CSP ee Pentesters: Fahamka Aasaaska
Faallo
Mewayz Team
Editorial Team
Waa maxay sababta Pentester kasta uu ugu baahan yahay in uu sare u qaado siyaasadda amniga macluumaadka
Siyaasadda Badbaadada Mawduuca (CSP) waxay noqotay mid ka mid ah hababka difaaca ugu muhiimsan browser-ka ee ka dhanka ah qorista goobta (XSS), duritaanka xogta, iyo weerarrada gujisyada. Haddana ka qaybgalka tijaabada gelitaanka, madaxyada CSP waxay ahaanayaan mid ka mid ah kuwa ugu badan ee si khaldan loo habeeyey - oo si khaldan loo fahmay - kontaroolada amniga. Daraasad 2024 ah oo lagu falanqeeyay in ka badan 1 milyan oo shabakadood ayaa lagu ogaaday in kaliya 12.8% la geeyay madaxyada CSP gabi ahaanba, iyo kuwa, ku dhawaad 94% ay ku jiraan ugu yaraan hal daciifnimo siyaasadeed oo laga faa'iidaysan karo. Qalableyda, fahamka CSP maaha mid ikhtiyaari ah - waa farqiga u dhexeeya qiimeynta heerka sare iyo warbixinta taas oo dhab ahaantii xoojisa booska amniga macmiilka. Haddi aad samaynayso qiimaynta arjiga webka, ugaarsiga fadliga dhiqlaha, ama aad ku dhisayso amaanka goob ganacsi oo gacanta ku haysa xogta macmiilka ee xasaasiga ah, aqoonta CSP waa aasaas. Hagahan waxa uu kala jebinayaa waxa ay CSP tahay, sida ay u hoos shaqaynayso, halka ay ku fashilanto, iyo sida denbiilayaasha ay si nidaamsan u qiimeeyaan ugana gudbaan siyaasadaha daciifka ah.Waa maxay Siyaasadda Nabadgelyada Mawduucadu dhab ahaantii qabato
Dhinaceeda, CSP waa hannaan ammaan oo caddaynaya oo lagu bixiyo madaxa jawaabta HTTP (ama ka yar, sumadda). Waxay faraysaa browserka ilaha macluumaadka - qoraallada, qaababka, sawirrada, xarfaha, fareemada, iyo in ka badan - loo oggol yahay inay ku shubaan oo ku fuliyaan bogga la siiyay. Marka kheyraadku jebiyo siyaasadda, browserku wuu xannibaa oo si ikhtiyaari ah ayuu u wargeliyaa xadgudubka meel cayiman.
Dhiirigelinta asalka ah ee ka dambeysay CSP waxay ahayd in la yareeyo weerarada XSS. Difaacyada XSS ee dhaqameed sida fayadhowrka gelinta iyo codaynta wax-soo-saarka ayaa waxtar leh laakiin way jilicsan yihiin - macnaha guud ee la seegay ama qaladka codaynta ayaa dib u soo celin kara dayacanka. CSP waxay ku darsataa lakab difaac-qoto dheer: xitaa haddii uu weerarku ku dudo qoraal xaasidnimo ah DOM, siyaasad si habboon loo habeeyey ayaa ka ilaalinaysa browserka inuu fuliyo.CSP waxay ku shaqaysaaqaabka liiska cad-cad. Halkii aad isku dayi lahayd inaad xannibto waxyaabaha xun-xun ee la yaqaan, waxay qeexaysaa waxa si cad loo oggol yahay. Wax kasta oo kale waa la diidayaa. Rogaal celintan qaabka ammaanku waa mid awood leh aragti ahaan, laakiin ficil ahaan, ilaalinta siyaasadaha adag ee dhammaan codsiyada shabakadaha adag - gaar ahaan aaladaha maamulaya daraasiin qaybood oo isku dhafan sida CRM, qaansheegta, falanqaynta, iyo nidaamyada ballansashada - aad bay u adag tahay.
Anatomy of the CSP Header: Awaamiirta iyo Ilaha
Madaxa CSP waxa uu ka kooban yahayawaamiirta, mid kastaa waxa uu gacanta ku hayaa nooc kheyraad oo gaar ah. Fahamka awaamiirtan ayaa muhiim u ah qof kasta oo qiimeeya siyaasadda bartilmaameedka. Awaamiirta ugu muhiimsan waxaa ka mid ahdefault-src(dib-u-dhaca dardaaran kasta oo aan si cad loo dejin),script-src ( JavaScript execution ), style-src (CSS), img-src (images), isku xidhka-src, isku xidhka-src (iframes ku dhex jira), iyoobject-src(plugins sida Flash ama applets Java).
