Modern web applications depend on a lot of auxiliary scripts which are often hosted on third-party CDNs. Should an attacker be able to tamper with the fâ¦
tl;dr CSP Lv.2ã®nonceã使ãã¨æå¤ã¨ç°¡åã«CSPã®æ©æµãåãããã Firefoxã¯unsafe-inlineã¨ã®æåãããããã®ã§æ³¨æ ãµã³ãã«å®è£ ã¨ãã¦Expressã§ç°¡åã«nonce対å¿ã§ããconnectãã©ã°ã¤ã³ãæ¸ããï¼ãã¢ããï¼ Violation Reportããã©ã¦ã¶ã«ãã£ã¦ç´°ããæåã®å·®ç°ãããã CSP Lv.2 nonceã®ç»å ´ã¨èæ¯ CSPã®ç¹ã«unsafe-inlineã¯XSSã«å¯¾ãã¦æçµé²è¡ç·çã«å¼·åãªå¹æãããã ãããç¹ã«ãµã¼ãã¼ããã®å¤ã®åã渡ãé¨åãªã©ã§ã©ããã¦ãinline scriptã使ããããªãã¨ããããããunsafe-inlineãç¦æ¢ããã¨DOM dataçã使ããããå¾ããã¤ããæãã ã£ãã @kazuho ã§ããããã¨ãã£ã¦DOM dataãã¼ããã¨ããæãã§ã¯ãããã§ãããCSPã§inline scriptç¦æ¢ãã¡
HTTP ã¬ã¤ã HTTP ã®æ¦è¦ å ¸åç㪠HTTP ã»ãã·ã§ã³ HTTP ã¡ãã»ã¼ã¸ MIME ã¿ã¤ãï¼IANA ã¡ãã£ã¢ç¨®å¥ï¼ HTTP ã®å§ç¸® HTTP ãã£ãã·ã¥ HTTP èªè¨¼ HTTP Cookie ã®ä½¿ç¨ HTTP ã®ãªãã¤ã¬ã¯ã HTTP æ¡ä»¶ä»ããªã¯ã¨ã¹ã HTTP ç¯å²ãªã¯ã¨ã¹ã ã³ã³ãã³ããã´ã·ã¨ã¼ã·ã§ã³ HTTP/1.x ã®ã³ãã¯ã·ã§ã³ç®¡ç HTTP ã®é²å ãããã³ã«ã®ã¢ããã°ã¬ã¼ãã®ä»çµã¿ ãããã·ãµã¼ãã¼ã¨ãã³ããªã³ã° HTTP ã¯ã©ã¤ã¢ã³ããã³ã HTTP ã»ãã¥ãªã㣠ãµã¤ãã®å®å ¨å HTTP Observatory Permissions Policy ã³ã³ãã³ãã»ãã¥ãªãã£ããªã·ã¼ (CSP) ãªãªã¸ã³éãªã½ã¼ã¹å ±æ (CORS) Cross-Origin Resource Policy (CORP) Strict-Transport-Securit
#ssmjp 2014/10 XSSã®éç¨ã®è©± ééããªã©ããã¾ããã @yagihashoo ã¾ã§ã ## 10/28 9:26è¿½è¨ nonce-valueãè¦æ ¼ä¸ã¯Base64ã ãï¼ã¨ããææãããã ããã®ã§ã¹ã©ã¤ã18-19ãä¿®æ£ãã¾ããã 詳細ã¯ä»¥ä¸ãã覧ãã ããã http://www.w3.org/TR/CSP2/#source-list-valid-nonces ## 10/29 15:00è¿½è¨ Path matchingã®ä¾ç¤ºã«ã¤ãã¦ééãããã£ãããã¹ã©ã¤ã14ãä¿®æ£ãã¾ãããRead less
å¼ç¤¾ã®ãã¼ã ãã¼ã¸ã«CSP(Content Security Policy)ãå°å ¥ãã¾ãããCSPã«ã¤ãã¦ã¯ãã¯ãããããããæ°ã®ã¹ã©ã¤ãã5åã§ãããCSPããããããããã¨æãã¾ãã以ä¸ã«ã¹ã©ã¤ãã®ä¸é¨ãå¼ç¨ãã¾ãã å ·ä½çã«ã¯ã以ä¸ã®ããã«æå®ãã¦ä½¿ãã¾ãã Content-Security-Policy: default-src 'self' ãã®çµæã以ä¸ã®ããã«JavaScriptã®è¨è¿°ãå¶éããã¾ãã å¤é¨ã®JavaScriptã®èªã¿è¾¼ã¿ã¯ç¦æ¢ HTMLã½ã¼ã¹ã«è¨è¿°ãã<script>...</script>ã®JavaScriptã¯ç¦æ¢ ã¤ãã³ãå±æ§(onload="xxxx"ãªã©)ã¯ç¦æ¢ ä½ãæ¸ããªããªããããªããã¨æãããããããã¾ããããJavaScriptã¯å ¨ã¦*.jsãã¡ã¤ã«ã«è¨è¿°ããã°ãããã¨ãããã¨ã§ãã CSPã¯ãJavaScriptã®ã³ã¼ãã¨ãã¼ã¿ãåé¢ãã¦
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}