCC \u306b\u306f\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u3092\u691c\u51fa\u3057\u3066\u9632\u6b62\u3059\u308b\u30aa\u30d7\u30b7\u30e7\u30f3\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u3088\u3046\u306a\u6a5f\u80fd\u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3067\u304d\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u4e3b\u306a\u7279\u5fb4\u3068\u985e\u4f3c\u7528\u8a9e\u3068\u306e\u6bd4\u8f03<\/h2>\n<table>\n<thead>\n<tr>\n<th>\u5b66\u671f<\/th>\n<th>\u8aac\u660e<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u66f8\u5f0f\u6587\u5b57\u5217\u653b\u6483<\/td>\n<td>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6307\u5b9a\u5b50\u3092\u5229\u7528\u3057\u3066\u30e1\u30e2\u30ea\u3092\u64cd\u4f5c\u3059\u308b<\/td>\n<\/tr>\n<tr>\n<td>\u30d0\u30c3\u30d5\u30a1\u30aa\u30fc\u30d0\u30fc\u30d5\u30ed\u30fc<\/td>\n<td>\u30d0\u30c3\u30d5\u30a1\u306e\u5883\u754c\u3092\u8d85\u3048\u3066\u30c7\u30fc\u30bf\u3092\u66f8\u304d\u8fbc\u3080<\/td>\n<\/tr>\n<tr>\n<td>SQL\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3<\/td>\n<td>\u60aa\u610f\u306e\u3042\u308b\u5165\u529b\u306b\u3088\u308bSQL\u30af\u30a8\u30ea\u306e\u60aa\u7528<\/td>\n<\/tr>\n<tr>\n<td>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0<\/td>\n<td>\u30a6\u30a7\u30d6\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u633f\u5165\u3059\u308b<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u3068\u4ed6\u306e\u8106\u5f31\u6027\u306b\u306f\u3044\u304f\u3064\u304b\u306e\u985e\u4f3c\u70b9\u304c\u3042\u308a\u307e\u3059\u304c\u3001\u305d\u306e\u60aa\u7528\u65b9\u6cd5\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u3001\u7d50\u679c\u306f\u5927\u304d\u304f\u7570\u306a\u308a\u307e\u3059\u3002<\/p>\n<h2>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306b\u95a2\u3059\u308b\u5c55\u671b\u3068\u5c06\u6765\u306e\u6280\u8853<\/h2>\n<p>\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u958b\u767a\u624b\u6cd5\u304c\u9032\u6b69\u3059\u308b\u306b\u3064\u308c\u3001\u958b\u767a\u8005\u306f\u66f8\u5f0f\u6587\u5b57\u5217\u653b\u6483\u306a\u3069\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u8a8d\u8b58\u3092\u6df1\u3081\u3066\u3044\u307e\u3059\u3002\u5b89\u5168\u306a\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u6a19\u6e96\u3001\u81ea\u52d5\u30b3\u30fc\u30c9\u5206\u6790\u30c4\u30fc\u30eb\u3001\u5b9a\u671f\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u76e3\u67fb\u306e\u5c0e\u5165\u306b\u3088\u308a\u3001\u3053\u306e\u3088\u3046\u306a\u8106\u5f31\u6027\u306e\u6570\u306f\u6642\u9593\u306e\u7d4c\u904e\u3068\u3068\u3082\u306b\u6e1b\u5c11\u3059\u308b\u3068\u4e88\u60f3\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u3055\u3089\u306b\u3001Rust \u306e\u3088\u3046\u306a\u30e1\u30e2\u30ea\u5b89\u5168\u6a5f\u80fd\u304c\u7d44\u307f\u8fbc\u307e\u308c\u305f\u30d7\u30ed\u30b0\u30e9\u30df\u30f3\u30b0\u8a00\u8a9e\u306e\u958b\u767a\u306b\u3088\u308a\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306b\u5bfe\u3059\u308b\u8ffd\u52a0\u306e\u4fdd\u8b77\u5c64\u3092\u63d0\u4f9b\u3067\u304d\u307e\u3059\u3002<\/p>\n<h2>\u30d7\u30ed\u30ad\u30b7\u30b5\u30fc\u30d0\u30fc\u304c\u3069\u306e\u3088\u3046\u306b\u4f7f\u7528\u3055\u308c\u308b\u304b\u3001\u307e\u305f\u306f\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u3068\u3069\u306e\u3088\u3046\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u308b\u304b<\/h2>\n<p>OneProxy \u304c\u63d0\u4f9b\u3059\u308b\u3088\u3046\u306a\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u3092\u8efd\u6e1b\u3059\u308b\u5f79\u5272\u3092\u679c\u305f\u3057\u307e\u3059\u3002\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068\u30bf\u30fc\u30b2\u30c3\u30c8 \u30b5\u30fc\u30d0\u30fc\u306e\u9593\u306e\u4ef2\u4ecb\u5f79\u3068\u3057\u3066\u6a5f\u80fd\u3057\u3001\u53d7\u4fe1\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u691c\u67fb\u3057\u3066\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc \u30ec\u30d9\u30eb\u3067\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u5b9f\u88c5\u3059\u308b\u3053\u3068\u3067\u3001\u6f5c\u5728\u7684\u306a\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u3092\u30bf\u30fc\u30b2\u30c3\u30c8 \u30b5\u30fc\u30d0\u30fc\u306b\u5230\u9054\u3059\u308b\u524d\u306b\u508d\u53d7\u3057\u3066\u30d6\u30ed\u30c3\u30af\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u6b21\u306e\u3088\u3046\u306b\u69cb\u6210\u3067\u304d\u307e\u3059\u3002<\/p>\n<ol>\n<li><strong>\u30e6\u30fc\u30b6\u30fc\u5165\u529b\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/strong>: \u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u5165\u529b\u3092\u30bf\u30fc\u30b2\u30c3\u30c8 \u30b5\u30fc\u30d0\u30fc\u306b\u8ee2\u9001\u3059\u308b\u524d\u306b\u691c\u8a3c\u3057\u3001\u60aa\u610f\u306e\u3042\u308b\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u304c\u8106\u5f31\u306a\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u5230\u9054\u3059\u308b\u306e\u3092\u9632\u304e\u307e\u3059\u3002<\/li>\n<li><strong>\u30a6\u30a7\u30d6\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb<\/strong>: \u9ad8\u5ea6\u306a\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306b\u306f\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u306b\u5bfe\u3059\u308b\u4fdd\u8b77\u6a5f\u80fd\u3092\u542b\u3080 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb (WAF) \u6a5f\u80fd\u3092\u7d44\u307f\u8fbc\u3080\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/li>\n<li><strong>\u30ed\u30ae\u30f3\u30b0\u3068\u30e2\u30cb\u30bf\u30ea\u30f3\u30b0<\/strong>: \u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u53d7\u4fe1\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30ed\u30b0\u306b\u8a18\u9332\u3057\u3066\u76e3\u8996\u3057\u3001\u6f5c\u5728\u7684\u306a\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u8a66\u307f\u3092\u691c\u51fa\u3057\u3066\u5206\u6790\u3059\u308b\u306e\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/li>\n<\/ol>\n<h2>\u95a2\u9023\u30ea\u30f3\u30af<\/h2>\n<p>\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u6b21\u306e\u30ea\u30bd\u30fc\u30b9\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<ol>\n<li><a href=\"https:\/\/www.owasp.org\/images\/2\/26\/OWASPAppSecDC2006-MitjaK.pdf\" target=\"_new\" rel=\"noopener nofollow\">\u66f8\u5f0f\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3059\u308b<\/a> \u2013 OWASP AppSec DC 2006 \u3067\u306e Mitja Kolsek \u3068 Kostya Kortchinsky \u306b\u3088\u308b\u30d7\u30ec\u30bc\u30f3\u30c6\u30fc\u30b7\u30e7\u30f3\u3002<\/li>\n<li><a href=\"https:\/\/crypto.stanford.edu\/cs155\/papers\/formatstring-1.2.pdf\" target=\"_new\" rel=\"noopener nofollow\">\u66f8\u5f0f\u6587\u5b57\u5217\u306e\u30d0\u30b0 \u2013 \u521d\u898b<\/a> \u2013 \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u3092\u8a73\u7d30\u306b\u8abf\u67fb\u3057\u305f Aleph One \u306e\u8ad6\u6587\u3002<\/li>\n<li><a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_new\" rel=\"noopener nofollow\">OWASP \u30c8\u30c3\u30d7 10<\/a> \u2013 \u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u306e\u8106\u5f31\u6027\u3092\u542b\u3080\u3001OWASP \u306e Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30ea\u30b9\u30af\u306e\u30c8\u30c3\u30d7 10 \u30ea\u30b9\u30c8\u3002<\/li>\n<\/ol>\n<p>\u7d50\u8ad6\u3068\u3057\u3066\u3001\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u6587\u5b57\u5217\u653b\u6483\u306f\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2 \u30b7\u30b9\u30c6\u30e0\u306b\u91cd\u5927\u306a\u30ea\u30b9\u30af\u3092\u3082\u305f\u3089\u3057\u307e\u3059\u304c\u3001\u5b89\u5168\u306a\u30b3\u30fc\u30c7\u30a3\u30f3\u30b0\u624b\u6cd5\u3092\u63a1\u7528\u3057\u3001\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306e\u6a5f\u80fd\u3092\u6d3b\u7528\u3059\u308b\u3053\u3068\u3067\u3001\u958b\u767a\u8005\u306f\u3053\u308c\u3089\u306e\u8105\u5a01\u304b\u3089\u9632\u5fa1\u3057\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3068\u30c7\u30fc\u30bf\u306e\u6574\u5408\u6027\u3068\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u78ba\u4fdd\u3067\u304d\u307e\u3059\u3002<\/p>","protected":false},"featured_media":497608,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-477282","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>Format String Attack: Understanding the Vulnerability Exploited by Hackers<\/mark>","faq_items":[{"question":"What is a Format String Attack?","answer":"A Format String Attack is a type of security vulnerability that occurs in computer programming. It allows attackers to exploit the way a program handles formatted input\/output functions, potentially leading to unauthorized access, data leaks, or even code execution on the target system."