{"id":816,"date":"2025-08-04T17:19:41","date_gmt":"2025-08-04T08:19:41","guid":{"rendered":"https:\/\/nexive.tech\/?p=816"},"modified":"2025-08-04T17:19:41","modified_gmt":"2025-08-04T08:19:41","slug":"%e3%80%90%e3%82%b5%e3%82%af%e3%83%83%e3%81%a8%e8%a7%a3%e8%aa%ac%e3%80%91php%e3%81%a0%e3%81%91%e3%81%a7%e5%ae%9f%e8%a3%85%e3%81%99%e3%82%8b%e7%b0%a1%e6%98%93csrf%e5%af%be%e7%ad%96%e3%81%ae%e5%9f%ba","status":"publish","type":"post","link":"https:\/\/nexive.tech\/?p=816","title":{"rendered":"\u3010\u30b5\u30af\u30c3\u3068\u89e3\u8aac\u3011PHP\u3060\u3051\u3067\u5b9f\u88c5\u3059\u308b\u7c21\u6613CSRF\u5bfe\u7b56\u306e\u57fa\u672c\u69cb\u6210"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">1. \u672c\u8a18\u4e8b\u306e\u30dd\u30a4\u30f3\u30c8<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>PHP\u306e\u307f\u3092\u7528\u3044\u305f\u57fa\u672c\u7684\u306aCSRF\u5bfe\u7b56\u306e\u5b9f\u88c5\u65b9\u6cd5\u3092\u89e3\u8aac<\/li>\n\n\n\n<li>\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u975e\u4f9d\u5b58\u3067\u3001\u30d5\u30a9\u30fc\u30e0\u51e6\u7406\u306b\u9069\u7528\u53ef\u80fd\u306a\u69cb\u6210<\/li>\n\n\n\n<li>\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u6d3b\u7528\u3057\u305f\u30c8\u30fc\u30af\u30f3\u751f\u6210\u30fb\u691c\u8a3c\u306e\u6d41\u308c\u3092\u7d39\u4ecb<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">2. CSRF\u3068\u306f\uff1f<\/h2>\n\n\n\n<p>CSRF\uff08Cross-Site Request Forgery\uff09\u306f\u3001\u8a8d\u8a3c\u6e08\u307f\u30e6\u30fc\u30b6\u30fc\u306e\u6a29\u9650\u3092\u60aa\u7528\u3057\u3066\u3001\u610f\u56f3\u3057\u306a\u3044\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5916\u90e8\u30b5\u30a4\u30c8\u304b\u3089\u9001\u4fe1\u3055\u305b\u308b\u653b\u6483\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u4f8b\u3048\u3070\u3001\u30ed\u30b0\u30a4\u30f3\u6e08\u307f\u306e\u9280\u884c\u30b5\u30a4\u30c8\u306b\u5bfe\u3057\u3001\u653b\u6483\u8005\u304c\u4ed5\u8fbc\u3093\u3060\u5916\u90e8\u30da\u30fc\u30b8\u3092\u901a\u3058\u3066\u52dd\u624b\u306b\u9001\u91d1\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5b9f\u884c\u3055\u305b\u308b\u3068\u3044\u3063\u305f\u30b1\u30fc\u30b9\u304c\u4ee3\u8868\u4f8b\u3067\u3059\u3002\u30e6\u30fc\u30b6\u30fc\u306eCookie\u304c\u81ea\u52d5\u9001\u4fe1\u3055\u308c\u308b\u3053\u3068\u3067\u3001\u4e0d\u6b63\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u3042\u3063\u3066\u3082\u6b63\u5f53\u306a\u64cd\u4f5c\u3068\u3057\u3066\u51e6\u7406\u3055\u308c\u308b\u30ea\u30b9\u30af\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n\n\n\n<p>CSRF\u5bfe\u7b56\u3068\u3057\u3066\u4e00\u822c\u7684\u306a\u306e\u306f\u3001\u30d5\u30a9\u30fc\u30e0\u9001\u4fe1\u6642\u306b\u30e9\u30f3\u30c0\u30e0\u306a\u30c8\u30fc\u30af\u30f3\u3092\u57cb\u3081\u8fbc\u307f\u3001\u305d\u308c\u304c\u6b63\u5f53\u306a\u3082\u306e\u3067\u3042\u308b\u304b\u3092\u30b5\u30fc\u30d0\u30fc\u5074\u3067\u691c\u8a3c\u3059\u308b\u65b9\u5f0f\u3067\u3059\u3002\u3053\u306e\u4ed5\u7d44\u307f\u306b\u3088\u308a\u3001\u653b\u6483\u8005\u304c\u7528\u610f\u3057\u305f\u507d\u306e\u30d5\u30a9\u30fc\u30e0\u304b\u3089\u306f\u30c8\u30fc\u30af\u30f3\u304c\u4e00\u81f4\u305b\u305a\u3001\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u62d2\u5426\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u5b9f\u52d9\u3067\u306f\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u306b\u7d44\u307f\u8fbc\u307e\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