Awaamiir kastaa waxay aqbashaa hal ama in ka badan tibaaxaha ishaee qeexaya asalka la oggol yahay. Kuwani waxay u dhexeeyaan magacyo gaar ah oo martigeliyaha ah (https://cdn.example.com) ilaa ereyo fure oo ballaadhan:
- 'naftiisa' — waxay ogolaataa agabka asal ahaan ka yimid dukumeentiga
- midna' — xannibay dhammaan agabka noocaas ah
- 'aan-ammaan ahayn-inline' - waxay ogolaataa qoraallada khadka ah ama qaababka (si wax ku ool ah u dhexdhexaadiya ilaalinta XSS)
- 'nabadgelyo-eval' — ogolaato eval(), setTimeout(string), iyo fulinta koodka firfircoon ee la midka ah
- 'nonce-{random}' — waxay ogolaataa qoraalo khad toosan oo gaar ah oo lagu sumadeeyay wax is-daba-marin ah
- 'sdict-dynamic' — wuxuu aaminsan yahay qoraallada ay ku raran yihiin qoraallo hore loo aaminay, iyaga oo iska indhatiraya liisaska oggolaanshaha ee ku saleysan martida loo yahay
- xogta: - waxay u ogolaataa xogta URI-yada sida ilaha nuxurka
Madaxa CSP-ga dhabta ah wuxuu u ekaan karaa sidan:Content-Security-Policy: default-src 'self'; script-src 'naftiisa' https://cdn.jsdelivr.net 'nonce-abc123'; style-src 'naftiisa' 'aan-ammaan-inline'; img-src *; object-src 'midna'. Pentester ahaan, shaqadaadu waa inaad akhrido siyaasaddan oo aad isla markiiba ogaatid meesha ay ku xooggan tahay, meelaha ay daciifsan tahay, iyo meelaha laga faa'iidaysan karo.
Qabaynta khaldan ee caadiga ah ee CSP Pentesters waa inay beegsadaan
Farqiga u dhexeeya geynta madaxa CSP iyo geynta ku-xigeenkamadaxa CSP waa mid aad u weyn. Ficil ahaan, siyaasadaha intooda badani waxay ka kooban yihiin daciifnimo ay keeneen ku habboonaanta horumariyaha, isdhexgalka qolo saddexaad, ama isfaham la'aan fudud. Inta lagu jiro qiimeynta, dembiilayaasha waa inay si nidaamsan u hubiyaan guuldarrooyinkan caadiga ah. Habaynta khaldan ee ugu xun waa joogitaanka 'aan-ammaan-inline'' ee script-src dardaaranka. Kelmadan muhiimka ah waxay ka dhigaysaa dhammaan faa'iidooyinka ka-hortagga XSS ee CSP-da run ahaantii faa'iido la'aan, sababtoo ah waxay u oggolaanaysaa browser-ku inuu fuliyo wax kasta oo khadka tag ah - sida saxda ah waxa culeyska XSS uu ku durayo. Iyadoo ay taasi jirto, qiyaastii 87% ee boggaga leh CSP waxa ku jira 'aan-ammaan-inline''oo ku jira qoraal-src-kooda, sida lagu sheegay cilmi-baadhis ay daabaceen kooxda ammaanka Google. Sidoo kale,'aan-ammaan-xumo'waxay u furaysaa albaabka fulinta koodka iyada oo loo marayo hawlaha xargaha-to-koodka, kuwaas oo weeraryahannadu ay ku xidhi karaan dhibcaha duritaanka ku salaysan DOM. Liisaska oggolaanshaha martida loo yahay ee aadka u ballaadhan waa dahab kale. Liistada caddaynta dhammaan domainka CDN sida *.googleapis.comama *.cloudflare.commacnaheedu waa kheyraad kasta oo lagu hayo goobahaas waxay noqdaan ilo qoraal ah oo la aamini karo. Weeraryahanadu waxay geli karaan JavaScript xaasidnimo adeegyadan waxayna ku fulin karaan gudaha macnaha amniga ee bartilmaameedka. Aaladaha sidaCSP Evaluator(waxaa soo saaray Google) waxay si degdeg ah u calaamadin kartaa gelitaanadan aadka loo oggol yahay. Pentesters waa in ay sidoo kale raadiyaan ilo cad-cad (*), xaddidaadahaobject-srcka maqan, iyo maqnaanshahabase-uriiyoqaab-tallaabodardaaranka - laba hab-raac oo inta badan la iska indho-tiray si ay u faafiyaan xogta ama foomamka afduubka.Farsamooyinka la dhaafi karo ee CSP ee la taaban karo
Marka pentester aqoonsado siyaasadda CSP inta lagu jiro sahanka, tallaabada xigta ayaa go'aamineysa in la hareer mari karo iyo in kale. Farsamo dhowr ah oo si wanaagsan loo diiwaangeliyay ayaa jira, ku habboonaantooduna waxay gebi ahaanba ku xiran tahay awaamiirta gaarka ah iyo tibaaxaha isha ee siyaasadda bartilmaameedka."Siyaasadda Nabadgelyada Mawduucadu waxay u xoog badan tahay sida dardaarankeeda ugu liidata. Hal tibaax oo si xad dhaaf ah loo oggolaaday ayaa daaha ka qaadi karta siyaasad kale oo adag - iyo kuwa khibradda leh ayaa si sax ah u garan kara halka ay wax ka eegi karaan."