},{"question":"How did Format String Attacks originate?","answer":"The concept of Format String Attacks was first highlighted in a 2000 paper titled \"Exploiting Format String Vulnerabilities\" by Kostya Kortchinsky. Since then, these attacks have been a significant concern in software development due to their potential to compromise system integrity and confidentiality."},{"question":"How does a Format String Attack work?","answer":"In a Format String Attack, the attacker manipulates the format string parameter in formatted input\/output functions, such as <code>printf()<\/code> and <code>sprintf()<\/code>. By controlling the format string, the attacker can read sensitive data, write to memory addresses, or even execute arbitrary code by exploiting certain format specifiers."},{"question":"What are the key features of a Format String Attack?","answer":"The key features of a Format String Attack include the attacker's ability to control the format string, exploit stack-based memory access, and manipulate memory contents through format specifiers."},{"question":"What types of Format String Attacks exist?","answer":"Format String Attacks can be classified into two main types:\r\n<ol>\r\n \t<li>Reading Attacks: Exploiting format specifiers to read sensitive data from the program's memory.<\/li>\r\n \t<li>Writing Attacks: Exploiting format specifiers to write data to specific memory addresses, enabling the modification of variables or function pointers.<\/li>\r\n<\/ol>"},{"question":"How can Format String Attacks be prevented?","answer":"To prevent Format String Attacks, developers should:\r\n<ul>\r\n \t<li>Validate user-controlled input before using it as a format string.<\/li>\r\n \t<li>Avoid using format strings with user-controlled data whenever possible.<\/li>\r\n \t<li>Utilize compiler security features like <code>-fstack-protector<\/code> to detect and prevent vulnerabilities.<\/li>\r\n<\/ul>"},{"question":"How can proxy servers like OneProxy help with Format String Attacks?","answer":"Proxy servers like OneProxy can aid in mitigating Format String Attacks by:\r\n<ul>\r\n \t<li>Filtering user input before forwarding it to the target server.<\/li>\r\n \t<li>Implementing Web Application Firewall (WAF) functionality to protect against format string vulnerabilities.<\/li>\r\n \t<li>Logging and monitoring incoming requests to detect and analyze potential attack attempts.<\/li>\r\n<\/ul>"},{"question":"Are there any other vulnerabilities similar to Format String Attacks?","answer":"While Format String Attacks are unique, there are other vulnerabilities in the realm of cybersecurity, such as Buffer Overflow, SQL Injection, and Cross-Site Scripting, each with distinct exploitation methods and consequences."},{"question":"How can I learn more about Format String Attacks?","answer":"For further information about Format String Attacks, you can explore the following resources:\r\n<ol>\r\n \t<li><a href=\"https:\/\/www.owasp.org\/images\/2\/26\/OWASPAppSecDC2006-MitjaK.pdf\" target=\"_new\">Exploiting Format String Vulnerabilities<\/a> - A presentation by Mitja Kolsek and Kostya Kortchinsky at OWASP AppSec DC 2006.<\/li>\r\n \t<li><a href=\"https:\/\/crypto.stanford.edu\/cs155\/papers\/formatstring-1.2.pdf\" target=\"_new\">The Format String Bug - A First Look<\/a> - A paper by Aleph One exploring format string vulnerabilities in-depth.<\/li>\r\n \t<li><a href=\"https:\/\/owasp.org\/www-project-top-ten\/\" target=\"_new\">OWASP Top Ten<\/a> - OWASP's top ten list of web application security risks, including format string vulnerabilities.<\/li>\r\n<\/ol>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki\/477282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki\/477282\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/media\/497608"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/media?parent=477282"}],"curies":[{"name":"\u3046\u30fc\u3093","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}