u591a\u3044\u3067\u3059\u304c\u3001\u672c\u8a18\u4e8b\u3067\u306fPHP\u306e\u307f\u3067\u6700\u5c0f\u9650\u306e\u4ed5\u7d44\u307f\u3092\u81ea\u4f5c\u3059\u308b\u65b9\u6cd5\u306b\u7126\u70b9\u3092\u5f53\u3066\u307e\u3059\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. \u8a73\u7d30\u89e3\u8aac<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u30c8\u30fc\u30af\u30f3\u306e\u751f\u6210\u3068\u4fdd\u5b58<\/h3>\n\n\n\n<p>\u30bb\u30c3\u30b7\u30e7\u30f3\u3092\u4f7f\u3063\u3066\u30c8\u30fc\u30af\u30f3\u3092\u751f\u6210\u30fb\u4fdd\u6301\u3057\u307e\u3059\u3002\u30da\u30fc\u30b8\u521d\u56de\u8868\u793a\u6642\u306b\u30c8\u30fc\u30af\u30f3\u3092\u4f5c\u6210\u3057\u3001\u30d5\u30a9\u30fc\u30e0\u306b\u57cb\u3081\u8fbc\u307f\u307e\u3059\u3002<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro cbp-has-line-numbers\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;--cbp-line-number-color:#D4D4D4;--cbp-line-number-width:calc(2 * 0.6 * .875rem);line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:16px 0 0 16px;width:100%;text-align:left;background-color:#1e1e1e\"><span style=\"background:#c7c7c7;padding:0.3rem 0.5rem 0.2rem;border-radius:1rem;font-size:0.8em;line-height:1;height:1.25rem;text-align:center;display:inline-flex;align-items:center;justify-content:center;color:#1e1e1e\">PHP<\/span><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#D4D4D4;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;?php\nsession_start();\n\n\/\/ \u30c8\u30fc\u30af\u30f3\u304c\u672a\u751f\u6210\u3067\u3042\u308c\u3070\u4f5c\u6210\nif (empty($_SESSION&#91;'csrf_token'&#93;)) {\n    $_SESSION&#91;'csrf_token'&#93; = bin2hex(random_bytes(32));\n}\n$token = $_SESSION&#91;'csrf_token'&#93;;\n?>\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki dark-plus\" style=\"background-color: #1E1E1E\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D4D4D4\">&lt;?php<\/span><\/span>\n<span class=\"line\"><span style=\"color: #DCDCAA\">session_start<\/span><span style=\"color: #D4D4D4\">();<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #6A9955\">\/\/ \u30c8\u30fc\u30af\u30f3\u304c\u672a\u751f\u6210\u3067\u3042\u308c\u3070\u4f5c\u6210<\/span><\/span>\n<span class=\"line\"><span style=\"color: #C586C0\">if<\/span><span style=\"color: #D4D4D4\"> (<\/span><span style=\"color: #DCDCAA\">empty<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #9CDCFE\">$_SESSION<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93;)) {<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #9CDCFE\">$_SESSION<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93; = <\/span><span style=\"color: #DCDCAA\">bin2hex<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #DCDCAA\">random_bytes<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #B5CEA8\">32<\/span><span style=\"color: #D4D4D4\">));<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #9CDCFE\">$token<\/span><span style=\"color: #D4D4D4\"> = <\/span><span style=\"color: #9CDCFE\">$_SESSION<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93;;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">?