1åã§ããããX-ãã³ãã«ãHTTPã¬ã¹ãã³ã¹ããã
æè¿ã®ã¢ãã³ãªWebãã©ã¦ã¶ããµãã¼ããã¦ãããã»ãã¥ãªãã£ã«é¢é£ããã㪠X- ãªHTTPã¬ã¹ãã³ã¹ããããã¾ã¨ãã¦ã¿ã¾ããããã以å¤ã«ããã£ããæãã¦ãã ããã
|
0:XSSãã£ã«ã¿ãç¡å¹ã«ããã 1:XSSãã£ã«ã¿ãæå¹ã«ããã XSSãã£ã«ã¿ãæå¹ã«ãããã¨ã§ã¨ã³ãã¦ã¼ã¶ãXSSã®è¢«å®³ã«ããå¯è½æ§ãä½æ¸ããããã¾ãã«èª¤æ¤ç¥ãããã¨ã§ç»é¢ã®è¡¨ç¤ºãä¹±ãããã¨ããããIE8+ãSafariãChrome(å¤å) ã§æå¹ãIEã§ã¯ãX-XSS-Protection: 1; mode=blockãã¨ããæå®ãå¯è½ã |
---|---|
|
nosniff ãæå®ããå ´åã«ã¯ãIE8+ã«ããã¦ã³ã³ãã³ãã®å
容ãããã¡ã¤ã«ã¿ã¤ããæ¨æ¸¬ããåä½ããªããªããéHTMLãHTMLæ±ãããããã¨ã«ãã£ã¦çºçããXSSã®é²å¾¡ã«æå¹ã |
ã³ã³ãã³ããä»ã®ãã¬ã¼ã å
ã§è¡¨ç¤ºå¯è½ãã©ãããæå®ãã¯ãªãã¯ã¸ã£ãã¯å¯¾çã«æå¹ãDENY ãæå®ããã¨å¤é¨ãããã¬ã¼ã ã«åãè¾¼ãã§ã³ã³ãã³ãã表示ãããã¨ã¯ã§ããªããªããSAMEORIGIN ãæå®ããã¨åããã¡ã¤ã³ã®ã¨ãã®ã¿ãã¬ã¼ã å
ã«åãè¾¼ãã§ã³ã³ãã³ãã表示ãããã¨ãã§ãããIE8+ãChromeãSafariãOperaãFirefoxã®åãã©ã¦ã¶ã§å¯¾å¿ãã¦ããã |
|
|
IE8+ã«ããã¦ãã©ã¦ã¶ã®ããã¥ã¡ã³ãã¢ã¼ããæå®ãããGoogle Chrome Frame ã使ç¨ãã¦ããå ´åã«ã¯ X-UA-Compatible: chrome=1 ã¨æå®ãããã¨ã§IEå
ã§Google Chrome Frameã使ã£ã¦ã³ã³ãã³ãã表示ããããã¨ãã§ããã |
|
Firefox 4+ã§æå¹ãContent Security Policy ãæå¹ã«ããã(ãã®ãã¡ãã¡ãã¨æ¸ãããâ¦) |
ã¨ããããã»ã¨ãã©ãIE8以éã«Microsoftãå°å ¥ãªãã ãããMicrosoftã¯ãã¡ãã¨æ´çãã¦ææ¸ã«ã¾ã¨ãã¦æ¬²ããã