💡 DID YOU KNOW?
Mewayz replaces 8+ business tools in one platform
CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.
Start Free →
JSONP xadgudubka barta dhamaadkawaa mid ka mid ah hababka la isku halayn karo ee ugu kalsoonida badan. Haddii CSP-du ay liis gareeyaan domain martigelinaya barta dhamaadka JSONP (Google API-yo badan, tusaale ahaan), weeraryahanku waxa uu samayn karaa cabbir dib-u-wacitaan kaas oo fuliya JavaScript aan sabab lahayn. Tusaale ahaan, haddii script-srcay ku jiraan accounts.google.com, barta dhamaadka JSONP ee /o/oauth2/revoke?callback=alert(1) waxa loo isticmaali karaa il qoraal ahaan. Pentesters waa in ay xisaabiyaan dhammaan xayndaabyada liiska caddeeyey oo ay mid walba ka hubiyaan JSONP, martigelinta maktabadda Xaglaha ah (taas oo awood u siinaysa muditaanka qaab-dhismeedkang-app), ama fur nuglaanta dib-u-dejin oo lagu xidhi karoscript-srcliiska oggolaanshaha.
Afduubka saldhigga URIwuxuu shaqeeyaa marka siyaasaddu ay weydo awaamiirtabase-uri. Marka la durayo sumaddaDhismaha Habka Qiimaynta CSP
Qiimaynta CSP ee waxtarka leh waxay u baahan tahay hab habaysan oo aan ahayn imtixaan ad-hoc ah. Pentesters waa in ay ku daraan falanqaynta CSP kooda caadiga ah ee tijaabinta arji shabakadeed socodka shaqada, oo ka bilaabma sahamin dadban oo u socda isku dayo ka faa'iidaysi firfircoon.Ka bilow adiga oo ururinaya dhammaan madaxyada CSP iyo calaamadaha badan ee codsiga. Nidaamyadu way ku kala duwanaan karaan inta u dhaxaysa dhibcaha dhamaadka - guddiga maamulka ayaa laga yaabaa inuu yeesho kontarool adag marka loo eego bogga soo degista suuq-geynta, ama liddi ku ah. Isticmaal aaladaha horumariyaha browserka, kormeerka jawaabta Burp Suite, ama aaladaha khadka taliska sidacurl -Isi aad u qabsato madaxyada. Ku quudi siyaasad kasta oo gaar ah qalabka qiimaynta otomaatiga ah: Google's CSP Evaluator, Mozilla's Observatory, iyocsp-bypass kaydka GitHub dhamaantood waxay bixiyaan qiimaynaha bilowga ah ee degdega ah.
Marka xigta, khariidad siyaasadda lidka ku ah habdhaqanka kaydinta arjiga ee dhabta ah. Ma jiraan qoraallo laga soo raray xayndaabyada aan ku jirin liiska caddaymaha (oo tilmaamaya in siyaasaddu ay ku jirto qaabka warbixinta-kaliya ama aan la dhaqangelin)? Codsigu si weyn ma ugu tiirsan yahay qoraallada khadka tooska ah ee ku jabi doona siyaasad adag - soo jeedinta horumariyayaashu waxay dabciyeen CSP si ay u ilaaliyaan shaqeynta? Goobaha leh qaab-dhismeedyo adag - ka fikir qalabka maaraynta ganacsiga oo leh qaybo isku dhafan oo ka kooban dashboards falanqaynta, jadwalka ballanta, habaynta lacag bixinta, iyo iskaashiga kooxda - ilaalinta CSP adag ee dusha sare ee muuqaal kasta waa caqabad injineernimo oo dhab ah. Pentesters waa in ay fiiro gaar ah u yeeshaan sifooyinka dhawaan lagu soo kordhiyey ama isdhexgalka dhinac saddexaad, sababtoo ah kuwani waa kuwa ugu badan ee keenay siyaasad ka baxsan.
