タグ

iisとpythonに関するkkamegawaのブックマーク (1)

  • httpoxy

    Recommended reading Summary What Is Affected Immediate Mitigation Prevention Interesting, but once you’ve mitigated How It Works Why It Happened History of httpoxy CVEs A CGI application vulnerability (in 2016) for PHP, Go, Python and others httpoxy is a set of vulnerabilities that affect application code running in CGI, or CGI-like environments. It comes down to a simple namespace conflict: RFC 3

    kkamegawa
    kkamegawa 2016/07/19
    リモートから環境変数http_proxyを書き換えられてしまう脆弱性とその対策について。なるほど…IISもPHP使っていたら無関係じゃないと
  • 1