<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>bildirgec.org - etiketler: httponly cookie</title>
    <link>http://www.bildirgec.org/</link>
    <language>tr-tr</language>
    <ttl>40</ttl>
    <description>bildirgec.org - etiketler: httponly cookie</description>
    <item>
      <title>Mozilla Firefox 2.0.0.5 ile HTTPonly cookie'leri destekliyor</title>
      <author>Yns</author>
      <description>&lt;p&gt;Httponly cookie'ler XSS sald&#305;r&#305;lar&#305;na kar&#351;&#305; dolayl&#305; bir &#231;&#246;z&#252;m sa&#287;l&#305;yor. &#199;&#252;nk&#252;, HTTPonly cookie'lere javascript yard&#305;m&#305;yla ula&#351;&#305;lalam&#305;yor.&lt;/p&gt;


	&lt;p&gt;Bu da XSS sald&#305;r&#305;lar&#305;n&#305;n/senaryolar&#305;n&#305;n en tehlikesini ortadan kald&#305;r&#305;yor.&#350;u ana kadar, Firefox, bu tip cookie'leri destekleme konusunda IE'den geri kalm&#305;&#351;t&#305;.(ilgin&#231; ama do&#287;ru)&lt;/p&gt;


	&lt;p&gt;Firefox, son olarak 2.0.0.5 versiyonunda bu &#246;zelli&#287;i ekledi.Art&#305;k, HTTPonly cookie'ler Firefox taraf&#305;ndan destekleniyor.&lt;/p&gt;


	&lt;p&gt;Yeni ate&#351;li tilki versiyonumuzu indirip ufak bir test yapal&#305;m.&lt;br&gt;&lt;strong&gt;test.php&lt;/strong&gt;&lt;br&gt;&lt;code&gt;
&amp;lt;?
header("Set-Cookie: hidden=value; httpOnly");
?&amp;gt;

&amp;lt;script&amp;gt;alert(document.cookie)&amp;lt;/script&amp;gt;
&lt;/code&gt;&lt;/p&gt;


	&lt;p&gt;E&#287;er Firefox 2.0.0.5 kullan&#305;yorsan&#305;z sonu&#231; bo&#351; d&#246;n&#252;yor.&lt;/p&gt;


	&lt;p&gt;HTTPonly cookie'ler hakk&#305;nda &lt;a href="http://ilia.ws/archives/121-httpOnly-cookie-flag-support-in-PHP-5.2.html"&gt;buradan&lt;/a&gt; bilgi alabilirsiniz.&lt;/p&gt;&lt;p&gt;Bu yaz&#305; &lt;a href="http://www.bildirgec.org/uye/Yns"&gt;Yns&lt;/a&gt; taraf&#305;ndan &lt;a href=" http://www.bildirgec.org/yazi/mozilla-firefox-2-0-0 "&gt;bildirgec.org&lt;/a&gt; adresli sitede yay&#305;mlanmak &#252;zere yaz&#305;lm&#305;&#351;t&#305;r. Kaynak g&#246;sterilmeksizin kopyalanamaz.&lt;/p&gt;&lt;hr&gt;Pilli Projeleri: &lt;a href="http://pilli.com"&gt;Pilli.com: Kolektif Ba&#287;&#305;ms&#305;z &#304;&#231;erik&lt;/a&gt; | &lt;a href="http://sosyomat.com"&gt;Sosyomat.com: Arkada&#351;&#305;n&#305; Etiketle&lt;/a&gt; | &lt;a href="http://put.io"&gt;Put.io: Online Cloud Storage&lt;/a&gt;</description>
      <pubDate>Mon, 23 Jul 2007 07:56:00 GMT</pubDate>
      <guid isPermaLink="false">46718@http://www.bildirgec.org/</guid>
      <link>http://www.bildirgec.org/yazi/mozilla-firefox-2-0-0</link>
      <category>firefox</category>
      <category>httponly cookie</category>
    </item>
  </channel>
</rss>

