タグ

ブックマーク / httpoxy.org (1)

  • httpoxy

    Recommended reading Summary What Is Affected Immediate Mitigation Prevention Interesting, but once you’ve mitigated How It Works Why It Happened History of httpoxy CVEs A CGI application vulnerability (in 2016) for PHP, Go, Python and others httpoxy is a set of vulnerabilities that affect application code running in CGI, or CGI-like environments. It comes down to a simple namespace conflict: RFC 3

    kimutansk
    kimutansk 2016/07/19
    CGI系の実行環境下ではリモートからHTTP_PROXYの環境変数置き換えられる・・・て、確かに言われてみるとその通り。これはまずいか。
  • 1