{"id":477747,"date":"2023-08-09T09:19:35","date_gmt":"2023-08-09T09:19:35","guid":{"rendered":""},"modified":"2023-09-05T11:15:18","modified_gmt":"2023-09-05T11:15:18","slug":"json-hijacking","status":"publish","type":"wiki","link":"https:\/\/oneproxy.pro\/jp\/wiki\/json-hijacking\/","title":{"rendered":"JSON\u30cf\u30a4\u30b8\u30e3\u30c3\u30af"},"content":{"rendered":"<p>\u300cJavaScript Object Notation \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u300d\u3068\u3082\u547c\u3070\u308c\u308b JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001\u30c7\u30fc\u30bf\u4ea4\u63db\u5f62\u5f0f\u3068\u3057\u3066 JSON (JavaScript Object Notation) \u3092\u5229\u7528\u3059\u308b Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u5f71\u97ff\u3092\u4e0e\u3048\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u4e0a\u306e\u8106\u5f31\u6027\u3067\u3059\u3002\u3053\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u653b\u6483\u306b\u5bfe\u3057\u3066\u9069\u5207\u306b\u4fdd\u8b77\u3055\u308c\u3066\u3044\u306a\u3044\u5834\u5408\u3001\u653b\u6483\u8005\u306f\u88ab\u5bb3\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u6a5f\u5bc6\u30c7\u30fc\u30bf\u3092\u76d7\u3080\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001Web \u30da\u30fc\u30b8\u304c\u305d\u306e Web \u30da\u30fc\u30b8\u3092\u63d0\u4f9b\u3057\u305f\u30c9\u30e1\u30a4\u30f3\u3068\u306f\u7570\u306a\u308b\u30c9\u30e1\u30a4\u30f3\u306b\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u4fe1\u3067\u304d\u306a\u3044\u3088\u3046\u306b\u3059\u308b\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3067\u3042\u308b\u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc\u3092\u60aa\u7528\u3057\u307e\u3059\u3002<\/p>\n<h2>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u8d77\u6e90\u306e\u6b74\u53f2\u3068\u305d\u308c\u306b\u3064\u3044\u3066\u306e\u6700\u521d\u306e\u8a00\u53ca\u3002<\/h2>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u30012006 \u5e74\u306b Jeremiah Grossman \u306b\u3088\u3063\u3066\u521d\u3081\u3066\u767a\u898b\u3055\u308c\u3001\u6587\u66f8\u5316\u3055\u308c\u307e\u3057\u305f\u3002\u5f7c\u306e\u7814\u7a76\u3067\u306f\u3001JSON \u5fdc\u7b54\u3092\u5229\u7528\u3059\u308b Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306f\u3001\u3053\u306e\u8106\u5f31\u6027\u304b\u3089\u4fdd\u8b77\u3059\u308b\u305f\u3081\u306e\u6a19\u6e96\u7684\u306a\u65b9\u6cd5\u304c\u306a\u3044\u305f\u3081\u3001\u3053\u306e\u8106\u5f31\u6027\u306e\u5f71\u97ff\u3092\u53d7\u3051\u3084\u3059\u3044\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u3059\u308b\u6700\u521d\u306e\u8a00\u53ca\u306f\u3001\u9069\u5207\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u304c\u8b1b\u3058\u3089\u308c\u3066\u3044\u306a\u3044\u30c7\u30fc\u30bf\u4ea4\u63db\u5f62\u5f0f\u3068\u3057\u3066 JSON \u3092\u4f7f\u7528\u3059\u308b\u3053\u3068\u306b\u95a2\u9023\u3059\u308b\u6f5c\u5728\u7684\u306a\u30ea\u30b9\u30af\u306b\u6ce8\u76ee\u3092\u96c6\u3081\u307e\u3057\u305f\u3002<\/p>\n<h2>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u3059\u308b\u8a73\u7d30\u60c5\u5831\u3002 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u30c8\u30d4\u30c3\u30af\u3092\u5c55\u958b\u3057\u307e\u3059\u3002<\/h2>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u5b89\u5168\u306a JSON \u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc\u306a\u3069\u306e\u9069\u5207\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30e1\u30ab\u30cb\u30ba\u30e0\u3092\u5b9f\u88c5\u305b\u305a\u306b JSON \u30c7\u30fc\u30bf\u3092\u63d0\u4f9b\u3059\u308b\u3068\u304d\u306b\u767a\u751f\u3057\u307e\u3059\u3002\u901a\u5e38\u3001Web \u30da\u30fc\u30b8\u304c\u30b5\u30fc\u30d0\u30fc\u304b\u3089 JSON \u30c7\u30fc\u30bf\u3092\u30ea\u30af\u30a8\u30b9\u30c8\u3059\u308b\u3068\u3001\u30da\u30fc\u30b8\u4e0a\u306e