,,,
:
:
. -220
. .
, , . , , - .
, , , . -, . , , , web-, , " " . -,
, ICQ. , . , - , ( , )
.
,
?
, , ,
, .
, ,- .
.
" " ,
.
,
.
Windows 95 98. .
.
Windows 9 - . , , " ". , . , . ,
. , , .
, .
, , , - . - . - , (,
, ). , . , . , , , . - - , ,
,
. , ( ), -. - , : , , .
,
. Microsoft Internet Explorer, Microsoft Outlook Express Outlook Microsoft Office .
, web-. , , ( Windows NT, 2000 , , ). , , .
?
- .
. - , , .
. ,
. ActiveX, HTML- , , (, Media Player). , Microsoft
- . ,
, . -
, , - . , . , Java,
ActiveX, cookie, , .
...
firewall - , .
firewall , . , - , . Firewall ,
(, ). firewall web-: ActiveX, (JavaScript, Visual Basic), Java-.
, ,
firewall
-
.
. , , , , . , (Nimda, Sircam). . . ,
, , , . , . . , , - . Microsoft ( )
(http://windowsupdate.microsoft.com). , (Internet Explorer, COM+), , " " (Service Pack), . RollUp Package, , Service Pack . , ,
, , .
, , , . , , . , . , , . ,
firewall , . . ,
: Russian Security News-line (http://bugtraq.ru/rsn), SECURITY.NNOV (http://www.security.nnov.ru/), CERT Coordination Center (http://www.cert.org).
www.cert.org -
!
. , . , , . , . . , , , , . . , , .
Microsoft ,
, . - - . , , - , Microsoft Microsoft Baseline Security Analyzer. , , , -
, . . , MBSA , . . MBSA 1.0 Finjan Malicious
Code Research Center , XML
. , , , . , , , HTML-. .
?
- . , , . , , , , . , , , . .
, . , IRC ( I-Worm.LoveLetter, ILOVEYOU), Microsoft - Internet Information Server, ( , , Nimda).
( , ). - BadtransII
, LOG- . - Nimda "" . ,
, . , , , .
, WWW - , . , - - , . , , .
, , , www- , .
, - . (. www-). , , , EXE-, MS Office .
- web-. HTML- Javascript, , Java, ActiveX ( MS Windows).
, . , Java- (sandbox), . Javascript , Javascript .
""
, . , .
web- Javascript. , :
<html>
<head><title>Example of DoS </title></head>
<body>
<script>
while(1) {
alert(It is time to restart your browser.);
}
</script>
</body>
</html>
- ,
.
- ,
(). ,
- .
URL,
, - . :
<a href=http://www.cracker.com/
onMouseover=http://www.goodbank.com/;
return true>
Click here to enter your credit number</a>
, , , www.goodbank.com, , , www.cracker.com. www.cracker.com.
Javascript . - , - . , , Javascript . , .
, - WWW-, Javascript HTML- . cross-site scripting , . , WWW- , . , . , , <script> , , .
cross-site scripting
. ,
:
<A HREF=http:/example.com/comment.cgi?mycomment=
<SCRIPT> </SCRIPT>>Click here</A>
WWW- example.com, , .
Cross-site scripting SSL
cross-site scripting , SSL. , WWW-, , , , .
cross-site scripting .
. , ( ActiveX, Java Javascript) . , . , , , , , . , , , .
Java, ActiveX Javascript, .
, HTTP- . , , WWW- . Digest- ( ) - . .
, , www-, , IP- , URL , ( ), URL , . -, WWW .
, GET, LOG-, URL-. POST , .
, ( , - history). ( ).
www- (, -) cookies (, , ). , ( - , cookies). cookies WWW. cookies, .
- SSL
, -, SSL ( - TLS).
SSL TCP/IP (TCP) . SSL (, , ) . HTTP , , HTTP- .
SSL, HTTP- , SSL ( ). URL , SSL, "https://". HTTP- () SSL-. , "" . , . , VeriSign. , , .
, ( , . .).
SSL -
SSL -. HTTP- , . - HTTP-. CONNECT HTTP-.
CONNECT -, TCP- , . , - CONNECT, , 443, HTTP SSL.
- -
- HTTP- , .
, WWW - . , HTTP-, - . HTTP- , 80, - (80-86, 8000-8006, 8080-8086, 8888).
-
( ):
- , . - IP-, -.
- WWW-, Proxy-Authorization. -, , 407 Proxy Authentication Required Proxy-Authenticate, WWW-Authenticate. Digest Proxy-Authentication-Info.
, www- - HTTP- - , . (Authorization Proxy-Authorization) , .
, , ( ). , Basic Ethernet - , Digest.
, , WWW , . - .
WWW - , HTTP.
HTTP : () . TCP HTTP- - 80. URL - (), , .
, , URL, . . HTML- , " ", . , , , , , Content-Type, I- .
www-. : , . HTML-, .
HTML-. , , . . , . <form> : action method. URL, , - .
: GET POST. GET , , URL . URL , , : "/cgi-bin/dir/script.pl?name=John&age=25 &hobby=reading&hobby=football". , "=", . POST : "-me=John&age=25&hobby=reading&hob-by=football" , URL .
