侨民面临哪些安全问题?
我听到了很多关于侨民安全问题的讨论,有人能总结一下它们是什么吗?
I heard allot of buzz around the security issues with diaspora, can someone summarize what they were?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
他们已经修补了其中的许多漏洞,但实际上整个项目几乎是书中所有基于网络的安全漏洞的混乱。以下是从他们的 alpha 代码发布第一天开始出现的问题的简要概述:
/image/123/delete/
删除自己的图像(其 ID 恰好为 123),但他们只需手动输入 URL/image /1/delete/
删除 ID 为 1 的图像,即使该图像不是他们的。如果您对技术细节感到好奇,请随时访问 自我教育。
They've since patched many of them, but really the whole project was a mess of nearly every web-based security exploit in the book. Here's a quick rundown of the problems from day one of their alpha code release:
/image/123/delete/
to delete an image of their own (whose ID happened to be 123), they could just manually type in the URL/image/1/delete/
to delete the image with an ID of 1, even if that image wasn't their's.If you're curious about the technical details, feel free to educate yourself.