當一個站點具有以下crossdomain.xml配置時。以下含義是什麼?這個crossdomain.xml暗示了什麼?
其次,如果站點A(HTTP)承載了Flash上傳腳本上傳到S3,這是crossdomain.xml文件安全地對S3的根目錄?
<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.macromedia.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<!--
Read this: www.adobe.com/devnet/articles/crossdomain_policy_file_spec.html
-->
<!-- Most restrictive policy:
<site-control permitted-cross-domain-policies="none"/>
-->
<!-- Least restrictive policy: -->
<site-control permitted-cross-domain-policies="all"/>
<allow-access-from domain="*" to-ports="*" secure="false"/>
<allow-http-request-headers-from domain="*" headers="*" secure="false"/>
<!--
If you host a crossdomain.xml file with allow-access-from domain="*"
and don’t understand all of the points described here, you probably
have a nasty security vulnerability. ~ simon willison
-->
</cross-domain-policy>
作爲最寬鬆的,什麼可能發生壽有此crossdomain.xml文件的S3桶最差?由於這些配置,用戶是否可以操縱此S3存儲桶中的現有文件(即刪除,覆蓋)? – 2012-08-06 08:50:31
當我說「用戶」時,我的意思是「未經授權的用戶」 – 2012-08-06 08:56:19