- 3
- 0
- 约9.35千字
- 约 29页
- 2017-08-11 发布于浙江
- 举报
10-cookie-security.ppt
FF3: most specific cookie sent first * SOP: same as server-side read/write * RFC 2109 (cookie RFC) has an option for including domain, path in Cookie header, but not supported by browsers. * Both LSID and GAUSR are “secure” cookies; Alice visits automatically due to phishing filter * * * * * All these shopping carts stored data on browser non-keyed checksums (e.g. CRC) are sufficient for this purpose !! * * FF2, Chrome: HttpOnly cookie can be overwritten to by script (but cannot be read) 3rd party cookies often used for session management. Consider . It is a 1st party when accessing from but a 3rd party when accessing from yahoo.co.uk * 3rd party becomes first party by doing: Set document.local = “3rd party address”, Set cookie Set document.location back to original value (obtained from the referer header) * Cookie Same Origin Policy Dan Boneh CS 142 Winter 2009 Monday: session management using cookies Same origin policy: “high level” Review: Same Origin Policy (SOP) for DOM: Origin A can access origin B’s DOM if match on (scheme, domain, port) Today: Same Original Policy (SOP) for cookies: Generally speaking, based on: ([scheme], domain, path) optional scheme://domain:port/path?params scope Setting/deleting cookies by server Delete cookie by setting “expires” to date in past Default scope is domain and path of setting URL Browser Server GET … HTTP Header: Set-cookie: NAME=VALUE ; domain = (when to send) ; path = (when to send) secure = (only send over SSL); expires = (when expires) ; HttpOnly (later) if expires=NULL: this session only Scope setting rules (write SOP) domain: any domain-suffix of URL-hostname, except TLD example: host = “” ? can set cookies for all of . but not for another site or TLD Problematic for sites like . path: can be set to anything allowed domains . disallowed domains .com Cookies are identified by (name,domain,path) Both cookies stored in browser’s
您可能关注的文档
- 1. 六一儿童节,王老师为小朋友购买演出用的服装,买3件T恤和5件短裤....doc
- 1. 项目协调手册.doc
- 1.1 Definition of the Problem. 1.2 Technical Objectives and Research Challenges. 1.2.1 Scop.pdf
- 1.1 Exact Security of Signature Schemes.pdf
- 1.1 新手上路:自己的第一个数据透视表.xls
- 1.1. Contextual Information.pdf
- 1.2 intro.ppt
- 1.2Strategic planning.ppt
- 1.2《时间和位移》(人教版)高一物理必修一PPT课件.ppt
- 1.2《时间和位移》PPT课件(人教版必修1).ppt
- 九年级道德与法治《民事权利的宣言书:初识民法》教学设计.docx
- 第三章空气和氧气 九年级科学提升课.pptx
- 探索自我认识自己的意义与方法.pptx
- 走向真实情境的深度探究:初中地理《巴西》教学设计.docx
- 基于生命观念的系统构建:人体生命活动的调节专题复习与分层提升.docx
- 八年级信息技术《公众号信息的收集、整理与复习应用》教学设计.docx
- 四年级上册英语(外研版)模块复习课(14模块):核心知识建构与综合应用能力提升.docx
- 五年级英语上册 Unit 1 Which Do You Like Better Lesson 3 基于比较选择的口语交际课教学设计.docx
- 基于问题情境与语用功能的小学英语教学设计——以外研版五年级下册Module 5 Unit 1 “It’s big and light.docx
- 九年级历史一轮复习大单元设计:经济大危机与第二次世界大战.docx
最近下载
- 供应商审核评分表.xls VIP
- 《水库大坝安全管理条例》(2024版)培训与解读课件.pptx
- 2025年中考无锡物理试题及答案.docx VIP
- 护理不良事件登记(报告)表,护理不良事件分析讨论记录.docx VIP
- 新能源汽车发动机选型趋势.docx VIP
- T∕CPHA 33-2024 通用码头和多用途码头绿色港口等级评价指南.pdf VIP
- GB50555-2010 民用建筑节水设计标准.pdf VIP
- 危险作业审批人员与监护人员安全知识考试题(附答案).docx VIP
- 幼小衔接数学《每日计算练习一》.pdf VIP
- TCFA0310021-2023 铸造企业规范条件.docx VIP
原创力文档

文档评论(0)