On mobile? Send a link to your computer to download HTTP Toolkit there:
On mobile? Send a link to your computer to download HTTP Toolkit there:
Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? RESTful APIãè¨è¨ããéã®ã¹ãã¼ã¿ã¹ã³ã¼ãã®æéã§ãã ã¡ã½ããå¥ GET æåããå ´å 200 OKï¼æãä¸è¬ç 304 Not Modifiedï¼æ¡ä»¶ä»ãGETã§ãã£ãã·ã¥ã使ããããå ´å POST æåããå ´å 201 Created ä½æãããªã½ã¼ã¹ã®URIã示ãLocationããããä»ãã¦ãã è°è« 200 OKã ã¨ã¾ããã®ãï¼ 200 OKãå¿çããå®è£ ãå¤ããããã¾ããã¨ããããã§ããªã 200 OKã¯POSTçµæããã£ãã·ã¥å¯è½ã201 Createdã¯POSTçµæããã£ãã·ã¥ä¸å¯è½ã¨ãã¦åãã¦ããããããã
WEBç³»ã®æ å ±ã»ãã¥ãªãã£é¢é£ã®å¦ç¿ã¡ã¢ã§ããã¡ã¢ãªã®ã§ä»æ å ±ã®ãã¤ã³ã¿ã ããã¨ãã®åæ¯ãªè¨äºãããã¾ãã â»2020.9 注è¨:æ¬ããã°ã®è§£èª¬è¨äºã¯å 容ãå¤ããªã£ã¦ããã¾ããOWASP ZAPãªã©ã®ã½ããã¦ã§ã¢ã®è§£èª¬ã¯ç¾è¡ãã¼ã¸ã§ã³ã®ä»æ§ããä¹é¢ãã¦ããå¯è½æ§ãããã¾ãã OWASP ZAPã¯ãåä½ã§ä½¿ããããFiddlerãBurp Suiteãªã©ã®ä»ã®ãã¼ã«ã«ãããã·ã¨çµã¿åããã¦å¤æ®µãããã·ã®å½¢ã«ãã¦å©ç¨ããã»ãã便å©ã§ãã â ãªãZAP+ä»ãããã·ã®å½¢ã«ããã OWASP ZAPã¯ãããã便å©ãªæ©è½ãããåé¢ããã°æ©è½ã«é¢ãã¦ãã¾ãã¡ãªæåãããã¤ãæã£ã¦ãã¾ãã OWASP ZAPã®ãã°æ©è½ã®ãã¾ãã¡ãã®ä¾ï¼ZAP 2.5.0ã§ã®ç¾è±¡ï¼ï¼ ã»ãåçã¹ãã£ã³ãã®ãã°ã¨ãå±¥æ´ãã®ãã°ãå¥ã§ã診æ対象ãµã¤ãã«ã¢ã¯ã»ã¹ãããåçã¹ãã£ã³ããå¾ã«ããã£ããã»ãã·ã§ã³ãã¡ã¤ã«ãä¿åãã¦ZA
ãã©ã¦ã¶ã«æ¬¡ã®ãã㪠HTTP ã¬ã¹ãã³ã¹ããããåºåããã¨ãä»»æã®ãã¡ã¤ã«åã§åºåå 容ããã¦ã³ãã¼ãããããã¨ãã§ããã Accept-Ranges: bytes Content-Type: application/octet-stream Content-Disposition: attachment; filename=ãã¡ã¤ã«å Content-Length: