跳到主要内容

7. 安全考虑事项 (Security Considerations)

7.1. 可靠性和一致性 (Reliability and Consistency)

URI 的可靠性取决于 resource owner 的意图和实现.

7.2. 恶意构造 (Malicious Construction)

攻击者可能构造恶意 URI, 用于:

  • 利用解析器脆弱性
  • 绕过安全检查
  • 执行注入攻击

7.3. 后端转码 (Back-End Transcoding)

字符编码转换可能引入安全脆弱性.

7.4. 少见 IP 地址格式 (Rare IP Address Formats)

某些 IP 地址格式可能被用于欺骗.

7.5. 敏感信息 (Sensitive Information)

警告 (Warning): 不要在 URI 中包含敏感信息, 例如密码, 原因包括:

  • URI 可能被记录到日志中
  • URI 可能出现在 referrer header 中
  • URI 可能被缓存

7.6. 语义攻击 (Semantic Attacks)

视觉上相似的字符可能被用于欺骗用户.

示例 (Examples):

  • Cyrillic "а" 看起来像 Latin "a"
  • example.comexamp1e.com, 即 l 与 1

下一章 (Next Chapter): 8. IANA 考虑事项 (IANA Considerations) - URI scheme registration