10—cookie—security.pptVIP

  • 0
  • 0
  • 约小于1千字
  • 约 29页
  • 2017-04-19 发布于四川
  • 举报
10—cookie—security

Cookie Same Origin Policy;;;Scope setting rules (write SOP);Cookies are identified by (name,domain,path);Reading cookies on server (read SOP);Examples;Client side read/write: document.cookie;javascript: alert(document.cookie);Viewing/deleting cookies in Browser UI;Cookie protocol problems;Example 1: login server problems;Example 2: “secure” cookies are not secure;Interaction with the DOM SOP;Cookies have no integrity !!;Storing security data on browser?;*;Solution: cryptographic checksums;*;Cookie theft: basic cross site scripting (XSS);Example: reflected XSS;;*;HttpOnly Coo

文档评论(0)

1亿VIP精品文档

相关文档