Cov ncuav qab zib puas ruaj ntseg https?
Cov ncuav qab zib puas ruaj ntseg https?

Video: Cov ncuav qab zib puas ruaj ntseg https?

Video: Cov ncuav qab zib puas ruaj ntseg https?
Video: leej twg tej ntxhai - Mang Vang [ Official MV ] 2024, Tej zaum
Anonim

ncuav qab zib xa mus rau hauv HTTP header. Yog li lawv zoo li ruaj ntseg raws li cov HTTPS kev sib txuas uas nyob ntawm ntau qhov SSL / TLS tsis zoo li lub zog cipher lossis qhov ntev ntawm tus yuam sij pej xeem. Thov nco ntsoov tias tshwj tsis yog koj teeb tsa ruaj ntseg chij rau koj ncuav qab zib , cov ncuav qab zib tuaj yeem kis tau los ntawm kev sib txuas HTTP tsis ruaj ntseg.

Kuj kom paub yog, yog cov ncuav qab zib encrypted hauv

Cov ntaub ntawv xa mus rau SSL ( HTTPS ) yog tag nrho encrypted , headers suav nrog (li no ncuav qab zib ), tsuas yog tus tswv uas koj tab tom xa daim ntawv thov tsis yog encrypted . Nws kuj txhais tau hais tias qhov kev thov GET yog encrypted (lwm tus URL).

Tsis tas li ntawd, JavaScript puas tuaj yeem nyeem cov ncuav qab zib ruaj ntseg? Tag nrho cov ntsiab lus ntawm HttpOnly ncuav qab zib yog lawv ua tau tsis nkag los ntawm JavaScript . Tib txoj kev (tshwj tsis yog siv cov kab mob browser) rau koj cov ntawv rau nyeem lawv yog kom muaj cov ntawv sib koom tes ntawm lub server uas yuav nyeem tus ncuav qab zib tus nqi thiab ncha nws rov qab los ua ib feem ntawm cov ntsiab lus teb.

Ib tug kuj yuav nug, cov ncuav qab zib puas ruaj ntseg?

Ruaj ntseg ncuav qab zib yog hom HTTP ncuav qab zib uas muaj ruaj ntseg attribute set, uas txwv lub Scope ntawm lub ncuav qab zib rau " ruaj ntseg "channels (qhov twg" ruaj ntseg " yog txhais los ntawm tus neeg siv tus neeg sawv cev, feem ntau web browser). Ruaj ntseg ncuav qab zib los ntawm ib qho chaw tsis ruaj ntseg, cuam tshuam lawv txoj kev ncaj ncees.

HttpOnly yog dab tsi thiab ruaj ntseg chij?

HttpOnly thiab ruaj ntseg chij tuaj yeem siv los ua cov ncuav qab zib ntau dua ruaj ntseg . Thaum a ruaj ntseg chij yog siv, ces cov ncuav qab zib tsuas yog xa mus rau HTTPS, uas yog HTTP tshaj SSL / TLS. Thaum twg HttpOnly chij yog siv, JavaScript yuav tsis muaj peev xwm nyeem cov ncuav qab zib nyob rau hauv cov ntaub ntawv ntawm XSS exploitation.

Pom zoo: