HttpOnly Cookies - , XSS, xss. .
xsrf secuirty, , XSS, , xss.
. POST .
, XSS JavaScript, , xmlhttprequest. , xmlhttprequest, XSRF, POST. , XSS , . - , , , .
XSS - , <> html-. PHP :
$var=htmlspeicalchars($var,ENT_QUOTES);
, xss. html. , , . , , "onload =".
$var="' onload='alert(document.cookie)'";
html:
print("<img src='http://HOST/img.php?=".$var."'>");
HOWEVER, , <span>, - , ! xss, <script>. , , " " " ".
"XST", HTTP "TRACE", . , - HTTP- "TRACE". "GET" "POST" javascript <img> "GET", HTTP- . , TRACE Apache, , . , Nessus, , Apache TRACE, .