&gt;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">\u30d5\u30a9\u30fc\u30e0\u306b\u30c8\u30fc\u30af\u30f3\u3092\u57cb\u3081\u8fbc\u3080<\/h3>\n\n\n\n<p>\u30d5\u30a9\u30fc\u30e0\u5185\u306bhidden\u30d5\u30a3\u30fc\u30eb\u30c9\u3067\u30c8\u30fc\u30af\u30f3\u3092\u57cb\u3081\u8fbc\u307f\u307e\u3059\u3002<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro cbp-has-line-numbers\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;--cbp-line-number-color:#D4D4D4;--cbp-line-number-width:calc(1 * 0.6 * .875rem);line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:16px 0 0 16px;width:100%;text-align:left;background-color:#1e1e1e\"><span style=\"background:#c7c7c7;padding:0.3rem 0.5rem 0.2rem;border-radius:1rem;font-size:0.8em;line-height:1;height:1.25rem;text-align:center;display:inline-flex;align-items:center;justify-content:center;color:#1e1e1e\">HTML<\/span><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#D4D4D4;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;form method=\"post\" action=\"submit.php\">\n    &lt;input type=\"hidden\" name=\"csrf_token\" value=\"&lt;?php echo htmlspecialchars($token, ENT_QUOTES); ?>\">\n    &lt;input type=\"text\" name=\"message\">\n    &lt;input type=\"submit\" value=\"\u9001\u4fe1\">\n&lt;\/form>\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki dark-plus\" style=\"background-color: #1E1E1E\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #808080\">&lt;<\/span><span style=\"color: #569CD6\">form<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">method<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;post&quot;<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">action<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;submit.php&quot;<\/span><span style=\"color: #808080\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #808080\">&lt;<\/span><span style=\"color: #569CD6\">input<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">type<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;hidden&quot;<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">name<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;csrf_token&quot;<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">value<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;<\/span><span style=\"color: #F44747\">&lt;<\/span><span style=\"color: #CE9178\">?php echo htmlspecialchars($token, ENT_QUOTES); ?&gt;&quot;<\/span><span style=\"color: #808080\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #808080\">&lt;<\/span><span style=\"color: #569CD6\">input<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">type<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;text&quot;<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">name<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;message&quot;<\/span><span style=\"color: #808080\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #808080\">&lt;<\/span><span style=\"color: #569CD6\">input<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">type<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;submit&quot;<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #9CDCFE\">value<\/span><span style=\"color: #D4D4D4\">=<\/span><span style=\"color: #CE9178\">&quot;\u9001\u4fe1&quot;<\/span><span style=\"color: #808080\">&gt;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #808080\">&lt;\/<\/span><span style=\"color: #569CD6\">form<\/span><span style=\"color: #808080\">&gt;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">\u30b5\u30fc\u30d0\u30fc\u5074\u3067\u306e\u691c\u8a3c<\/h3>\n\n\n\n<p>\u30d5\u30a9\u30fc\u30e0\u9001\u4fe1\u5f8c\u3001\u30c8\u30fc\u30af\u30f3\u304c\u6b63\u3057\u3044\u304b\u3092\u691c\u8a3c\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<div