论文部分内容阅读
随着 Internet的广泛应用 ,通过 WWW对网络的攻击日益增多 .作为实现 WWW交互能力的重要手段CGI(com mon gateway interface) ,其安全机制直接影响到 Web服务器的安全性 ,使攻击者有可能通过 Web服务器实现其攻击目的 .比较了 3种主要的保护 CGI程序安全运行模型 ,并通过对一个攻击例子和对 Apache Su EXECCGI安全模型源代码的分析 ,指出该例子的攻击链可以通过 Su EXEC的安全防护层并讨论其不安全的因素 ,给出了相应的防御措施 ,提出了一个改进的 CGI安全保护层模型 .
With the wide application of the Internet, the number of attacks on the Internet through the WWW is increasing.As an important means of achieving the WWW interactive capability, the security mechanism of the CGI (com mon gateway interface) directly affects the security of the Web server and makes it possible for attackers to pass Web server to achieve its purpose.Comparison of the three main types of CGI safe operation model, and through an attack example and analysis of the source code of Apache Su EXECCGI security model, pointed out that this example attack chain can be through Su EXEC security Protective layer and discusses the factors of its insecurity, gives the corresponding defensive measures, and proposes an improved CGI security protection layer model.