, HTTP- www-. HTTP- , , HTTP- , , . , , . WWW , HTTP- - front end www-, , , - back end. : , : HTTP- - - .
CGI
CGI. HTTP- , , , . HTTP- , QUERY_STRING, URL, ( , , , GET). , CGI- , . , , , URL HTTP- , . CGI-. , , HTTP- . , CGI-, - Content-Type.
- HTML-. (, ). , HTTP- , . . , , PHR ASP (Active Server Pages), JSP (Java Server Pages). CGI, , , , CGI-, , .
- Javascript. , Javascript, <script> </script>, . , Java. HTML- <applet>, , - , Java-. http://java.sun.com.
HTTP- - HTTP-, -. . - : , , , URL cgi cgi-bin, , . , Cache-Control, . : Last-Modified Expires - " ".
, WWW . - , , HTTP-. WWW-Authenticate Authorization. : Basic Digest, . ; MD5.
WWW , , , : , () .
, mirror world, , . . , , DNS-, -. , , , , , HTML- , . , , . , .
WWW. HTTP-. , , HTTP- CGI- ( CGI-). , , - HTTP-. , CGI- , . CGI- .
,
.
,
, , -,
, .
,
, .
.
, ,
. , ..,
, -
.
, :
,
.
, , ,
, ,
.
- .
.
,
, .
, , ,
.
. ,
,
, ()
.
, ,
$1 .,
$20 . ,
. ? ,
?
,
.
, ,
, .
,
,
.
.
.
, ,
,
.
. :
(, ).
,
, .
, :
, , ,
.
,
. .
. ,
, .
,
- , ,
, 2 . ,
,
, .
,
.
,
.
(), .
"" .
: (,
).
, ""
. ,
,
.
. ,
, .
,
. ,
- ().
80 ,
,
.
.
.
, . -,
. -,
.
-,
,
,
.
, ,
.
. ,
.
.
()
(VPN).
,
() ,
.
, ,
. VPN ,
,
.
,
, , .
- .
,
.
.
.
- ,
. , ,
, .
, Internet/Intranet. , , , ( , , ).
, , , c - (). , , , , , - / ( , ) , ( ), .
, () , . : , : , , .
.
(Public Key Infrastructure - PKI).
, PKI, ,
, : (
) , ,
, () ,
. ,
,
.
, ,
,
,
. , PKI
, ,
.
. , , , , . : , , , , . . , , VeriVoice Security Lock VeriVoice , , . , , (, ).
. .
, . , , , . , , , . USB, PS/2 , , .
, , , . , , ; .
, , - , , - . , , (, , ) .
- ( ). , , , . , , , , PKI. - (, LAN, WAN VPN) , - , , . , , ( , "" " "), Internet/Intranet , . Orga Micardo - Standard, Public Dual - EEPROM 4 32 , 32 64 ROM ( ). Orga MICARDO Software Development Kit, .
, . $40, , , ( , , , ), , EEPROM-. $100, - $150.
, . , Smart Credit Card Internet Keyboard Presario 5000 , , (, ).
, , . -, , . , (, ), , , .
-, PCMCIA , , .
eToken
- , . ; , eToken R2 Aladdin 64 , DES-X 120- .
, , , , , , . eToken Microsoft CryptoKey MS Crypto API CSP (Crypto Service Provider) X.509 . - Digital Signature Trust (DST) TrustID, eToken Internet Explorer Netscape. RSA-KEON, PKI, eToken Microsoft Outlook, Outlook Express Netscape Messenger.
, , . , Windows 2000 Windows XP . Aladdin PKINIT Kerberos 5. . eToken , , .
, : USB, , . " " (hot plug), .
: USB, Aladdin.
, , . , , , , CD- , .
Aladdin. : , 30 . , . SDK, , / .
, " " , 64 , . , eToken R2, DESX 120 . , eToken PRO, , RSA/1024, 3DES (TripleDES), SHA-1, MD5 (Private) , .
, . Siemens CardOS/M4 FAT. , Windows.
, , - , 16- , DESX-. , , , . , - , .
eToken R2 , , , PIN-. John the Ripper , PIN- 1 .
. , - . -, .
, , ( , ), . , , . , , , CuteFTP, GetRight, GolZilla, Net Sonic . (spyware).
spyware, Aureate, Cydoor, DoubleQick,
EverAd, OnFlow WebSOOO.
adware, spyware .
, ,
,
,
-. ,
.
spyware. spyware
(, Y3K, Spektor, AgentSpy . .).
,
. , ,
.
- , : " " , , . . . . , - .
. , - . . -firewall, . . , . , , , .
?
. , - , . - , , Napster ? , Windows Media Player 8, Windows XP, , . , , , ( , Microsoft) . , , . , - Microsoft , Associated Press.
, . , Investigator . , . Investigator , , , . , web-, .
, Investigator , . . -. . 200 . , ?
:
. Chip 2002
. Chip, 2002
. 兔- "
""
. , . WORLD WILD WEB Chip,
2002
. Ô Chip, 2002
:
Sec.Ru -
- www.pps.ru/bib
Copyright (c) 2025 Stud-Baza.ru , , , .