class=\"wp-block-kevinbatdorf-code-block-pro cbp-has-line-numbers\" data-code-block-pro-font-family=\"Code-Pro-JetBrains-Mono\" style=\"font-size:.875rem;font-family:Code-Pro-JetBrains-Mono,ui-monospace,SFMono-Regular,Menlo,Monaco,Consolas,monospace;--cbp-line-number-color:#D4D4D4;--cbp-line-number-width:calc(2 * 0.6 * .875rem);line-height:1.25rem;--cbp-tab-width:2;tab-size:var(--cbp-tab-width, 2)\"><span style=\"display:flex;align-items:center;padding:16px 0 0 16px;width:100%;text-align:left;background-color:#1e1e1e\"><span style=\"background:#c7c7c7;padding:0.3rem 0.5rem 0.2rem;border-radius:1rem;font-size:0.8em;line-height:1;height:1.25rem;text-align:center;display:inline-flex;align-items:center;justify-content:center;color:#1e1e1e\">PHP<\/span><\/span><span role=\"button\" tabindex=\"0\" style=\"color:#D4D4D4;display:none\" aria-label=\"Copy\" class=\"code-block-pro-copy-button\"><pre class=\"code-block-pro-copy-button-pre\" aria-hidden=\"true\"><textarea class=\"code-block-pro-copy-button-textarea\" tabindex=\"-1\" aria-hidden=\"true\" readonly>&lt;?php\nsession_start();\n\nif ($_SERVER&#91;'REQUEST_METHOD'&#93; === 'POST') {\n    if (!isset($_POST&#91;'csrf_token'&#93;, $_SESSION&#91;'csrf_token'&#93;) ||\n        !hash_equals($_SESSION&#91;'csrf_token'&#93;, $_POST&#91;'csrf_token'&#93;)) {\n        die('\u4e0d\u6b63\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u3059');\n    }\n\n    \/\/ \u6b63\u5e38\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3068\u3057\u3066\u51e6\u7406\u3092\u7d9a\u884c\n    $message = $_POST&#91;'message'&#93;;\n    echo \"\u53d7\u4fe1\u30e1\u30c3\u30bb\u30fc\u30b8: \" . htmlspecialchars($message, ENT_QUOTES);\n}\n?>\n<\/textarea><\/pre><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:24px;height:24px\" fill=\"none\" viewBox=\"0 0 24 24\" stroke=\"currentColor\" stroke-width=\"2\"><path class=\"with-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2m-6 9l2 2 4-4\"><\/path><path class=\"without-check\" stroke-linecap=\"round\" stroke-linejoin=\"round\" d=\"M9 5H7a2 2 0 00-2 2v12a2 2 0 002 2h10a2 2 0 002-2V7a2 2 0 00-2-2h-2M9 5a2 2 0 002 2h2a2 2 0 002-2M9 5a2 2 0 012-2h2a2 2 0 012 2\"><\/path><\/svg><\/span><pre class=\"shiki dark-plus\" style=\"background-color: #1E1E1E\" tabindex=\"0\"><code><span class=\"line\"><span style=\"color: #D4D4D4\">&lt;?php<\/span><\/span>\n<span class=\"line\"><span style=\"color: #DCDCAA\">session_start<\/span><span style=\"color: #D4D4D4\">();<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #C586C0\">if<\/span><span style=\"color: #D4D4D4\"> (<\/span><span style=\"color: #9CDCFE\">$_SERVER<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;REQUEST_METHOD&#39;<\/span><span style=\"color: #D4D4D4\">&#93; === <\/span><span style=\"color: #CE9178\">&#39;POST&#39;<\/span><span style=\"color: #D4D4D4\">) {<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #C586C0\">if<\/span><span style=\"color: #D4D4D4\"> (!<\/span><span style=\"color: #DCDCAA\">isset<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #9CDCFE\">$_POST<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93;, <\/span><span style=\"color: #9CDCFE\">$_SESSION<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93;) ||<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">        !