·Î±×ÀÎ | ȸ¿ø°¡ÀÔ (´º½º·¹ÅͽÅû) | SITEMAP
   
  °³¹ß   Ç÷§Æû   ½Ã½ºÅÛ   ¸Å´ÏÁö¸ÕÆ®   Àüü±â»ç  
ÀÚ¹Ù
´å³Ý
C/C++
DB
¸ðµ¨¸µ
À¥°³¹ß
±âŸ
À¯´Ð½º/¸®´ª½º
À©µµ¿ì
±âŸ
¼­¹ö
³×Æ®¿öÅ©
º¸¾È
±âŸ
BM
PM
±âŸ
 
±â»çÀúÀå
0
 
¸¶ÀÌ ½ºÅ©·¦
[Ã¥¼Ò°³] À¥ ÇØÅ· ÆÐÅϰú ´ëÀÀ

±èÅÂÁ¤ ±âÀÚ (tjkim@zdnet.co.kr) ( ZDNet Korea )   2008/01/21
XSS
SQL injection
À¥ ¾ÖÇø®ÄÉÀ̼ǻóÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°ÝÀº ¿ä ¸î ³â°£ ²öÁú±â°Ô IT ´ã´çÀÚµéÀ» ±«·ÓÈ÷°í ÀÖ´Ù. ³²ÀÇ ÀÎÀû»çÇ×À» µµ¿ëÇØ ¿Â¶óÀÎ ±ÝÀ¶»ç±â¸¦ ¹úÀ̰ųª, »çÀÌÆ®¸¦ ¸¶ºñ½ÃŰ´Â °ø°ÝÀÌ ´ëÇ¥Àû »ç·Ê´Ù. °Ô´Ù°¡ ÃÖ±Ù¿¡´Â À¥2.0À̶ó´Â °³¹æÇü Æ®·£µå¿¡ ¸ÂÃç ±× À§Çù ¼öÁØÀÌ ´õ ³ô¾ÆÁö°í ÀÖ´Ù.

¡¸À¥ ÇØÅ· ÆÐÅϰú ´ëÀÀ¡¹Àº ÀÌ·± ¹®Á¦°¡ º»°Ý ´ëµÎµÈ 2005³â ³ª¿Â Ã¥ÀÌ´Ù. ¾÷°èÀÇ ºü¸¥ º¯È­¼Óµµ¸¦ °¨¾ÈÇÒ ¶§ ¿À´Ã³¯ ޵¶Çϱ⿡´Â ³°¾Ò´Ù´Â »ý°¢ÀÌ µå´Â °ÍÀÌ »ç½Ç. ÇÏÁö¸¸ ¸¹Àº Àü¹®°¡µéÀÌ ¾ÆÁ÷µµ ÀÌ Ã¥ÀÇ ´öÀ» ÅåÅåÈ÷ º»´Ù°í ÇÑ´Ù.

À۳⿡ ÀÌ Ã¥À» ±¸ÀÔÇß´Ù´Â F5³×Æ®¿÷½º ¾ç°æÀ± ºÎÀåÀº ¡°À¥ ÇØÅ·¿¡ ´ëÇÑ Á¤º¸´Â º¸Åë ¹Ìµð¾î¸¦ ÅëÇÑ ±â¼ú±â°í·Î¸¸ Á¢ÇØ IT ´ã´çÀڵ鵵 ³­ÇØÇØ ÇÏ´Â °æ¿ì°¡ ¸¹´Ù¡±¸ç ¡°¡®À¥ ÇØÅ· ÆÐÅϰú ´ëÀÀ¡¯Àº ½ÇÁ¦ ¼­¹ö¿¡ ´ëÇÑ °ø°Ý ŸÀÔÀÌ ±¸Ã¼ÀûÀ¸·Î Á¦½ÃµÅ, ޵¶ÇÏ¸é ½ÇÀü¿¡¼­ È¿°ú¸¦ º¼ °Í¡±À̶ó°í ÃßõÇß´Ù.

