English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210184
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÄíÅ°°¡ HttpOnly Ç÷¡±×¾øÀÌ ¼³Á¤µÇ¾ú½À´Ï´Ù. Áï, JavaScript·Î ÄíÅ°¿¡ ¾×¼¼½º ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÆäÀÌÁö¿¡¼­ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼ö ÀÖÀ¸¸é ÄíÅ°¿¡ ¾×¼¼½ºÇÏ¿© ´Ù¸¥ »çÀÌÆ®·Î Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀÌ ¼¼¼Ç ÄíÅ° ÀÎ °æ¿ì ¼¼¼Ç ÇÏÀÌÀçÅ·ÀÌ °¡´ÉÇÒ ¼ö ÀÖ½À´Ï´Ù.

* Âü°í »çÀÌÆ®:
https://www.owasp.org/index.php/HttpOnly

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Any operating system Any version
ÇØ°áÃ¥ *Java
Servlet 3.0 (Java EE 6)Àº ¼¼¼Ç ÄíÅ°ÀÇ º¸¾È ¼Ó¼ºÀ» ±¸¼ºÇϴ ǥÁØ ¹æ¹ýÀ» µµÀÔÇß½À´Ï´Ù. ÀÌ´Â web.xml¿¡ ´ÙÀ½ ±¸¼ºÀ» Àû¿ëÇÏ¿© ¼öÇà ÇÒ ¼ö ÀÖ½À´Ï´Ù.

[web.xml]
<session-config>
<cookie-config>
<http-only>true</http-only>
</cookie-config>
</session-config>


*Tomcat
Tomcat 6 context.xml¿¡¼­ ÄÁÅؽºÆ® ű×ÀÇ ¼Ó¼º useHttpOnly ¸¦ ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇϽʽÿÀ.

<?xml version="1.0" encoding="UTF-8"?>
<Context path="/myWebApplicationPath" useHttpOnly="true">

*PHP
PHP°¡ °ü¸®ÇÏ´Â ¼¼¼Ç ÄíÅ°ÀÇ °æ¿ì HttpOnly Ç÷¡±×´Â ´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ÅëÇØ ¿µ±¸ÀûÀ¸·Î ¼³Á¤µË´Ï´Ù.

session.cookie_httponly = True
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)