ʵʩҪÁ죺
ÔÚЧÀÍÆ÷ÏìӦͷÖÐÌí¼ÓCSPÖ¸ÁÀýÈ磺httpContent-Security-Policy:default-src'self';script-src'self'https://trusted.cdn.com;×Ðϸ²âÊԺ͵÷½âCSP¹æÔò£¬ÒÔÖÆÖ¹¶ÔÍøÕ¾Õý³£¹¦Ð§Ôì³ÉÓ°Ïì¡£
SubresourceIntegrity£¨SRI£©SRIÊÇÒ»ÖÖÓÃÓÚÑéÖ¤Íⲿ×ÊÔ´£¨ÈçJavaScriptÎļþ£©ÍêÕûÐÔºÍÕæÊµÐԵļ¼Êõ¡£Í¨¹ýʹÓÃSRI£¬¿ÉÒÔÈ·±£¼ÓÔØµÄ×ÊԴûÓб»?¸Ä¶¯£¬´Ó¶øÌá¸ßÄþ¾²ÐÔ¡£
×ܽá
»ÆÈë¿Ú»á¼ûËäÈ»²¢·ÇÖÂÃüµÄÄþ¾²Íþв£¬µ«Ëüȷʵ»áÓ°ÏìÓû§ÌåÑéºÍÍøÕ¾µÄÐÅÓþ¡£Í¨¹ýÁË½â»ÆÈë¿Ú»á¼ûµÄ³£¼ûÔÒò£¬²¢½ÓÄÉÏàÓ¦µÄ½â¾ö²½·¥£¬Äú¿ÉÒÔÓÐЧµØÖÆÖ¹ÕâÒ»ÎÊÌâµÄ±¬·¢£¬È·±£ÍøÕ¾µÄÕý³£ÔËÐкÍÓû§µÄÂúÒâ¶È¡£ÎÞÂÛÊÇÈ·±£È«Õ¾HTTPS¡¢Çå³ý»ìÏýÄÚÈÝ£¬Õվɵ÷½âÄþ¾²²ß?ÂÔ£¬Ã¿Ò»¸öϸ½Ú¶¼ÐèÒª×Ðϸ¿´´ý¡£
Ï£Íû±¾ÎÄÌṩµÄÐÅÏ¢ÄÜ×ÊÖúÄú¸üºÃµØÓ¦¶Ô»ÆÈë¿Ú»á¼ûÎÊÌ⣬ÌáÉýÍøÕ¾µÄÕûÌåÄþ¾²ÐÔºÍÓû§ÌåÑé¡£
¼ÌÐø´ÓµÚ¶þ²¿·ÖÉîÈë̽ÌÖ»ÆÈë¿Ú»á¼ûµÄÎÊÌ⣬²¢Ìṩ¸ü¶à½â¾ö²½·¥ºÍʵÓý¨Ò飬×ÊÖúÄúÈ«ÃæÁ˽âºÍÓ¦¶ÔÕâÒ»ÎÊÌ⣬½øÒ»²½ÌáÉýÍøÕ¾µÄÄþ¾²ÐÔºÍÓû§ÌåÑé¡£
½â¾ö²½·¥£º
¼ì²é²¢¸üÐÂËùÓÐÄÚ²¿Á´½ÓºÍ×ÊÔ´£¬È·±£Ê¹ÓÃHTTPSÐÒ顣ʹÓÃרҵµÄÄþ¾²É󼯹¤¾ß£¬ÈçQualysºÍNessus£¬¼ì²éSSLÖ¤ÊéºÍÆäËûÄþ¾²ÅäÖá£ÓëµÚÈý·½Äþ¾²Ð§ÀÍÏàÖú£¬°´ÆÚ½øÐÐÄþ¾²É¨ÃèºÍÉ󼯡£
½á¹û£ºÍ¨¹ýÒÔÉÏ´ë?Ê©£¬¸ÃÍøÕ¾µÄ»ÆÈë¿Ú»á¼ûÎÊÌâ»ñµÃÁËÓÐЧµÄ½â¾ö£¬Óû§ÌåÑé»ñµÃÁËÏÔÖø¸ÄÉÆ£¬Í¬Ê±ÍøÕ¾µÄÐÅÓþÒ²»ñµÃÁËÌáÉý¡£
×ܽá
»ÆÈë¿Ú»á¼ûÎÊÌâËäÈ»²»ÈçºìÉ«¾¯¸æÄÇôÑÏÖØ£¬µ«Í¬Ñù»áÓ°ÏìÓû§ÌåÑéºÍÍøÕ¾µÄÐÅÓþ¡£Í¨¹ýÀí½âÆä³£¼ûÔÒò²¢½ÓÄÉÏàÓ¦µÄ½â¾ö²½·¥£¬Äú¿ÉÒÔÓÐЧµØ¼õÉÙ»òÖÆÖ¹»ÆÈë¿Ú»á¼ûÎÊÌâµÄ±¬·¢¡£Á¬ÐøµÄÄþ¾²ÖÎÀíºÍ°´ÆÚµÄÄþ¾²Éó¼ÆÊÇÈ·±£ÍøÕ¾ºã¾ÃÄþ¾²ÔËÐеÄÒªº¦¡£
Èç¹ûÄúÁíÓÐÈκιØÓÚ»ÆÈë¿Ú»á¼ûÎÊÌâµÄÒÉÎÊ£¬»òÕßÐèÒª½øÒ»²½µÄ¼¼ÊõÖ§³Ö£¬ÇëËæÊ±ÁªÏµ×¨ÒµµÄÍøÂçÄþ¾²ÍŶӡ£ÎÒÃǽ«½ß¾¡È«Á¦×ÊÖúÄú½â¾öÎÊÌ⣬ȷ±£ÄúµÄÍøÕ¾ºÍÓû§µÄÔÚÏßÌåÑé¶¼ÄܵÃ?µ½×î¼Ñ°ü¹Ü¡£
Ï£ÍûÕâÆªÎÄÕÂÄÜΪÄúÌṩÓмÛÖµµÄÐÅÏ¢£¬²¢×ÊÖúÄúÔÚ»¥ÁªÍøÊ±´ú¸üºÃµØÖÎÀíºÍÔËÓªÄúµÄÍøÕ¾¡£Ð»Ð»ÄúµÄÔĶÁ£¡
У¶Ô£ºÍõÖ¾Óô(1C0m4pJyqZtPma0S7t9ZFfz4hTykKag)