- Ka qabso oo katalogi madaxyada CSP meel kasta oo u gaar ah iyo nooca jawaabta
- Ku wad falanqaynta siyaasada toosan adoo isticmaalaya Qiimeeyaha CSP iyo aaladaha la midka ah
- Tiri dhammaan xayndaabyada liiska cadcad ee JSONP-dhammaadka, maktabadaha xaglaha ah, iyo hagidda furan Tijaabi saadaalin la'aanta, dib-u-isticmaalka, ama daadinta siyaasadaha aan ku salaysnayn
- Hubi in qaabka warbixinta-kaliya aan lagu qaldamin qaab la dhaqan galiyay
- Isku daygii dukumeenti ahaa ee farsamooyinka ka-hortagga daciifnimada la aqoonsaday
- Ku qor natiijooyinka hagitaan dib-u-habayn, oo ay ku jiraan isbeddelada dardaaranka ah
Qoritaanka Natiijooyinka CSP ee la fulin karo ee Warbixinada Pentest
Aqoonsiga daciifnimada CSP waa kala badh shaqada - in si wax ku ool ah loola xiriiro kooxaha horumarinta ayaa go'aamisa in ay dhab ahaantii hagaajinayaan. Helitaanka si fudud u sheegaya "CSP waxay oggolaataa khad aan badbaado lahayn" iyada oo aan macnaha guud lahayn waxay u badan tahay in laga horraysiiyo. Taa beddelkeeda, dembiilayaasha waa inay muujiyaan saamaynta la taaban karo ee daciif kasta iyaga oo ku xidhaya vector XSS dhab ah ama aragti gaar ah oo u gaar ah codsiga bartilmaameedka. U qaabee natiijooyinkaaga CSP si ay ugu daraan siyaasadda hadda jirta, dardaaranka gaarka ah ama odhaahda isha ee nugul, caddaynta fikradda muujinaysa ka faa'iidaysiga ama sheeko weerar cad, iyo siyaasad lagu taliyey oo la saxo. Haddii ay suurtagal tahay, bixi madaxa saxda ah ee ay tahay in kooxda horumarinta ay geyso. Ururada ku hawlan codsiyada shabakadaha adag sida Mewayz ee xoojiya CRM, qaansheeg bixinta, mushahar bixinta, maamulka HR, iyo daraasiin ka mid ah qaybaha kale ee hal interface ka badan isticmaalayaasha 138,000 - talooyinka dib u habeynta CSP waa inay ku xisaabtamaan baaxadda buuxda ee isku dhafka dhinac saddexaad iyo soo dejinta firfircoonida leh. Siyaasad aad u dagaal badan waxay jebin doontaa shaqada; Mid ka mid ah oo aad u oggolaaday wuxuu bixiyaa kalsooni been ah. Ugu dambayntii, CSP ma aha xabbad qalin ah, iyo pentiers waa in ay u habeeyaan si waafaqsan warbixintooda. Waa lakab awood leh oo ku jira istaraatijiyad qoto dheer oo difaac ah oo sida ugu fiican u shaqaynaysa iyada oo ay weheliso xaqiijinta gelinta adag, codaynta wax soo saarka, daacadnimada kheyraadka hoose (SRI), iyo dhaqamada horumarineed ee sugan. Ururada si sax ah u hela CSP waxay ula dhaqmaan sidii siyaasad nololeed - mid ka soo baxda codsigooda, si joogto ah loo tijaabiyo, oo aan waligood ku tiirsanayn 'aan-ammaan-inline''sidoo kale jid gaaban oo joogto ah. Qalableyda, haynta falanqaynta CSP waxay u beddeshaa hubinta madaxa caadiga ah mid ka mid ah wax-soosaarka ugu qiimaha badan ee qiimayn kasta oo arji shabakad ah.Su'aalaha Inta badan La Isweydiiyo
Waa maxay Nidaamka Badbaadada Macluumaadka
Siyaasadda Nabadgelyada Mawduucadu waa hannaan ammaan oo dhinaca browser-ka ah kaasoo koontaroolaya agabka boggu soo shuban karo, ka caawinaya ka-hortagga XSS, duritaanka xogta, iyo weerarrada gujis-jacking. Pentesters waa inay fahmaan CSP sababtoo ah waa mid ka mid ah kontaroolada amniga ee inta badan si khaldan loo habeeyey - daraasaduhu waxay muujinayaan ku dhawaad 94% siyaasadaha la diray waxay ka kooban yihiin daciifnimo laga faa'iidaysan karo. Aqoonta aasaasiga ah ee CSP waxay u ogolaataa pentesters in ay aqoonsadaan dayacanka muhiimka ah ee iskaaneriyeyaasha iswada ay inta badan seegaan gabi ahaanba.
