Ãë¾àÁ¡ID |
210184 |
À§Çèµµ |
20 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÄíÅ°°¡ HttpOnly Ç÷¡±×¾øÀÌ ¼³Á¤µÇ¾ú½À´Ï´Ù. Áï, JavaScript·Î ÄíÅ°¿¡ ¾×¼¼½º ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ÆäÀÌÁö¿¡¼ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÒ ¼ö ÀÖÀ¸¸é ÄíÅ°¿¡ ¾×¼¼½ºÇÏ¿© ´Ù¸¥ »çÀÌÆ®·Î Àü¼ÛÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ°ÍÀÌ ¼¼¼Ç ÄíÅ° ÀÎ °æ¿ì ¼¼¼Ç ÇÏÀÌÀçÅ·ÀÌ °¡´ÉÇÒ ¼ö ÀÖ½À´Ï´Ù.
* Âü°í »çÀÌÆ®: https://www.owasp.org/index.php/HttpOnly
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Any operating system Any version |
ÇØ°áÃ¥ |
*Java Servlet 3.0 (Java EE 6)Àº ¼¼¼Ç ÄíÅ°ÀÇ º¸¾È ¼Ó¼ºÀ» ±¸¼ºÇϴ ǥÁØ ¹æ¹ýÀ» µµÀÔÇß½À´Ï´Ù. ÀÌ´Â web.xml¿¡ ´ÙÀ½ ±¸¼ºÀ» Àû¿ëÇÏ¿© ¼öÇà ÇÒ ¼ö ÀÖ½À´Ï´Ù.
[web.xml] <session-config> <cookie-config> <http-only>true</http-only> </cookie-config> </session-config>
*Tomcat Tomcat 6 context.xml¿¡¼ ÄÁÅؽºÆ® ű×ÀÇ ¼Ó¼º useHttpOnly ¸¦ ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇϽʽÿÀ.
<?xml version="1.0" encoding="UTF-8"?> <Context path="/myWebApplicationPath" useHttpOnly="true">
*PHP PHP°¡ °ü¸®ÇÏ´Â ¼¼¼Ç ÄíÅ°ÀÇ °æ¿ì HttpOnly Ç÷¡±×´Â ´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ÅëÇØ ¿µ±¸ÀûÀ¸·Î ¼³Á¤µË´Ï´Ù.
session.cookie_httponly = True |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|