Security
Vuln Report
Since around 2006, I have been reporting vulnerabilities (mostly XSS) found in Japanese web services to the companies involved and to IPA (Information-technology Promotion Agency, Japan). Everything listed here was confirmed fixed before publication (except one case where the operator could not be reached). Rather than disclosing vulnerabilities publicly, I reported them directly; early on I once published one on my blog without contacting the operator, but after that I switched to responsible disclosure through IPA.
“What kind of threat do you believe XSS could cause?”
At the time, the dangers of XSS were not yet widely understood. This is the question that came back from the IPA Security Center after receiving my report (2006, sic, translated):
5) Threats that could arise from the vulnerability XSS
Your report contained the entry above. What kind of threat do you believe could arise from cross-site scripting? We would appreciate it if you could provide specific details.
Session hijacking via cookie theft, phishing for personal information with input forms disguised as the legitimate site — I explained such threats one by one as the report moved forward.
I also reported an XSS in goo’s search, but I have lost the primary materials from that time and cannot reconstruct the details, so it is not included in the table below.
Reports
| Target | Route | Location | Outcome | Window | When |
|---|---|---|---|---|---|
| key.blogdns.net | IPA#52164334 | 入力フォーム | 取扱い終了(運営者不通) | 約3ヶ月 | 2006-08 |
| nun.nu | ブログ公開 | リダイレクタ | 修正済み | — | 2006-09 |
| Vector | IPA#85254681 | info.html | 修正済み | 約1ヶ月 | 2006-09 |
| ライブドア | IPA#96290952 | 検索 | 修正済み | 約1ヶ月 | 2006-09 |
| u.dan.co.jp | ブログ公開 | リダイレクタ | 修正済み | — | 2006-11 |
| CNET Japan | 直接 | 検索 | 修正済み | 2日 | 2007-02 |
| ニコニコ動画 | 直接 + IPA#77094233 | 検索 | 修正済み | 3日 | 2007-02 |
| ライブドア | IPA#53681582 | 検索 | 修正済み | 約3週間 | 2007-02 |
| Buzzurl 動画検索 | 直接 | 動画検索 | 修正済み | 翌日 | 2007-02 |
| はてな検索 | 直接 | 類似語推薦 | 修正済み | — | 2007-02 |
| Apache mod_cache | 公開(gist) | HTTP キャッシュ | 上流で修正済み | — | 2014-06 |