æè¿ã®ã¢ãã³ãªWebãã©ã¦ã¶ããµãã¼ããã¦ãããã»ãã¥ãªãã£ã«é¢é£ããã㪠X- ãªHTTPã¬ã¹ãã³ã¹ããããã¾ã¨ãã¦ã¿ã¾ããããã以å¤ã«ããã£ããæãã¦ãã ããã X-XSS-Protection 0:XSSãã£ã«ã¿ãç¡å¹ã«ããã 1:XSSãã£ã«ã¿ãæå¹ã«ããã XSSãã£ã«ã¿ãæå¹ã«ãããã¨ã§ã¨ã³ãã¦ã¼ã¶ãXSSã®è¢«å®³ã«ããå¯è½æ§ãä½æ¸ããããã¾ãã«èª¤æ¤ç¥ãããã¨ã§ç»é¢ã®è¡¨ç¤ºãä¹±ãããã¨ããããIE8+ãSafariãChrome(å¤å) ã§æå¹ãIEã§ã¯ãX-XSS-Protection: 1; mode=blockãã¨ããæå®ãå¯è½ã 2008/7/2 - IE8 Security Part IV: The XSS FilterBug 27312 â [XSSAuditor] Add support for header X-XSS-Protection X-Content-Ty
Erlangã«ããWebãµã¼ãã¼ã¨ããã°ãYAWSã¨ããã®ãæåãããã§ãããããã£ã¨åå§çãªä»å±ã©ã¤ãã©ãªã»ã¢ã¸ã¥ã¼ã«httpdã使ã£ã¦ã¿ã¾ããã 解説ææ¸ãï¼ããããç¥ããªããã©ï¼è¦ã¤ãããªãã£ãã®ã§ãmanãã¼ã¸ã¨ã½ã¼ã¹ãæ¾ãèªã¿ã man httpd -- http://www.erlang.org/doc/man/httpd.html man httpd_conf -- http://www.erlang.org/doc/man/httpd_conf.html ã½ã¼ã¹ otp_src_R11B-4/lib/inets/src/http_server/*.erl [è¿½è¨ date="2007-06-29"]ä»ã¾ã§è¦è½ã¨ãã¦ããã®ã§ãããERLANG_HOMEãErlangãç½®ãããã£ã¬ã¯ããªãVSNããã¼ã¸ã§ã³ã¨ã㦠$ERLANG_HOME/lib/inets-$VSN/exam
Firefox2ã§ãhttponlyã使ããã¨ãã話ãè³ã«ãã¾ããã httpOnly - Firefox Add-ons*1 httponlyãããããæ®åãããï¼ ã¨ããã®ã§ãã¿ã«ãã¦ã¿ã¾ãã ãªãããã®æ¥è¨ã¯ãWinXPï¼IE6SP2ç°å¢ãåæã¨ãã¦æ¸ãã¾ããã ã¯ããã« httponlyã¯ãXSSèå¼±æ§ãããç¶æ³ã«ããã¦ããcookieãçªåãããªãããã«ãããã¨ãçã£ãIEã®ç¬èªæ©è½ã§ãã MSDN - Mitigating Cross-site Scripting With HTTP-only Cookies ãã®æ©è½ãæå¹ã«ããããã«ã¯ãçºè¡ããcookieã«httponlyå±æ§ãä»ãã¾ãã Set-Cookie: key=value; domain=example.com; HttpOnly httponlyå±æ§ãä»ããããcookieã¯ãJavaScriptã®docume
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}