Submit Search
Spring小話
0 likes
1,358 views
eiryu
2013/1/24 日本Springユーザ会勉強会 LT資料
Read more
1 of 9
1
2
3
4
5
6
7
8
9
More Related Content
KEY
Cakephp api
Eiji Yokota
PDF
Spring AMQP × RabbitMQ
Keisuke Nishitani
PDF
Springの今
Kazuyuki Kawamura
PDF
Javaでのバリデーション 〜Bean Validation篇〜
eiryu
PDF
Introducing thymeleaf
eiryu
PDF
Ninja framework使ってみた
eiryu
PDF
JMeter小話
eiryu
PDF
Thymeleafのすすめ
eiryu
Cakephp api
Eiji Yokota
Spring AMQP × RabbitMQ
Keisuke Nishitani
Springの今
Kazuyuki Kawamura
Javaでのバリデーション 〜Bean Validation篇〜
eiryu
Introducing thymeleaf
eiryu
Ninja framework使ってみた
eiryu
JMeter小話
eiryu
Thymeleafのすすめ
eiryu
Featured
(20)
PDF
2024 Trend Updates: What Really Works In SEO & Content Marketing
Search Engine Journal
PDF
Storytelling For The Web: Integrate Storytelling in your Design Process
Chiara Aliotta
PDF
Artificial Intelligence, Data and Competition – SCHREPEL – June 2024 OECD dis...
OECD Directorate for Financial and Enterprise Affairs
PDF
How to Leverage AI to Boost Employee Wellness - Lydia Di Francesco - SocialHR...
SocialHRCamp
PDF
2024 State of Marketing Report – by Hubspot
Marius Sescu
PDF
Everything You Need To Know About ChatGPT
Expeed Software
PDF
Product Design Trends in 2024 | Teenage Engineerings
Pixeldarts
PDF
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
PDF
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
marketingartwork
PDF
Skeleton Culture Code
Skeleton Technologies
PDF
PEPSICO Presentation to CAGNY Conference Feb 2024
Neil Kimberley
PDF
Content Methodology: A Best Practices Report (Webinar)
contently
PPTX
How to Prepare For a Successful Job Search for 2024
Albert Qian
PDF
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
PDF
Trends In Paid Search: Navigating The Digital Landscape In 2024
Search Engine Journal
PDF
5 Public speaking tips from TED - Visualized summary
SpeakerHub
PDF
ChatGPT and the Future of Work - Clark Boyd
Clark Boyd
PDF
Getting into the tech field. what next
Tessa Mero
PDF
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Lily Ray
PDF
How to have difficult conversations
Rajiv Jayarajah, MAppComm, ACC
2024 Trend Updates: What Really Works In SEO & Content Marketing
Search Engine Journal
Storytelling For The Web: Integrate Storytelling in your Design Process
Chiara Aliotta
Artificial Intelligence, Data and Competition – SCHREPEL – June 2024 OECD dis...
OECD Directorate for Financial and Enterprise Affairs
How to Leverage AI to Boost Employee Wellness - Lydia Di Francesco - SocialHR...
SocialHRCamp
2024 State of Marketing Report – by Hubspot
Marius Sescu
Everything You Need To Know About ChatGPT
Expeed Software
Product Design Trends in 2024 | Teenage Engineerings
Pixeldarts
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
marketingartwork
Skeleton Culture Code
Skeleton Technologies
PEPSICO Presentation to CAGNY Conference Feb 2024
Neil Kimberley
Content Methodology: A Best Practices Report (Webinar)
contently
How to Prepare For a Successful Job Search for 2024
Albert Qian
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
Trends In Paid Search: Navigating The Digital Landscape In 2024
Search Engine Journal
5 Public speaking tips from TED - Visualized summary
SpeakerHub
ChatGPT and the Future of Work - Clark Boyd
Clark Boyd
Getting into the tech field. what next
Tessa Mero
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Lily Ray
How to have difficult conversations
Rajiv Jayarajah, MAppComm, ACC
Ad
Spring小話
1.
Spring小話 @eiryu
2.
自己紹介 ● TwitterID:@eiryu ●
エンジニア6年目 ● Spring歴9ヶ月くらい ● Java ● PostgreSQL ● もうすぐ引っ越します
3.
Webアプリケーション脆弱性テストにて ● GET http://host/app/error.bak
200 OK ● GET http://host/app/error.old 200 OK ● GET http://host/app/error.OLD 200 OK
4.
実際のコントローラ @RequestMapping("/error") public class ErrorController
{ @RequestMapping("") public String error() { ... } ... }
5.
挙動 ● error ● error/ ●
error.do ● error.php ● error.nande.yanen (下3つは一例) デフォルトでは、 error/ や error.* が処理対象とし て登録されている
6.
対策1 コントローラ修正 @RequestMapping("/error") public class ErrorController
{ @RequestMapping("/") public String error() { ... } ... }
7.
対策2 useDefaultSuffixPatternを無効に <bean class="org.springframework.web.servlet.mvc.annotation. DefaultAnnotationHandlerMapping">
<property name="useDefaultSuffixPattern" value="false"/> </bean>
8.
元ネタ http://d.hatena.ne. jp/eiryu9/20130120/1358651987
9.
ご清聴ありがとうございました