,,,
:
:
. -220
. .
, , . , , - .
, , , . -, . , , , web-, , " " . -,
, ICQ. , . , - , ( , )
.
,
?
, , ,
, .
, ,-
. .
" "
,
.
, .
Windows 95 98.
.
.
Windows 9 - . , , " ". , . , . ,
. , , .
, .
, , , - . - . - , (,
, ). , . , . , , , . - - , ,
,
. , ( ), -. - , : , , .
,
. Microsoft Internet Explorer, Microsoft Outlook Express Outlook Microsoft Office .
, web-. , , ( Windows NT, 2000 , , ). , , .
?
- .
. - , , .
. ,
. ActiveX, HTML- , , (, Media Player). , Microsoft
- . ,
, . -
, , - . , . , Java,
ActiveX, cookie, , .
...
firewall - , .
firewall , . , - , . Firewall ,
(, ). firewall web-: ActiveX, (JavaScript, Visual Basic), Java-.
, ,
firewall
-
.
. , , , , . , (Nimda, Sircam). . . ,
, , , . , . . , , - . Microsoft ( )
(http://windowsupdate.microsoft.com). , (Internet Explorer, COM+), , " " (Service Pack), . RollUp Package, , Service Pack . , ,
, , .
, , , . , , . , . , , . ,
firewall , . . ,
: Russian Security News-line (http://bugtraq.ru/rsn), SECURITY.NNOV (http://www.security.nnov.ru/), CERT Coordination Center (http://www.cert.org).
www.cert.org -
!
. , . , , . , . . , , , , . . , , .
Microsoft ,
, . - - . , , - , Microsoft Microsoft Baseline Security Analyzer. , , , -
, . . , MBSA , . . MBSA 1.0 Finjan Malicious
Code Research Center , XML
. , , , . , , , HTML-. .
?
- . , , . , , , , . , , , . .
, . , IRC ( I-Worm.LoveLetter, ILOVEYOU), Microsoft - Internet Information Server, ( , , Nimda).
( , ). - BadtransII
, LOG- . - Nimda "" . ,
, . , , , .
, WWW - , . , - - , . , , .
, , , www- , .
, - . (. www-). , , , EXE-, MS Office .
- web-. HTML- Javascript, , Java, ActiveX ( MS Windows).
, . , Java- (sandbox), . Javascript , Javascript .
""
, . , .
web- Javascript. , :
- ,
.
- ,
().
, -
. URL,
,
- . :
href=http://www.cracker.com/
onMouseover=http://www.goodbank.com/;
return true>
Click here to enter your credit number
, , , www.goodbank.com, , , www.cracker.com. www.cracker.com.
Javascript . - , - . , , Javascript . , .
, - WWW-, Javascript HTML- . cross-site scripting , . , WWW- , . , . , , >Click here
WWW- example.com, , .
Cross-site scripting SSL
cross-site scripting , SSL. , WWW-, , , , .
cross-site scripting .
. , ( ActiveX, Java Javascript) . , . , , , , , . , , , .
Java, ActiveX Javascript, .
, HTTP- . , , WWW- . Digest- ( ) - . .
, , www-, , IP- , URL , ( ), URL , . -, WWW .
, GET, LOG-, URL-. POST , .
, ( , - history). ( ).
www- (, -) cookies (, , ). , ( - , cookies). cookies WWW. cookies, .
- SSL
, -, SSL ( - TLS).
SSL TCP/IP (TCP) . SSL (, , ) . HTTP , , HTTP- .
SSL, HTTP- , SSL ( ). URL , SSL, "https://". HTTP- () SSL-. , "" . , . , VeriSign. , , .
, ( , . .).
SSL -
SSL -. HTTP- , . - HTTP-. CONNECT HTTP-.
CONNECT -, TCP- , . , - CONNECT, , 443, HTTP SSL.
- -
- HTTP- , .
, WWW - . , HTTP-, - . HTTP- , 80, - (80-86, 8000-8006, 8080-8086, 8888).
-
( ):
- , . - IP-, -.
- WWW-, Proxy-Authorization. -, , 407 Proxy Authentication Required Proxy-Authenticate, WWW-Authenticate. Digest Proxy-Authentication-Info.
, www- - HTTP- - , . (Authorization Proxy-Authorization) , .
, , ( ). , Basic Ethernet - , Digest.
, , WWW , . - .
WWW - , HTTP.
HTTP : () . TCP HTTP- - 80. URL - (), , .
, , URL, . . HTML- , " ", . , , , , , Content-Type, I- .
www-. : , . HTML-, .
HTML-. , , . . , .
Copyright (c) 2024 Stud-Baza.ru , , , .