JavaScript \u30b3\u30fc\u30c9\u3067\u7c21\u5358\u306b\u89e3\u6790\u3057\u3066\u4f7f\u7528\u3067\u304d\u308b\u6b63\u898f\u306e JSON \u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u53d7\u3051\u53d6\u308a\u307e\u3059\u3002<\/p>\n<p>\u305f\u3060\u3057\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u5834\u5408\u3001\u653b\u6483\u8005\u306f\u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc\u3092\u60aa\u7528\u3057\u3066 JSON \u30c7\u30fc\u30bf\u3092\u76d7\u3080\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u3001\u88ab\u5bb3\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u3092\u3060\u307e\u3057\u3066\u3001\u653b\u6483\u8005\u304c\u5236\u5fa1\u3059\u308b\u60aa\u610f\u306e\u3042\u308b\u30b5\u30fc\u30d0\u30fc\u306b\u5bfe\u3057\u3066\u30af\u30ed\u30b9\u30aa\u30ea\u30b8\u30f3 \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5b9f\u884c\u3055\u305b\u307e\u3059\u3002\u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc\u306f (\u5f93\u6765\u306e Ajax \u30ea\u30af\u30a8\u30b9\u30c8\u3068\u306f\u7570\u306a\u308a) JSON \u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u9069\u7528\u3055\u308c\u306a\u3044\u305f\u3081\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30fc\u30d0\u30fc\u306f JSON \u30c7\u30fc\u30bf\u3092\u76f4\u63a5\u53d7\u4fe1\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u300cX-Content-Type-Options: nosniff\u300d\u3084\u300cwhile(1);\u300d\u306a\u3069\u306e\u9069\u5207\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30d8\u30c3\u30c0\u30fc\u3084\u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc\u304c\u5b58\u5728\u3057\u306a\u3044\u305f\u3081\u3001\u653b\u6483\u8005\u306f JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u653b\u6483\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002\u653b\u6483\u8005\u306f\u6a5f\u5bc6\u30c7\u30fc\u30bf\u3092\u76d7\u3080\u3053\u3068\u306b\u3088\u308a\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30d7\u30e9\u30a4\u30d0\u30b7\u30fc\u3068\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u4fb5\u5bb3\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h2>JSON\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u5185\u90e8\u69cb\u9020\u3002 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u4ed5\u7d44\u307f\u3002<\/h2>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001\u7279\u5b9a\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u6280\u8853\u3092\u63a1\u7528\u305b\u305a\u306b JSON \u5fdc\u7b54\u3092\u4f7f\u7528\u3059\u308b Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u4e3b\u306b\u30bf\u30fc\u30b2\u30c3\u30c8\u3068\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u306e\u5185\u90e8\u69cb\u9020\u306b\u306f\u6b21\u306e\u30b9\u30c6\u30c3\u30d7\u304c\u542b\u307e\u308c\u307e\u3059\u3002<\/p>\n<ol>\n<li>\u88ab\u5bb3\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u306f\u3001JSON \u30c7\u30fc\u30bf\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u3092 Web \u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3057\u307e\u3059\u3002<\/li>\n<li>Web \u30b5\u30fc\u30d0\u30fc\u306f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u51e6\u7406\u3057\u3001\u30ec\u30b9\u30dd\u30f3\u30b9\u3068\u3057\u3066 JSON \u30c7\u30fc\u30bf\u3092\u9001\u308a\u8fd4\u3057\u307e\u3059\u3002<\/li>\n<li>\u653b\u6483\u8005\u306f\u88ab\u5bb3\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u3092\u3060\u307e\u3057\u3066\u8ffd\u52a0\u306e\u30af\u30ed\u30b9\u30aa\u30ea\u30b8\u30f3\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4f5c\u6210\u3055\u305b\u3001\u305d\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u653b\u6483\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u306b\u9001\u4fe1\u3055\u308c\u307e\u3059\u3002<\/li>\n<li>JSON \u30ea\u30af\u30a8\u30b9\u30c8\u306b\u306f\u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc\u304c\u9069\u7528\u3055\u308c\u306a\u3044\u305f\u3081\u3001\u653b\u6483\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u306f\u88ab\u5bb3\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u304b\u3089\u76f4\u63a5 JSON \u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u508d\u53d7\u3057\u307e\u3059\u3002<\/li>\n<li>\u653b\u6483\u8005\u306f\u3001Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30c9\u30e1\u30a4\u30f3\u5185\u3067\u306e\u307f\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u306f\u305a\u306e\u6a5f\u5bc6 JSON \u30c7\u30fc\u30bf\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/li>\n<\/ol>\n<h2>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u4e3b\u8981\u306a\u6a5f\u80fd\u306e\u5206\u6790\u3002<\/h2>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u4e3b\u306a\u7279\u5fb4\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ul>\n<li>\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306e\u60aa\u7528: JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306b\u3088\u308b JSON \u30ea\u30af\u30a8\u30b9\u30c8\u306e\u9664\u5916\u3092\u5229\u7528\u3057\u3001\u653b\u6483\u8005\u304c JSON \u30ec\u30b9\u30dd\u30f3\u30b9\u3092\u508d\u53d7\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/li>\n<li>\u9069\u5207\u306a\u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc\u306e\u6b20\u5982: \u300cwhile(1);\u300d\u306a\u3069\u306e\u5b89\u5168\u306a JSON \u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc\u304c\u5b58\u5728\u3057\u306a\u3044\u3002\u307e\u305f\u306f\u300cX-Content-Type-Options: nosniff\u300d\u3092\u4f7f\u7528\u3059\u308b\u3068\u3001Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u5bfe\u3057\u3066\u8106\u5f31\u306b\u306a\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/li>\n<li>JSON \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u306b\u7126\u70b9\u3092\u5f53\u3066\u308b: \u3053\u306e\u653b\u6483\u306f\u3001\u30c7\u30fc\u30bf\u4ea4\u63db\u306b JSON \u30a8\u30f3\u30c9\u30dd\u30a4\u30f3\u30c8\u3092\u5229\u7528\u3059\u308b Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u4e2d\u5fc3\u306b\u884c\u308f\u308c\u307e\u3059\u3002<\/li>\n<\/ul>\n<h2>JSON\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u7a2e\u985e<\/h2>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001\u653b\u6483\u306e\u5b9f\u884c\u306b\u4f7f\u7528\u3055\u308c\u308b\u65b9\u6cd5\u306b\u57fa\u3065\u3044\u3066\u3001\u4e3b\u306b 2 \u3064\u306e\u30bf\u30a4\u30d7\u306b\u5206\u985e\u3067\u304d\u307e\u3059\u3002<\/p>\n<ol>\n<li>\n<p><strong>\u76f4\u63a5\u306e JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af:<\/strong> \u3053\u306e\u30bf\u30a4\u30d7\u306e\u653b\u6483\u3067\u306f\u3001\u653b\u6483\u8005\u306f\u88ab\u5bb3\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u3092\u3060\u307e\u3057\u3066\u3001\u653b\u6483\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u306b JSON \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u76f4\u63a5\u9001\u4fe1\u3055\u305b\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001\u653b\u6483\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u306f\u8ffd\u52a0\u306e\u624b\u9806\u3092\u884c\u308f\u305a\u306b JSON \u30c7\u30fc\u30bf\u3092\u76f4\u63a5\u53d7\u4fe1\u3057\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>JSONP (\u30d1\u30c7\u30a3\u30f3\u30b0\u4ed8\u304d JSON) \u30cf\u30a4\u30b8\u30e3\u30c3\u30af:<\/strong> JSONP \u306f\u3001\u30af\u30ed\u30b9\u30aa\u30ea\u30b8\u30f3 \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u884c\u3046\u969b\u306e\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306e\u5236\u9650\u3092\u514b\u670d\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3055\u308c\u308b\u6280\u8853\u3067\u3059\u3002 JSONP \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u3067\u306f\u3001\u653b\u6483\u8005\u306f JSONP \u30b3\u30fc\u30eb\u30d0\u30c3\u30af\u95a2\u6570\u3092\u64cd\u4f5c\u3057\u3066 JSON \u30c7\u30fc\u30bf\u3092\u53d7\u4fe1\u3057\u3001\u6a5f\u5bc6\u60c5\u5831\u3092\u62bd\u51fa\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<\/li>\n<\/ol>\n<p>\u4ee5\u4e0b\u306f\u30012 \u7a2e\u985e\u306e JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u9055\u3044\u3092\u5f37\u8abf\u3057\u305f\u6bd4\u8f03\u8868\u3067\u3059\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u30bf\u30a4\u30d7<\/th>\n<th>\u65b9\u6cd5<\/th>\n<th>\u5229\u70b9<\/th>\n<th>\u77ed\u6240<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\u76f4\u63a5\u306eJSON\u30cf\u30a4\u30b8\u30e3\u30c3\u30af<\/td>\n<td>JSON \u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3057\u3066\u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc\u3092\u5229\u7528\u3057\u307e\u3059\u3002<\/td>\n<td>\u5b9f\u884c\u306e\u7c21\u7d20\u5316\u3001JSON \u30c7\u30fc\u30bf\u3078\u306e\u76f4\u63a5\u30a2\u30af\u30bb\u30b9<\/td>\n<td>\u30ed\u30b0\u3067\u3088\u308a\u898b\u3084\u3059\u304f\u306a\u308a\u3001\u691c\u51fa\u304c\u5bb9\u6613\u306b\u306a\u308a\u307e\u3059<\/td>\n<\/tr>\n<tr>\n<td>JSONP\u30cf\u30a4\u30b8\u30e3\u30c3\u30af<\/td>\n<td>JSONP\u30b3\u30fc\u30eb\u30d0\u30c3\u30af\u95a2\u6570\u3092\u64cd\u4f5c\u3057\u307e\u3059<\/td>\n<td>\u540c\u4e00\u30aa\u30ea\u30b8\u30f3\u30dd\u30ea\u30b7\u30fc\u3092\u30d0\u30a4\u30d1\u30b9\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308b<\/td>\n<td>\u8106\u5f31\u306a JSONP \u5b9f\u88c5\u304c\u5fc5\u8981<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>JSON\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u624b\u53e3\u3068\u305d\u306e\u4f7f\u7528\u306b\u95a2\u9023\u3059\u308b\u554f\u984c\u3068\u305d\u306e\u89e3\u6c7a\u7b56\u3002<\/h2>\n<h3>\u60aa\u7528\u65b9\u6cd5<\/h3>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u8cc7\u683c\u60c5\u5831\u3001\u8a8d\u8a3c\u30c8\u30fc\u30af\u30f3\u3001JSON \u5fdc\u7b54\u306b\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u305d\u306e\u4ed6\u306e\u6a5f\u5bc6\u30c7\u30fc\u30bf\u306a\u3069\u306e\u6a5f\u5bc6\u60c5\u5831\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306b\u4f7f\u7528\u3067\u304d\u307e\u3059\u3002\u76d7\u307e\u308c\u305f\u30c7\u30fc\u30bf\u306f\u3001\u653b\u6483\u8005\u306b\u3088\u3063\u3066\u3055\u307e\u3056\u307e\u306a\u60aa\u610f\u306e\u3042\u308b\u76ee\u7684\u306b\u60aa\u7528\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<h3>\u554f\u984c\u3068\u89e3\u6c7a\u7b56<\/h3>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u3059\u308b\u4e3b\u306a\u554f\u984c\u306f\u3001\u30c7\u30fc\u30bf\u4ea4\u63db\u5f62\u5f0f\u3068\u3057\u3066 JSON \u3092\u4f7f\u7528\u3059\u308b\u591a\u304f\u306e Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u6a19\u6e96\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u304c\u6b20\u5982\u3057\u3066\u3044\u308b\u3053\u3068\u3067\u3059\u3002 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u9023\u3059\u308b\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3059\u308b\u305f\u3081\u306b\u3001\u958b\u767a\u8005\u3068 Web \u30b5\u30a4\u30c8\u7ba1\u7406\u8005\u306f\u6b21\u306e\u30bd\u30ea\u30e5\u30fc\u30b7\u30e7\u30f3\u3092\u5b9f\u88c5\u3067\u304d\u307e\u3059\u3002<\/p>\n<ol>\n<li>\n<p><strong>\u5b89\u5168\u306a JSON \u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc:<\/strong> \u300cwhile(1);\u300d\u306a\u3069\u306e\u5b89\u5168\u306a\u30e9\u30c3\u30d1\u30fc\u5185\u306b JSON \u5fdc\u7b54\u3092\u542b\u3081\u307e\u3059\u3002\u307e\u305f\u306f\u300cX-Content-Type-Options: nosniff\u300d\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u30d6\u30e9\u30a6\u30b6\u306b\u3088\u308b JSON \u30c7\u30fc\u30bf\u306e\u76f4\u63a5\u89e3\u6790\u304c\u9632\u6b62\u3055\u308c\u3001\u6f5c\u5728\u7684\u306a\u653b\u6483\u8005\u304c JSON \u30c7\u30fc\u30bf\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u306a\u304f\u306a\u308a\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>\u30af\u30ed\u30b9\u30aa\u30ea\u30b8\u30f3\u30ea\u30bd\u30fc\u30b9\u5171\u6709 (CORS):<\/strong> CORS \u30dd\u30ea\u30b7\u30fc\u3092\u5b9f\u88c5\u3059\u308b\u3068\u3001JSON \u30c7\u30fc\u30bf\u3078\u306e\u30af\u30ed\u30b9\u30aa\u30ea\u30b8\u30f3 \u30a2\u30af\u30bb\u30b9\u3092\u5236\u9650\u3067\u304d\u3001\u653b\u6483\u8005\u306b\u3088\u308b\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306e\u514d\u9664\u306e\u60aa\u7528\u3092\u52b9\u679c\u7684\u306b\u9632\u3050\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>\u30c8\u30fc\u30af\u30f3\u30d9\u30fc\u30b9\u306e\u8a8d\u8a3c:<\/strong> OAuth \u306a\u3069\u306e\u30c8\u30fc\u30af\u30f3\u30d9\u30fc\u30b9\u306e\u8a8d\u8a3c\u65b9\u6cd5\u3092\u5229\u7528\u3059\u308b\u3068\u3001\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u9632\u6b62\u3057\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u5f71\u97ff\u3092\u8efd\u6e1b\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>\u30b3\u30f3\u30c6\u30f3\u30c4 \u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 \u30dd\u30ea\u30b7\u30fc (CSP):<\/strong> CSP \u30d8\u30c3\u30c0\u30fc\u3092\u69cb\u6210\u3059\u308b\u3053\u3068\u3067\u3001\u7ba1\u7406\u8005\u306f Web \u30da\u30fc\u30b8\u4e0a\u3067\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u5b9f\u884c\u3092\u8a31\u53ef\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u3092\u5236\u5fa1\u3057\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<\/ol>\n<h2>\u4e3b\u306a\u7279\u5fb4\u3084\u305d\u306e\u4ed6\u306e\u985e\u4f3c\u7528\u8a9e\u3068\u306e\u6bd4\u8f03\u3092\u8868\u3084\u30ea\u30b9\u30c8\u306e\u5f62\u5f0f\u3067\u793a\u3057\u307e\u3059\u3002<\/h2>\n<p>\u4ee5\u4e0b\u306f\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u3068\u985e\u4f3c\u306e\u7528\u8a9e\u304a\u3088\u3073\u95a2\u9023\u6982\u5ff5\u3068\u306e\u6bd4\u8f03\u8868\u3067\u3059\u3002<\/p>\n<table>\n<thead>\n<tr>\n<th>\u5b66\u671f<\/th>\n<th>\u8aac\u660e<\/th>\n<th>\u9055\u3044<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>JSON\u30cf\u30a4\u30b8\u30e3\u30c3\u30af<\/td>\n<td>JSON \u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5bfe\u3059\u308b\u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc\u306e\u9664\u5916\u3092\u60aa\u7528\u3059\u308b\u8106\u5f31\u6027\u3002<\/td>\n<td>JSON \u5fdc\u7b54\u306b\u7279\u6709\u3067\u3001\u5b89\u5168\u306a JSON \u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc\u3092\u6301\u305f\u306a\u3044 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u3092\u5bfe\u8c61\u3068\u3057\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0<\/td>\n<td>Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306b\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u633f\u5165\u3057\u3066\u30c7\u30fc\u30bf\u3092\u76d7\u3093\u3060\u308a\u3001\u30e6\u30fc\u30b6\u30fc \u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u3057\u305f\u308a\u3059\u308b\u653b\u6483\u3002<\/td>\n<td>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f JSON \u30c7\u30fc\u30bf\u3078\u306e\u76f4\u63a5\u30a2\u30af\u30bb\u30b9\u3092\u30bf\u30fc\u30b2\u30c3\u30c8\u3068\u3059\u308b\u306e\u306b\u5bfe\u3057\u3001\u30b9\u30af\u30ea\u30d7\u30c8\u306e\u633f\u5165\u306b\u7126\u70b9\u3092\u5f53\u3066\u307e\u3059\u3002<\/td>\n<\/tr>\n<tr>\n<td>\u30af\u30ed\u30b9\u30b5\u30a4\u30c8 \u30ea\u30af\u30a8\u30b9\u30c8 \u30d5\u30a9\u30fc\u30b8\u30a7\u30ea (CSRF)<\/td>\n<td>\u30e6\u30fc\u30b6\u30fc\u3092\u9a19\u3057\u3066\u3001\u4fe1\u983c\u3055\u308c\u305f\u30b5\u30a4\u30c8\u4e0a\u3067\u671b\u307e\u3057\u304f\u306a\u3044\u30a2\u30af\u30b7\u30e7\u30f3\u3092\u5b9f\u884c\u3055\u305b\u308b\u653b\u6483\u3002<\/td>\n<td>CSRF \u306f\u30e6\u30fc\u30b6\u30fc\u306e\u30a2\u30af\u30b7\u30e7\u30f3\u306b\u7126\u70b9\u3092\u5f53\u3066\u307e\u3059\u304c\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306f JSON \u306e\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306e\u60aa\u7528\u3092\u6271\u3044\u307e\u3059\u3002<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u9023\u3059\u308b\u5c06\u6765\u306e\u5c55\u671b\u3068\u30c6\u30af\u30ce\u30ed\u30b8\u30fc\u3002<\/h2>\n<p>Web \u30c6\u30af\u30ce\u30ed\u30b8\u30fc\u304c\u9032\u5316\u3059\u308b\u306b\u3064\u308c\u3066\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u9023\u3059\u308b\u6f5c\u5728\u7684\u306a\u30ea\u30b9\u30af\u3082\u9032\u5316\u3057\u307e\u3059\u3002\u958b\u767a\u8005\u3084\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c02\u9580\u5bb6\u306f\u3001\u3053\u306e\u3088\u3046\u306a\u8106\u5f31\u6027\u3092\u9632\u3050\u305f\u3081\u306e\u9769\u65b0\u7684\u306a\u65b9\u6cd5\u3092\u7d99\u7d9a\u7684\u306b\u6a21\u7d22\u3057\u3066\u3044\u307e\u3059\u3002 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u9023\u3059\u308b\u5c06\u6765\u306e\u6f5c\u5728\u7684\u306a\u5c55\u671b\u3068\u30c6\u30af\u30ce\u30ed\u30b8\u30fc\u306b\u306f\u6b21\u306e\u3088\u3046\u306a\u3082\u306e\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<ol>\n<li>\n<p><strong>\u5b89\u5168\u306a JSON \u30ec\u30b9\u30dd\u30f3\u30b9 \u30e9\u30c3\u30d1\u30fc\u306e\u6a19\u6e96\u5316:<\/strong> \u6a19\u6e96\u5316\u3055\u308c\u305f\u5b89\u5168\u306a JSON \u5fdc\u7b54\u30e9\u30c3\u30d1\u30fc\u306e\u63a1\u7528\u306b\u3088\u308a\u3001\u958b\u767a\u8005\u306f JSON \u30c7\u30fc\u30bf\u3092\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u653b\u6483\u304b\u3089\u4fdd\u8b77\u3059\u308b\u3053\u3068\u304c\u5bb9\u6613\u306b\u306a\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>JSON \u306e\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306e\u6539\u5584:<\/strong> JSON \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u3088\u308a\u5305\u62ec\u7684\u306b\u30ab\u30d0\u30fc\u3059\u308b\u305f\u3081\u306e\u540c\u4e00\u30aa\u30ea\u30b8\u30f3 \u30dd\u30ea\u30b7\u30fc\u306e\u6a5f\u80fd\u5f37\u5316\u306b\u3088\u308a\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u30ea\u30b9\u30af\u304c\u8efd\u6e1b\u3055\u308c\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb (WAF) \u306e\u9032\u6b69:<\/strong> Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3 \u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306b\u306f\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u8a66\u307f\u3092\u52b9\u679c\u7684\u306b\u691c\u51fa\u3057\u3066\u30d6\u30ed\u30c3\u30af\u3059\u308b\u305f\u3081\u306b\u3001\u3088\u308a\u9ad8\u5ea6\u306a\u30a2\u30eb\u30b4\u30ea\u30ba\u30e0\u304c\u7d44\u307f\u8fbc\u307e\u308c\u3066\u3044\u308b\u5834\u5408\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>JSON Web \u30c8\u30fc\u30af\u30f3 (JWT) \u306e\u63a1\u7528\u306e\u5897\u52a0:<\/strong> JWT \u306f\u3001\u95a2\u4fc2\u8005\u9593\u3067\u60c5\u5831\u3092 JSON \u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3068\u3057\u3066\u9001\u4fe1\u3059\u308b\u5b89\u5168\u306a\u65b9\u6cd5\u3092\u63d0\u4f9b\u3057\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u5f71\u97ff\u3092\u53d7\u3051\u306b\u304f\u304f\u3057\u307e\u3059\u3002<\/p>\n<\/li>\n<\/ol>\n<h2>\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306e\u4f7f\u7528\u65b9\u6cd5\u3001\u307e\u305f\u306f JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u3068\u306e\u95a2\u9023\u4ed8\u3051\u65b9\u6cd5\u3002<\/h2>\n<p>\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3068 Web \u30b5\u30fc\u30d0\u30fc\u306e\u9593\u306e\u4ef2\u4ecb\u8005\u3068\u3057\u3066\u6a5f\u80fd\u3059\u308b\u3053\u3068\u3067\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u30ea\u30b9\u30af\u3092\u8efd\u6e1b\u3059\u308b\u5f79\u5272\u3092\u679c\u305f\u3057\u307e\u3059\u3002\u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u3092 JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306b\u95a2\u9023\u4ed8\u3051\u308b\u65b9\u6cd5\u306f\u6b21\u306e\u3068\u304a\u308a\u3067\u3059\u3002<\/p>\n<ol>\n<li>\n<p><strong>\u30ea\u30af\u30a8\u30b9\u30c8\u306e\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0:<\/strong> \u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001\u53d7\u4fe1\u3059\u308b JSON \u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0\u3057\u3066\u3001\u6f5c\u5728\u7684\u306a JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u8a66\u884c\u306e\u5146\u5019\u3092\u793a\u3059\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u30d6\u30ed\u30c3\u30af\u3059\u308b\u3088\u3046\u306b\u69cb\u6210\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>\u5fdc\u7b54\u306e\u30e9\u30c3\u30d4\u30f3\u30b0:<\/strong> \u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u3001JSON \u5fdc\u7b54\u3092\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306b\u914d\u4fe1\u3059\u308b\u524d\u306b\u5b89\u5168\u306a\u5fdc\u7b54\u30d8\u30c3\u30c0\u30fc (\u300cwhile(1);\u300d\u306a\u3069) \u3067\u30e9\u30c3\u30d7\u3057\u3066\u3001\u8ffd\u52a0\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5c64\u3092\u63d0\u4f9b\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<li>\n<p><strong>CORS \u7ba1\u7406:<\/strong> \u30d7\u30ed\u30ad\u30b7 \u30b5\u30fc\u30d0\u30fc\u306f\u53b3\u683c\u306a CORS \u30dd\u30ea\u30b7\u30fc\u3092\u9069\u7528\u3057\u3066\u3001JSON \u30c7\u30fc\u30bf\u3078\u306e\u4e0d\u6b63\u30a2\u30af\u30bb\u30b9\u3092\u9632\u6b62\u3057\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u30ea\u30b9\u30af\u3092\u6700\u5c0f\u9650\u306b\u6291\u3048\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<\/li>\n<\/ol>\n<h2>\u95a2\u9023\u30ea\u30f3\u30af<\/h2>\n<p>JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u3068 Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u8a73\u7d30\u306b\u3064\u3044\u3066\u306f\u3001\u6b21\u306e\u30ea\u30bd\u30fc\u30b9\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<ol>\n<li><a href=\"https:\/\/owasp.org\/www-community\/attacks\/JSON_Hijacking\" target=\"_new\" rel=\"noopener nofollow\">OWASP JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af<\/a><\/li>\n<li><a href=\"https:\/\/www.jeremiahgrossman.com\/2006\/01\/advanced-web-attack-techniques-using.html\" target=\"_new\" rel=\"noopener nofollow\">\u30b8\u30a7\u30ec\u30de\u30a4\u30a2\u30fb\u30b0\u30ed\u30b9\u30de\u30f3\u306e\u30d6\u30ed\u30b0<\/a><\/li>\n<li><a href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/Security\/Same-origin_policy\" target=\"_new\" rel=\"noopener nofollow\">Mozilla Developer Network (MDN) \u2013 \u540c\u4e00\u751f\u6210\u5143\u30dd\u30ea\u30b7\u30fc<\/a><\/li>\n<\/ol>\n<p>Web \u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u958b\u767a\u8005\u3084\u7ba1\u7406\u8005\u304c\u30e6\u30fc\u30b6\u30fc \u30c7\u30fc\u30bf\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3068\u30d7\u30e9\u30a4\u30d0\u30b7\u30fc\u3092\u78ba\u4fdd\u3059\u308b\u306b\u306f\u3001JSON \u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u306e\u30ea\u30b9\u30af\u3092\u7406\u89e3\u3057\u3001\u5bfe\u51e6\u3059\u308b\u3053\u3068\u304c\u4e0d\u53ef\u6b20\u3067\u3042\u308b\u3053\u3068\u3092\u5fd8\u308c\u306a\u3044\u3067\u304f\u3060\u3055\u3044\u3002\u30d9\u30b9\u30c8 \u30d7\u30e9\u30af\u30c6\u30a3\u30b9\u3092\u5b9f\u88c5\u3057\u3001\u6700\u65b0\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3092\u5e38\u306b\u6700\u65b0\u306e\u72b6\u614b\u306b\u4fdd\u3064\u3053\u3068\u306f\u3001\u3053\u306e\u3088\u3046\u306a\u8106\u5f31\u6027\u304b\u3089\u4fdd\u8b77\u3059\u308b\u306e\u306b\u5f79\u7acb\u3061\u307e\u3059\u3002<\/p>","protected":false},"featured_media":477748,"menu_order":0,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"class_list":["post-477747","wiki","type-wiki","status-publish","has-post-thumbnail","hentry"],"acf":{"faq_title":"Frequently Asked Questions about <mark>JSON Hijacking: An Encyclopedia Article<\/mark>","faq_items":[{"question":"What is JSON hijacking?","answer":"<p>JSON hijacking, also known as \"JavaScript Object Notation hijacking,\" is a security vulnerability that affects web applications using JSON as a data interchange format. It allows attackers to steal sensitive data from the victim's browser when the application lacks proper security measures.<\/p>"},{"question":"Who discovered JSON hijacking, and when was it first mentioned?","answer":"<p>JSON hijacking was first discovered and documented by Jeremiah Grossman in 2006. He brought attention to this vulnerability, highlighting the risks associated with using JSON without appropriate security measures.<\/p>"},{"question":"How does JSON hijacking work?","answer":"<p>JSON hijacking exploits the same-origin policy exemption for JSON requests. The attacker tricks the victim's browser into making an additional cross-origin request, which is intercepted by the attacker's server, granting them direct access to the JSON data.<\/p>"},{"question":"What are the key features of JSON hijacking?","answer":"<p>Key features include exploiting the same-origin policy, absence of secure JSON response wrappers, and targeting web applications using JSON endpoints for data exchange.<\/p>"},{"question":"What are the types of JSON hijacking?","answer":"<p>JSON hijacking can be classified into two types:<\/p><ol><li>Direct JSON hijacking: The attacker tricks the victim's browser to send JSON directly to the attacker's server.<\/li><li>JSONP hijacking: The attacker manipulates the JSONP callback function to extract JSON data.<\/li><\/ol>"},{"question":"How can JSON hijacking be mitigated?","answer":"<p>To prevent JSON hijacking, developers can implement secure JSON response wrappers, utilize CORS policies, employ token-based authentication, and configure Content Security Policy (CSP) headers.<\/p>"},{"question":"How does JSON hijacking differ from Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)?","answer":"<p>JSON hijacking targets the direct access to JSON data exploiting same-origin policy. XSS injects malicious scripts into web apps, while CSRF tricks users into performing unwanted actions on trusted sites.<\/p>"},{"question":"What are the future perspectives and technologies related to JSON hijacking?","answer":"<p>Future developments may include standardized secure JSON response wrappers, improved same-origin policy for JSON, and increased adoption of JSON Web Tokens (JWT) for secure data transmission.<\/p>"},{"question":"How can proxy servers help protect against JSON hijacking?","answer":"<p>Proxy servers can act as intermediaries between clients and web servers, filtering requests, wrapping responses securely, and managing CORS to minimize the risk of JSON hijacking.<\/p>"}]},"_links":{"self":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki\/477747","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki"}],"about":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/types\/wiki"}],"version-history":[{"count":0,"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/wiki\/477747\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/media\/477748"}],"wp:attachment":[{"href":"https:\/\/oneproxy.pro\/jp\/wp-json\/wp\/v2\/media?parent=477747"}],"curies":[{"name":"\u3046\u30fc\u3093","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}