Modern web applications depend on a lot of auxiliary scripts which are often hosted on third-party CDNs. Should an attacker be able to tamper with the fâ¦
tl;dr CSP Lv.2ã®nonceã使ãã¨æå¤ã¨ç°¡åã«CSPã®æ©æµãåãããã Firefoxã¯unsafe-inlineã¨ã®æåãããããã®ã§æ³¨æ ãµã³ãã«å®è£ ã¨ãã¦Expressã§ç°¡åã«nonce対å¿ã§ããconnectãã©ã°ã¤ã³ãæ¸ããï¼ãã¢ããï¼ Violation Reportããã©ã¦ã¶ã«ãã£ã¦ç´°ããæåã®å·®ç°ãããã CSP Lv.2 nonceã®ç»å ´ã¨èæ¯ CSPã®ç¹ã«unsafe-inlineã¯XSSã«å¯¾ãã¦æçµé²è¡ç·çã«å¼·åãªå¹æãããã ãããç¹ã«ãµã¼ãã¼ããã®å¤ã®åãæ¸¡ãé¨åãªã©ã§ã©ããã¦ãinline scriptã使ããããªãã¨ããããããunsafe-inlineãç¦æ¢ããã¨DOM dataçã使ããããå¾ããã¤ããæãã ã£ãã @kazuho ã§ããããã¨ãã£ã¦DOM dataãã¼ããã¨ããæãã§ã¯ãããã§ãããCSPã§inline scriptç¦æ¢ãã¡
ãã®ãã¼ã¸ã¯ã³ãã¥ããã£ã¼ã®å°½åã§è±èªãã翻訳ããã¾ãããMDN Web Docs ã³ãã¥ããã£ã¼ã«ã¤ãã¦ãã£ã¨ç¥ãã仲éã«ãªãã«ã¯ãã¡ãããã P� �View in English ���Always switch to English ã³ã³ãã³ãã»ãã¥ãªãã£ããªã·ã¼ (CSP) ã¯ãç¹å®ã®ç¨®é¡ã®ã»ãã¥ãªãã£è å¨ã®ãªã¹ã¯ã鲿¢ã¾ãã¯æå°éã«æããã®ã«å½¹ç«ã¤æ©è½ã§ããããã¯ãã¦ã§ããµã¤ããããã©ã¦ã¶ã¼ã¸ã®ä¸é£ã®æç¤ºã§æ§æããã¦ããããµã¤ããæ§æããã³ã¼ããå®è¡ã§ãããã¨ãå¶éããããã«ãã©ã¦ã¶ã¼ã«æç¤ºãã¾ãã CSP ã®ä¸»ãªç¨éã¯ãææ¸ãèªã¿è¾¼ããã¨ã許å¯ãããªã½ã¼ã¹ãç¹ã« JavaScript ãªã½ã¼ã¹ãå¶å¾¡ãããã¨ã§ããããã¯ä¸»ã«ãæ»æè ã被害è ã®ãµã¤ãã«æªæã®ããã³ã¼ããæ³¨å ¥ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° (XSS) æ»æã«å¯¾ããé²å¾¡ã¨ãã¦ä½¿ç¨ããã¾ãã CSP ã«ã¯ä»ã«ããã¯
#ssmjp 2014/10 XSSã®éç¨ã®è©± ééããªã©ããã¾ããã @yagihashoo ã¾ã§ã ## 10/28 9:26è¿½è¨ nonce-valueãè¦æ ¼ä¸ã¯Base64ã ãï¼ã¨ããææãããã ããã®ã§ã¹ã©ã¤ã18-19ãä¿®æ£ãã¾ããã 詳細ã¯ä»¥ä¸ãã覧ãã ããã http://www.w3.org/TR/CSP2/#source-list-valid-nonces ## 10/29 15:00è¿½è¨ Path matchingã®ä¾ç¤ºã«ã¤ãã¦ééãããã£ãããã¹ã©ã¤ã14ãä¿®æ£ãã¾ããã
å¼ç¤¾ã®ãã¼ã ãã¼ã¸ã«CSP(Content Security Policy)ãå°å ¥ãã¾ãããCSPã«ã¤ãã¦ã¯ãã¯ãããããããæ°ã®ã¹ã©ã¤ãã5åã§ãããCSPããããããããã¨æãã¾ãã以ä¸ã«ã¹ã©ã¤ãã®ä¸é¨ãå¼ç¨ãã¾ãã å ·ä½çã«ã¯ã以ä¸ã®ããã«æå®ãã¦ä½¿ãã¾ãã Content-Security-Policy: default-src 'self' ãã®çµæã以ä¸ã®ããã«JavaScriptã®è¨è¿°ãå¶éããã¾ãã å¤é¨ã®JavaScriptã®èªã¿è¾¼ã¿ã¯ç¦æ¢ HTMLã½ã¼ã¹ã«è¨è¿°ãã<script>...</script>ã®JavaScriptã¯ç¦æ¢ ã¤ãã³ã屿§(onload="xxxx"ãªã©)ã¯ç¦æ¢ ä½ãæ¸ããªããªããããªããã¨æãããããããã¾ããããJavaScriptã¯å ¨ã¦*.jsãã¡ã¤ã«ã«è¨è¿°ããã°ãããã¨ãããã¨ã§ãã CSPã¯ãJavaScriptã®ã³ã¼ãã¨ãã¼ã¿ãåé¢ãã¦
ã¡ã³ããã³ã¹
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}