<\/span><span style=\"color: #DCDCAA\">hash_equals<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #9CDCFE\">$_SESSION<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93;, <\/span><span style=\"color: #9CDCFE\">$_POST<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;csrf_token&#39;<\/span><span style=\"color: #D4D4D4\">&#93;)) {<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">        <\/span><span style=\"color: #C586C0\">die<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #CE9178\">&#39;\u4e0d\u6b63\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3067\u3059&#39;<\/span><span style=\"color: #D4D4D4\">);<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    }<\/span><\/span>\n<span class=\"line\"><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #6A9955\">\/\/ \u6b63\u5e38\u306a\u30ea\u30af\u30a8\u30b9\u30c8\u3068\u3057\u3066\u51e6\u7406\u3092\u7d9a\u884c<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #9CDCFE\">$message<\/span><span style=\"color: #D4D4D4\"> = <\/span><span style=\"color: #9CDCFE\">$_POST<\/span><span style=\"color: #D4D4D4\">&#91;<\/span><span style=\"color: #CE9178\">&#39;message&#39;<\/span><span style=\"color: #D4D4D4\">&#93;;<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">    <\/span><span style=\"color: #DCDCAA\">echo<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #CE9178\">&quot;\u53d7\u4fe1\u30e1\u30c3\u30bb\u30fc\u30b8: &quot;<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #D4D4D4\">.<\/span><span style=\"color: #D4D4D4\"> <\/span><span style=\"color: #DCDCAA\">htmlspecialchars<\/span><span style=\"color: #D4D4D4\">(<\/span><span style=\"color: #9CDCFE\">$message<\/span><span style=\"color: #D4D4D4\">, ENT_QUOTES);<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">}<\/span><\/span>\n<span class=\"line\"><span style=\"color: #D4D4D4\">?&gt;<\/span><\/span>\n<span class=\"line\"><\/span><\/code><\/pre><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">\u88dc\u8db3\uff1ahash_equals\u3092\u4f7f\u3046\u7406\u7531<\/h3>\n\n\n\n<p><code>===<\/code>\u306b\u3088\u308b\u5358\u7d14\u6bd4\u8f03\u3067\u306f\u30bf\u30a4\u30df\u30f3\u30b0\u653b\u6483\u306b\u5bfe\u3057\u3066\u8106\u5f31\u306a\u305f\u3081\u3001PHP 5.6\u4ee5\u964d\u3067\u5c0e\u5165\u3055\u308c\u305f<code>hash_equals()<\/code>\u3092\u4f7f\u3044\u307e\u3059\u3002<br>\u3053\u306e\u95a2\u6570\u306f\u6bd4\u8f03\u306b\u304b\u304b\u308b\u6642\u9593\u3092\u4e00\u5b9a\u306b\u4fdd\u3064\u305f\u3081\u3001\u5b89\u5168\u306a\u6bd4\u8f03\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. \u3088\u304f\u3042\u308b\u30df\u30b9\u30fb\u8aa4\u89e3\u30fb\u843d\u3068\u3057\u7a74<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>\u30c8\u30fc\u30af\u30f3\u3092\u30bb\u30c3\u30b7\u30e7\u30f3\u306b\u4fdd\u5b58\u3057\u3066\u3044\u306a\u3044<\/strong>\uff1a\u9001\u4fe1\u3055\u308c\u305f\u30c8\u30fc\u30af\u30f3\u3068\u7a81\u304d\u5408\u308f\u305b\u308b\u305f\u3081\u3001\u30bb\u30c3\u30b7\u30e7\u30f3\u5074\u306e\u4fdd\u6301\u304c\u5fc5\u9808\u3067\u3059\u3002<\/li>\n\n\n\n<li><strong>\u30c8\u30fc\u30af\u30f3\u3092\u4f7f\u3044\u56de\u3059<\/strong>\uff1a\u540c\u3058\u30c8\u30fc\u30af\u30f3\u3092\u8907\u6570\u56de\u4f7f\u3044\u56de\u3059\u3068\u3001\u5225\u30da\u30fc\u30b8\u3067\u53d6\u5f97\u3057\u305f\u5024\u3092\u6d41\u7528\u3055\u308c\u308b\u30ea\u30b9\u30af\u304c\u3042\u308a\u307e\u3059\u3002<br>\u5fc5\u8981\u306b\u5fdc\u3058\u3066\u30ef\u30f3\u30bf\u30a4\u30e0\u5316\u3092\u691c\u8a0e\u3057\u307e\u3057