Waa maxay hababka khaldan ee CSP ee ugu badan ee ay helaan pentesters?
Habaynta khaldan ee CSP-da ugu caansan waxaa ka mid ah adeegsigainline-inlineiyo aan-ammaan ahayn dardaaran, ilo kaarka duurjoogta ah oo aad loo oggol yahay, maqan awoowayaasha-frame-code> dardaaranka awood u-jacking, iyo caddeynta dhammaan xayndaabka CDN ee martigeliya waxyaabaha la xakameyn karo weerarka. Pentesters waa inay sidoo kale raadiyaan awaamiirta maqan sida base-uri iyo form-action, kuwaas oo loo adeegsan karo phishing iyo xog-baxin xitaa marka kontaroolada qoraalku u muuqdaan kuwo adag.
Sidee ganacsatadu ugu ilaalin karaan codsiyadooda mareegaha iyagoo wata madax CSP sax ah?
Ganacsiyadu waa inay ku bilowdaan CSP adag iyagoo isticmaalaya qoraal aan ku salaysnayn ama xashiish ku salaysan oo ogolaansho ku leh halkii ay ka ahaan lahaayeen liiska cad-cad ee domainka. Geli habka warbixinta-kaliya marka hore si aad u aqoonsato jebinta ka hor inta aan la fulin. Nidaamyada sida Mewayz, 207-module-ganacsi OS ah oo ka bilaabma $19/mo, waxay ka caawiyaan kooxaha inay si ammaan ah u maamulaan joogitaankooda mareegaha iyagoo raacaya hababka ugu wanaagsan ee amniga casriga ah dhammaan goobaha taabashada dhijitaalka ah.
Waa maxay aaladaha ay adeegsadaan pentesters si ay u qiimeeyaan waxtarka CSP?
Pentesters caadi ahaan waxay isticmaalaan Google's CSP Evaluator, aaladaha horumariyaha browserka, iyo kordhinta Burp Suite si ay u falanqeeyaan madaxyada CSP ee daciifnimada. Tijaabada gacanta ayaa weli ah lama huraan - aaladaha otomaatiga ah waxay seegaan marinnada ku-tiirsanaanta macnaha guud sida dhibcaha dhammaadka JSONP iyo qaab-dhismeedka qaab-dhismeedka xagasha ee meelaha liiska cadcad. Qiimayn dhamaystiran waxa ay isku daraysaa iskaanka otomaatiga ah iyo dib u eegis gacanta lagu samaynayo dardaaran kasta oo lid ku ah farsamooyinka ka gudubka ee la yaqaan iyo kaydka teknoolajiyada gaarka ah ee codsiga.
Try Mewayz Free
All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.
Get more articles like this
Weekly business tips and product updates. Free forever.
You're subscribed!
Start managing your business smarter today
Join 30,000+ businesses. Free forever plan · No credit card required.
Ready to put this into practice?
Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.
Start Free Trial →Related articles
Hacker News
Laravel raised money and now injects ads directly into your agent
Apr 16, 2026
Hacker News
Claude Opus 4.7 Model Card
Apr 16, 2026
Hacker News
There's yet another study about how bad AI is for our brains
Apr 16, 2026
Hacker News
Qwen3.6-35B-A3B: Agentic Coding Power, Now Open to All
Apr 16, 2026
Hacker News
The Future of Everything Is Lies, I Guess: Where Do We Go from Here?
Apr 16, 2026
Hacker News
Cloudflare Email Service: now in public beta. Ready for your agents
Apr 16, 2026
Ready to take action?
Start your free Mewayz trial today
All-in-one business platform. No credit card required.
Start Free →14-day free trial · No credit card · Cancel anytime