Ãë¾àÁ¡ID |
210184 |
À§Çèµµ |
20 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
Äí۰¡ HttpOnly Ç÷¡±×¾øÀÌ ¼³Á¤µÇ¾ú½À´Ï´Ù. Áï, JavaScript·Î ÄíŰ¿¡ ¾×¼¼½º ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÆäÀÌÁö¿¡¼ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼ö ÀÖÀ¸¸é ÄíŰ¿¡ ¾×¼¼½ºÇÏ¿© ´Ù¸¥ »çÀÌÆ®·Î Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. À̰ÍÀÌ ¼¼¼Ç ÄíŰ ÀÎ °æ¿ì ¼¼¼Ç ÇÏÀÌÀçÅ·ÀÌ °¡´ÉÇÒ ¼ö ÀÖ½À´Ï´Ù.
* Âü°í »çÀÌÆ®: https://www.owasp.org/index.php/HttpOnly
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Any operating system Any version |
ÇØ°áÃ¥ |
*Java Servlet 3.0 (Java EE 6)Àº ¼¼¼Ç ÄíŰÀÇ º¸¾È ¼Ó¼ºÀ» ±¸¼ºÇϴ ǥÁØ ¹æ¹ýÀ» µµÀÔÇß½À´Ï´Ù. ÀÌ´Â web.xml¿¡ ´ÙÀ½ ±¸¼ºÀ» Àû¿ëÇÏ¿© ¼öÇà ÇÒ ¼ö ÀÖ½À´Ï´Ù.
[web.xml] <session-config> <cookie-config> <http-only>true</http-only> </cookie-config> </session-config>
*Tomcat Tomcat 6 context.xml¿¡¼ ÄÁÅØ½ºÆ® ű×ÀÇ ¼Ó¼º useHttpOnly ¸¦ ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇϽʽÿÀ.
<?xml version="1.0" encoding="UTF-8"?> <Context path="/myWebApplicationPath" useHttpOnly="true">
*PHP PHP°¡ °ü¸®ÇÏ´Â ¼¼¼Ç ÄíŰÀÇ °æ¿ì HttpOnly Ç÷¡±×´Â ´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ÅëÇØ ¿µ±¸ÀûÀ¸·Î ¼³Á¤µË´Ï´Ù.
session.cookie_httponly = True |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|