<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ename Hosting Blog &#187; httponly</title>
	<atom:link href="http://www.ename.ro/blog/tag/httponly/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ename.ro/blog</link>
	<description>Noutati despre hosting in general si serviciile oferite de Ename</description>
	<lastBuildDate>Fri, 16 Dec 2011 17:59:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>HttpOnly &#8211; in sfarsit, un plus de securitate</title>
		<link>http://www.ename.ro/blog/httponly-in-sfarsit-un-plus-de-securitate.html</link>
		<comments>http://www.ename.ro/blog/httponly-in-sfarsit-un-plus-de-securitate.html#comments</comments>
		<pubDate>Wed, 28 Jan 2009 00:31:55 +0000</pubDate>
		<dc:creator>dt</dc:creator>
				<category><![CDATA[Securitate]]></category>
		<category><![CDATA[ajax]]></category>
		<category><![CDATA[httponly]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.ename.ro/blog/?p=97</guid>
		<description><![CDATA[Una din metodele folosite de &#8220;baietii rai&#8221; pentru a sparge conturi se bazeaza pe injectarea de cod JavaScript in paginile atacate (XSS) si culegerea unor date private (cum ar fi identificatorul de sesiune stocat in cookie). In 2006 Microsoft a inventat httpOnly, un cuvant trimis in header care specifica faptul ca un cookie setat de [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Una din metodele folosite de &#8220;baietii rai&#8221; pentru a sparge conturi se bazeaza pe injectarea de cod JavaScript in paginile atacate (XSS) si culegerea unor date private (cum ar fi identificatorul de sesiune stocat in cookie).</p>
<p style="text-align: justify;">In 2006 Microsoft a inventat <em>httpOnly</em>, un cuvant trimis in header care specifica faptul ca un cookie setat de server nu poate fi accesat din JavaScript sau alte scripturi care ruleaza in browser. Ideea, foarte buna de altfel, a fost implementata in IE6 SP1 si ulterior in FireFox 2.</p>
<p style="text-align: justify;">Totusi a aparut repede o problema: <span id="more-97"></span><em>Ajax</em>, la moda in ultima vreme, mai exact <em>XmlHttpRequest</em>, permitea trimiterea unei cereri catre server si prelucrarea headerelor returnate, inclusiv a cookie-urilor, in cazul in care erau setate in mod repetat de server (si se pare ca in PHP ar fi comportamentul implicit). In felul acesta, toata protectia introdusa de <em>httpOnly</em> era compromisa. Rezolvarea a venit in decembrie 2008 pentru Internet Explorer si luna asta pentru Firefox (testat pe versiunea 3.1 beta) Ambele browsere au eliminat posibilitatea de a citi cookie-urile setate cu <em>httpOnly</em> din <em>XmlHttpRequest</em>. Probabil, in cateva luni, multi vor face upgrade la browsere si internetul va deveni un loc mai sigur <img src='http://www.ename.ro/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Doar pana cand se vor inmulti atacurile bazate pe Flash (care ofera tot timpul posibilitati nebanuite).</p>
<p style="text-align: justify;">O simpla linie de cod PHP poate proteja aplicatia de atacuri XSS:</p>
<pre class="code">ini_set("session.cookie_httponly", 1); </pre>
<p style="text-align: justify;">Referinte:</p>
<ul style="text-align: justify;">
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=380418">https://bugzilla.mozilla.org</a></li>
<li><a href="http://ha.ckers.org/blog/20070719/firefox-implements-httponly-and-is-vulnerable-to-xmlhttprequest/">http://ha.ckers.org/blog</a></li>
<li><a href="http://www.owasp.org/index.php/HTTPOnly">http://www.owasp.org</a></li>
<li><a href="http://www.microsoft.com/technet/security/bulletin/ms08-069.mspx">http://www.microsoft.com/technet/security/</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.ename.ro/blog/httponly-in-sfarsit-un-plus-de-securitate.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

