Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Web Security
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Hooopo
November 29, 2012
Programming
230
4
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Web Security
Web Security
Hooopo
November 29, 2012
More Decks by Hooopo
See All by Hooopo
test
hooopo
2
120
Other Decks in Programming
See All in Programming
in-process GraphQL のすすめ #ginzajs
izumin5210
4
1.5k
プロポーザルを書いてもらう
pvcresin
0
580
言葉の格闘技のススメ~紙とペンと言葉から始める、キャリアの描き方~
progresscicada
2
180
AI時代に学ぶ 好きなルール 嫌いなルール Linter編
shorty5121
0
190
Loosening the Reins: Go Generics Get More Flexible
kuro_kurorrr
0
340
【デモ】Kiroで体験する仕様駆動開発|設計からコーディングまでAIと進める開発フロー
cmkudo
0
460
楽しそうなつよつよエンジニアと目が死んでる僕/A brilliant engineer having a blast, and dead-eyed me.
3l4l5
2
260
Japan Community Day at Kubecon + CloudNativeCon Japan 2026: Learning Container Privilege Control by Building My Own Low-Level Container Runtime
ternbusty
1
170
複数の Claude Code が"放置"されてしまう問題をCLI ダッシュボードを自作して解決した話
sumihiro3
1
740
リアルな遅延を測る仕様
kota_yata
1
130
ALB ログから Trace を気合で繋げる技術
fohte
6
730
「人を評価する AI」の設計と実装
ryoyanara
0
250
Featured
See All Featured
The Illustrated Children's Guide to Kubernetes
chrisshort
51
53k
A designer walks into a library…
pauljervisheath
211
24k
My Coaching Mixtape
mlcsv
0
290
svc-hook: hooking system calls on ARM64 by binary rewriting
retrage
2
530
Fireside Chat
paigeccino
42
4k
B2B Lead Gen: Tactics, Traps & Triumph
marketingsoph
0
220
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
Build your cross-platform service in a week with App Engine
jlugia
234
19k
Making Projects Easy
brettharned
120
6.7k
Statistics for Hackers
jakevdp
799
230k
Conquering PDFs: document understanding beyond plain text
inesmontani
PRO
4
3k
Leo the Paperboy
mayatellez
8
2.2k
Transcript
Web Security
Same Origin Policy 同源策略
同源 • 协议相同 • 域名相同 • 端口相同
同源策略的内容 限制来自不同源的“document”或脚本, 对当前“document”读取或设置某些属 性
浏览器沙箱 • XMLHttpRequest和CURL发起请求有 什么不同? • 同源策略保护当前域还是被请求域? • SRC属性加载外部资源违背同源策略 么? •
第三方Cookie和会话Cookie
如何绕过同源策略 • document.domain = "csdn.net" • Flash的crossdomain.xml • JSONP解决跨域发送请求,带来的问 题?
• P3P解决跨域共享Cookie,带来的问 题?
Cross Site Scriping 跨站脚本攻击
XSS的分类 • 反射型 • 持久型
XSS攻击方式 • Cookie劫持 • XSS钓鱼(诱骗密码) • XSS蠕虫
对抗XSS • HTTP Only Cookie • IE8 XSS Filter •
Firefox的CSP(Content Security Policy) • IE8的X-Content-Type-Options: nosniff
IE8 XSS Filter • X-XSS-Protection: 1; mode=block
Firefox CSP • X-Content-Security-Policy: allow 'self' *.mydomain.com • X-Content-Security-Policy: allow
'self' img-src *;media-src medial. com script-src script.com
Firefox CSP XSS Filter • reflected-xss allow is equivalent to
X- XSS-Protection: 0 • reflected-xss filter is equivalent to X-XSS- Protection: 1 • reflected-xss block is equivalent to X- XSS-Protection: 1; mode=block
Auto HTML Escape能否彻底防御XSS?
Cross Site Request Forgery 跨站伪造请求
CSRF的原理 • 以用户的身份(Cookie)伪造请求
CSRF的危害 • 伪造普通用户的请求 • 伪造管理员的请求 • CSRF蠕虫
使用Post请求能否彻底防御 CSRF?
Referer检测能否正确防御 CSRF? • Flash某些版本可以自定义referer • 页面从HTTPS跳转到HTTP(RFC-2616) • Firefox中有相应参数可以设置是否发送HTTP Referer
CSRF的本质 • 所有请求参数都可以被攻击者猜到
正确的防御CSRF方法 • 不可预测原则 • one csrf token per session •
one csrf token per user
JSONP Hijacking JSONP 劫持
JSONP劫持本质是CSRF
点击劫持(Clickjacking)
点击劫持的防御 • FrameBusting:HTML5 iframe sandbox属性 和IE iframe security属性 • IE8+的
X-Frame-Options: DENY/SAMEORIGIN/Allow-From • Firefox的CSP
图片覆盖攻击(Cross Site Image Overlaying)
P3P头的副作用 IE默认禁止img,iframe,script,link等 标签发送第三方cookie,开启P3P之后会 允许发送第三方cookie
开源软件和CVE • Semantic Versioning
Refs • http://recxltd.blogspot.co.uk/2012/03/seven-web-server-http-headers-that.html • https://blog.whitehatsec.com/x-frame-options/ • http://blogs.msdn.com/b/ie/archive/2008/07/02/ie8-security-part-iv-the-xss-filter.aspx • http://homakov.blogspot.com/2012/06/saferweb-with-new-features-come-new.html •
http://msdn.microsoft.com/en-us/library/ie/gg622941(v=vs.85).aspx • https://www.owasp.org/index.php/HttpOnly • http://guides.rubyonrails.org/security.html#session-hijacking • http://en.wikipedia.org/wiki/HTTP_cookie#Secure_and_HttpOnly • http://rubylution.herokuapp.com/topics/32 • https://www.owasp.org/index.php/Clickjacking • http://blogs.msdn.com/b/ie/archive/2010/10/26/mime-handling-changes-in-internet- explorer.aspx • http://hi.baidu.com/aullik5/item/da5f5fec1a78c9d5ea34c9f8 • http://seclab.stanford.edu/websec/framebusting/framebust.pdf • http://book.douban.com/subject/10546925/ • http://hi.baidu.com/sysdog/item/4b44b7dd892d9655d63aaeb5 • http://semver.org/