4 ms·
I agree for the third, but how sri will protect you from the first attack?
by therobot 9y ago
I agree for the third, but how sri will protect you from the first attack?
- krallja 9y agoIn this study, the JS is on a host separate from the site itself. Malicious JS from the compromised host will not match the SRI signature embedded in the HTML, and will be rejected. If the main HTML web server is compromised, there's nothing you can do: a compromised web server can send whatever <SCRIPT> tag it wants.
- therobot 9y agodirectly compromising in my understanding tells me that the server is compromised. The server suddenly "decides" to distribute malicious JS.