Chuyển đến nội dung chính

Introduction to Content Security for Beginners

[ad_1]

Browsers: What do they have in common (except maybe for being the "internet button")? They can not distinguish malicious content from benign. As this flaw had to be tackled, content security was introduced.

What causes content to become malicious?

Much of this malicious content can either be cross-site scripting (XSS) or clickjacking. Clickjacking, as the term suggests, is a form of hiding a hyperlink in another website's clickable content. This way, the user is lured to actions he is unaware of, makes clicks he never intended and potentially reveals valuable or even confidential information to the attacker.

Cross-site scripting on the other hand, can prove a lot more dangerous as it accounts for 84% of security issues. Cross-site scripting falls into the category of code injection, as the malicious person embeds content in the website and accesses all information under the umbrella of the legitimate site.

These two institute the most common attackers of a website bypassing the same origin policy. This policy is an important security aspect of the web world, as its mechanism is that it links two web pages only if they share the same origin. In practice, that means that if someone injects malicious content in one web page it can not access another page's information.

What can I do as a beginner?

This model ensures data confidentiality as the website owner provides secure, trusted, and whitelisted sources of content and covers a wide array of types such as HTML5, JavaScript, CSS, images, audio files, and many others. The Content Security Policy standard allows owners to predefine the content of their website whether it 'd be inline scripts, or resources. Each page can have a standard security policy in order to minimize the damage in such cases where an attacker has already infected malicious content. For example, there are many ways the owner can specify which content is safe and which one can load in each page without problems. The most usual among those are:

1) Trust only scripts from the same source via HTTPS

2) Images loaded should come from a particular CDN

3) Frames or inline scripts should not be allowed

4) Only allow fonts from Google Fonts

Content security policy standard was first introduced in 2004 and has evolved accordingly ever since, with the majority of browsers complying with it. It is a "must-have" tool particularly for online businesses that implement user accounts such as e-shops, banks or social media.


[ad_2]

Nhận xét

Bài đăng phổ biến từ blog này

DIY AT HOME - Home Projects +++

[ad_1] Are you a Home Projects kind of guy ... or not? Owning a home means having something to do, fix, repair, renovate, and create and more. In order to ensure that all these jobs get done effectively (and improve the value of your home) it is very important that you learn DIY (do it yourself) and become competent .. Dependent on your degree of profitability home projects can surely save you plenty of money. DIY is a learning process and a little help can often be just what you need to become a "Pro" Everyone needs a "pat on the back" now and again. The successful completion of home projects will obviously instill a sense of pride but better still will have your better half acknowledge your success with pride. I find that outdoor home projects such as building a storage shed may also have the neighbors green with envy. There are many home projects that enhance the value of a home, one of the most important being building a wooden deck. By utilizing the best p...

DIY AT HOME - Business Sales Close Plan - Milestones to Close the Deal***

[ad_1] Being with my feet on the sales ground for 25 years in IT, I can recommend that many steps in the sales process need to be discussed and agreed internally and with the business customer to come to an agreed and signed contract. Following this sales process through a so called 'Sales Close Plan', describes all the necessary milestones that need to be agreed from a resource perspective, internally from a supplier perspective as well as from the business customer resource perspective. This Sales Close Plan will enable you to set upfront the right expectations during the contract negotiation milestones during an enterprise sales process. Discuss with your business customer the close plan and have your customer sign/off the Sales Close Plan on timescales and milestones. If each milestone is finalized confirm this in email to your customer so all expectations and potential road blocks keeps transparent and visible to you as supplier and business customer. 1. Identify the Power...

Wrist Watch Camera DRONE!! Awesome Foldable Nano FPV Drone Review

Wrist watch drone Link - https://goo.gl/U6DQX6 Gearbest August Sale - https://goo.gl/m441qf DJI Phantom 3 Huge Discount - https://goo.gl/JMbRvg ( Coupon Code - DJI3seGB ) DJI Spark Huge Discount - https://goo.gl/gSG5fS ( Coupon code - Spark20 ) Da Heng DH 800 Nano FPV foldable wrist watch camera drone unboxing and review India 2017 | Awesome Foldable nano fpv drone 2017 | Best budget camera drone 2017 | Smallest foldable drone with camera 2017 Thanks for watching my video,hit the thumbs up if you liked it and SUBSCRIBE to my channel for more Awesome content. Don't forget to checkout my other videos. Follow Me On ~ https://twitter.com/Vimal_TRHD https://www.facebook.com/TechReviewHD/ http://google.com/+ VimalChintapatlaTR https://instagram.com/vimal_chintapatla/ Music~Cold Funk - Funkorama by Kevin MacLeod is licensed under a Creative Commons Attribution license ( https://creativecommons.org/licenses/by/4.0/) Source: http://incompetech.com/music/royalty-free/index.html?isrc=USUAN1...