\u3087\u3046\u3002<\/li>\n\n\n\n<li><strong>\u30c8\u30fc\u30af\u30f3\u306e\u51fa\u529b\u306b<code>htmlspecialchars<\/code>\u3092\u5fd8\u308c\u308b<\/strong>\uff1a\u30d5\u30a9\u30fc\u30e0\u306b\u30c8\u30fc\u30af\u30f3\u3092\u57cb\u3081\u8fbc\u3080\u969b\u3001\u30a8\u30b9\u30b1\u30fc\u30d7\u3057\u306a\u3044\u3068XSS\u306e\u6e29\u5e8a\u306b\u306a\u308a\u307e\u3059\u3002<\/li>\n\n\n\n<li><strong>GET\u30e1\u30bd\u30c3\u30c9\u306b\u9069\u7528\u3057\u3066\u3044\u306a\u3044<\/strong>\uff1aCSRF\u5bfe\u7b56\u306f\u57fa\u672c\u7684\u306b\u72b6\u614b\u5909\u66f4\u7cfb\uff08POST\u306a\u3069\uff09\u306b\u9650\u5b9a\u3057\u3066\u9069\u7528\u3059\u308b\u306e\u304c\u4e00\u822c\u7684\u3067\u3059\u3002<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">5. \u307e\u3068\u3081<\/h2>\n\n\n\n<p>CSRF\u306f\u5916\u90e8\u30b5\u30a4\u30c8\u304b\u3089\u306e\u610f\u56f3\u3057\u306a\u3044\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9632\u3050\u305f\u3081\u306e\u57fa\u672c\u7684\u306a\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u3067\u3059\u3002<\/p>\n\n\n\n<p>PHP\u306e\u307f\u3067\u3082\u30bb\u30c3\u30b7\u30e7\u30f3\u3068\u30c8\u30fc\u30af\u30f3\u3092\u7528\u3044\u305f\u4ed5\u7d44\u307f\u3092\u69cb\u7bc9\u53ef\u80fd\u3067\u3042\u308a\u3001<code>hash_equals<\/code>\u3084<code>htmlspecialchars<\/code>\u3092\u9069\u5207\u306b\u4f7f\u3046\u3053\u3068\u304c\u30dd\u30a4\u30f3\u30c8\u3067\u3059\u3002<\/p>\n\n\n\n<p>\u30d5\u30ec\u30fc\u30e0\u30ef\u30fc\u30af\u3092\u4f7f\u308f\u306a\u3044\u74b0\u5883\u3084\u3001\u5c0f\u898f\u6a21\u306a\u30b9\u30af\u30ea\u30d7\u30c8\u3067\u3082\u6d3b\u7528\u3067\u304d\u308b\u624b\u6cd5\u3068\u3057\u3066\u899a\u3048\u3066\u304a\u304f\u3068\u4fbf\u5229\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. \u672c\u8a18\u4e8b\u306e\u30dd\u30a4\u30f3\u30c8 2. CSRF\u3068\u306f\uff1f CSRF\uff08Cross-Site Request Forgery\uff09\u306f\u3001\u8a8d\u8a3c\u6e08\u307f\u30e6\u30fc\u30b6\u30fc\u306e\u6a29\u9650\u3092\u60aa\u7528\u3057\u3066\u3001\u610f\u56f3\u3057\u306a\u3044\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5916\u90e8\u30b5\u30a4\u30c8\u304b\u3089\u9001\u4fe1\u3055\u305b\u308b\u653b\u6483\u3067\u3059\u3002 \u4f8b\u3048\u3070\u3001\u30ed\u30b0\u30a4 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":893,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"swell_btn_cv_data":"","footnotes":""},"categories":[85],"tags":[],"class_list":["post-816","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-php"],"_links":{"self":[{"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/posts\/816","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nexive.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=816"}],"version-history":[{"count":2,"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/posts\/816\/revisions"}],"predecessor-version":[{"id":894,"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/posts\/816\/revisions\/894"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nexive.tech\/index.php?rest_route=\/wp\/v2\/media\/893"}],"wp:attachment":[{"href":"https:\/\/nexive.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=816"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nexive.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=816"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nexive.tech\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=816"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}