ãã¡ã¤ã«ãµã¤ãºåé¡ã¯ãã¡ã¤ã«åãæ¥æ¬èªã®æåãªã©ãASCII 以å¤ã®æåãå«ãå ´åã§ãããASCII 以å¤ã®æåãã¨ã³ã³ã¼ãããæ¹æ³ã¯ãã¾ãã¾ããããã©ã¦ã¶ã«ãã£ã¦å¯¾å¿ãã¾ã¡ã¾ã¡ã§ããã ããã§æ¬¡ã® PHP ã³ã¼ããç¨ãã¦ãã¹ããè¡ã£ãã download_test.php æå ã®ç°å¢ã§ãã¹ãããçµæã¯ãã¡ãã Opera 18 Chrome 31 Firefox 26 Opera 12 MSIE 8 MSIE 11 Saf
æè¿ã®ã¢ãã³ãªWebãã©ã¦ã¶ããµãã¼ããã¦ãããã»ãã¥ãªãã£ã«é¢é£ããã㪠X- ãªHTTPã¬ã¹ãã³ã¹ããããã¾ã¨ãã¦ã¿ã¾ããããã以å¤ã«ããã£ããæãã¦ãã ããã X-XSS-Protection 0:XSSãã£ã«ã¿ãç¡å¹ã«ããã 1:XSSãã£ã«ã¿ãæå¹ã«ããã XSSãã£ã«ã¿ãæå¹ã«ãããã¨ã§ã¨ã³ãã¦ã¼ã¶ãXSSã®è¢«å®³ã«ããå¯è½æ§ãä½æ¸ããããã¾ãã«èª¤æ¤ç¥ãããã¨ã§ç»é¢ã®è¡¨ç¤ºãä¹±ãããã¨ããããIE8+ãSafariãChrome(å¤å) ã§æå¹ãIEã§ã¯ãX-XSS-Protection: 1; mode=blockãã¨ããæå®ãå¯è½ã 2008/7/2 - IE8 Security Part IV: The XSS FilterBug 27312 â [XSSAuditor] Add support for header X-XSS-Protection X-Content-Ty
å æ¥ãWeb ãµã¼ãåå¼·ä¼ #2 ãéããã¾ãããå 容ã¯ãApache ã®ãã¥ã¼ãã³ã°ã¨ãããã¨ã§ãåå ãããã£ãã®ã§ãããä»ã®äºå®ããã£ã¦åå ã§ãã¾ããã§ããã ããã§ãåãå人çã«è¡ã£ã¦ãã Apache ã®ãã¥ã¼ãã³ã°ãç´¹ä»ãããã¨æãã¾ããæåãã¹ã©ã¤ãã§ä½æããããã¨æã£ãã®ã§ãããããã°ã«ã¾ã¨ããã»ãããããããªã®ã§ããã°ã«ã¾ã¨ãã¦ããã¾ãã ã¾ãã大åæã¨ã㦠Apache ããã¥ã¼ãã³ã°ããããã§ã大äºãªãã¨ã¯ãã® Apache ãæä¾ãã Web ãµã¼ãã¹ã®ç¨®é¡ã®ãã£ã¦å¤§ãããã¥ã¼ãã³ã°ããå 容ãç°ãªãã¨ãããã¨ã§ããä¾ãã°ãåç»ã»åçå ±æãµã¼ãã¹ã¨æ ªä¾¡æ å ±ã®ãµã¼ãã¹ãæ¯è¼ããã¨ãå½ç¶ã®ãã¨ãªãã大ãããµã¼ãã¹ã®å 容ãç°ãªãã¾ãããHTTP ã¬ãã«ã§ã¿ãã¨ã¯ã©ã¤ã¢ã³ãããã®ãªã¯ã¨ã¹ãæ°ããã¼ã¿ãµã¤ãºããªã©ãããªãéã£ã¦ãã¾ãã ã§ãã®ã§ãã¾ãã¯èªåãæ±ã£ã¦ããã¦ã§ããµã¼ã
æ¨è®¿é®çå 容ä¸åå¨ï¼è¯·æ ¸å¯¹åéè¯ï¼
ãåãåãããã©ã¼ã ãç»é²ãã©ã¼ã ããã£ã³ãã¼ã³ã®ç³è¾¼ãã©ã¼ã ã Webã«ã¯ãããããªãã©ã¼ã ãããã Webããã°ã©ãã¼ã§ããã°èª°ããä¸åº¦ã¯ä½ã£ããã¨ãããã¨æãã æ°äººããã°ã©ãã¼ã®åãã¦ã®å®åããã©ã¼ã ã§ãããã¨ãå¤ãã ããã æ°äººãä½ã£ã¦ããã¨ããã®ã«ãããããããæè¡çã«ãé¢ç½ãé¨åããªãããããæ£ããç¥èã®ãã人ãã¬ãã¥ã¼ãããã¨ãå°ãªãã¨æãããã åç´ãããã«ãã¹ããä¸è¶³ãã¦ããã¨ãããã¨ããããããããªãã ä¸è¨ã®çç±ã¯æ¶æ¸¬ã«ãããªãããææ°ãªãã©ã¼ã ãããããåºåã£ã¦ããã®ã¯äºå®ã ã ãããCAPTCHAã®è©±ã¨ã以åã®åé¡ã ã ããè¦ãããæªãä¾ãç°¡åã«ããã¦ãããæ°äººãåãã¦ã®å®åã«å½ããã¨ãã«ãããæ°ã«ãã¦ãããã°ãä¸ã®ä¸ã®ãã©ã¼ã ãã ãã¶è¯ããªãã¨æãã 1. ã¯ã©ã¤ã¢ã³ããµã¤ã(JavaScript)ã§ã®ãã§ãã¯ã®ã¿ã 2. é¸æè¢å¼ã®å ¥åæ¬ã«å¯¾ãããã§ãã¯ã®æ¼
ä»æ¥ã¯ãå°ãæè¡çãªè©±ã§ãããWebæ å½è ãç¥ã£ã¦ããã¨ããç¥èãããã¼ãã¯ãHTTPãããã¼ãã§ããç¥ããªãã¦ãWebãµã¤ãã¯ä½ãã¾ãããç¥ã£ã¦ããã¨ãµã¤ãä¸ã§ã®ä»çµã¿ä½ãã®è¦éãåºããããããã¾ããã ãã©ã¦ã¶ã§Webãã¼ã¸ã表示ããã¨ãã«ããã©ã¦ã¶ã¯Webãµã¼ãã¼ã¨éä¿¡ãã¦ãã¾ãããã®ã¨ãã«ä½¿ãããã®ããHTTPãã¨ããã«ã¼ã«ã§ãã HTTPã¯ãHTTPãªã¯ã¨ã¹ããã¨ãHTTPã¬ã¹ãã³ã¹ãã«åãã¦èãã¾ãããã©ã¦ã¶ããµã¼ãã¼ã«ããã®ãã¼ã¸ãè¦ãããã¨é ¼ãéä¿¡ããHTTPãªã¯ã¨ã¹ããã§ããã®ãªã¯ã¨ã¹ãã«å¿ãã¦ãµã¼ãã¼ããã©ã¦ã¶ã«è¿ãéä¿¡ããHTTPã¬ã¹ãã³ã¹ãã§ãã ã¾ãããã©ã¦ã¶ â ãµã¼ãã¼ã®ãHTTPãªã¯ã¨ã¹ãããã説æãã¾ãããã HTTPãªã¯ã¨ã¹ãã¯ãã©ã¦ã¶ãéããã®ã§ããããHTTPãªã¯ã¨ã¹ããä½ãã®ã¯ãã©ã¦ã¶ã§ãããµã¼ãã¼ã¯ãåãåã£ãHTTPãªã¯ã¨ã¹ãã®å 容ããã©ããªæ
HTTPå ¥é ããã HTTPå ¥é ä¸è¨ã«ç§»åãã¾ããã ã¨ã»ã»ã®HTTPå ¥é Copyright (C) 2005 æç«ã åçï¼2005å¹´3æ20æ¥ãæçµæ´æ°ï¼2005å¹´4æ3æ¥ https://www.tohoho-web.com/ex/http.htm
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}