¶Ç ±×´Â ¡°À¥ ÇØÅ·¿¡ ´ëÇØ Àß ¸ð¸£´Â °í°´¿¡°Ô ±× À§ÇèÀ» ¾Ë¸®´Â µ¥¿¡µµ ÁÖÈ¿Çß´Ù¡±¸ç ¡°°³ÀÎÀûÀ¸·Î ÇöÀç ½ÃÁß¿¡ ÀÖ´Â µ¿Á¾ µµ¼­ Áß¿¡¼­´Â À¸¶ä¡±À̶ó°í ÃßÄѼ¼¿ü´Ù.

XSS ¹× SQL injection ÁýÁß ¼³¸í
Ã¥ÀÇ ±¸Ã¼ÀûÀÎ ³»¿ëÀ» »ìÆìº¸¸é XSS(Cross site Scripting)¿Í SQL injection °ø°Ý¹®Á¦¿¡ ÃÊÁ¡À» ¸ÂÃè´Ù. µÑ ¸ðµÎ ¹Ì ¡®¸¶ÀÌÅÍ(MITER)¡¯»çÀÇ ¡®Common Weakness Enumeration(CWE)¡¯ Á¶»ç¿¡¼­ ÃÖ°í À§Çèµµ·Î ºÐ·ùµÈ °ø°ÝÀÌ´Ù. ¸ðµÎ À¥ÀÇ ¹ß´Þ¿¡ Æí½ÂÇØ ³ª¿Â °ñÄ©µ¢À̵éÀÌ´Ù.

XSS °ø°ÝÀº ÇØÄ¿°¡ »ç¿ëÀÚ ÀÔ·Â °ª¿¡ ´ëÇÑ °ËÁõÀÌ ºÎÁ·Çϰųª ÀÎÄÚµùÀ» Àû¿ëÇÏÁö ¾Ê¾ÒÀ» ¶§ ¹ß»ýÇÒ °¡´É¼ºÀÌ ³ô´Ù. ÀÏ´Ü °ø°ÝÀÌ ½ÃÀÛµÇ¸é ¡®ºòÆÀ(Victim)¡¯ ¼¼¼Ç µµ¿ë ȤÀº À¥ ÆäÀÌÁö Á¶ÀÛ ÇÇÇØ¸¦ ÀÔÀ» ¼ö ÀÖ´Ù. À¥ ÆäÀÌÁö Á¶ÀÛ ´ëºÎºÐÀº »çÀÌÆ®¸¦ ÇÇ½Ì ±Ù°ÅÁö·Î »ç¿ëÇϱâ À§ÇÔÀÌ´Ù.

¶Ç SQL injectionÀº ¡®SQL¡¯ÀÇ Äõ¸® ¹®ÀÚ¿­ »çÀÌ¿¡ ƯÁ¤ ¾Ç¼ºÄڵ带 »ðÀÔÇÏ´Â °ø°Ý±â¹ýÀ¸·Î, À¯¸í Æ÷ÅеéÀ» Áö¼ÓÀûÀ¸·Î ³ë¸®°í ÀÖ´Ù.

Ã¥Àº ÀÌ·± °ø°ÝµéÀÇ ±â¹ýÀ» ¸Å¿ì ¼¼ºÎÀûÀ¸·Î ¼³¸íÇϰí ÀÖ´Ù. ±×¸®°í °ø°Ý¼öÁØ¿¡ ¸Â´Â ´Ü°èÀû ¹æ¾î±â¹ýÀ» ½ÇÀü À§ÁÖ·Î ¾Ë·ÁÁØ´Ù. ȯ°æ¼³Á¤, ¿À·ùó¸® ¹æ½Ä, ÄÚµù, ±ä±Þ»çÇ× ´ëó µî¿¡ °üÇØ °ü¸®ÀÚµéÀÌ À߸ø ÇൿÇÏ´Â À¯ÇüÀ» ÁöÀûÇÑ °Íµµ Ư¡ÀÌ´Ù.

ÁýÇÊÀº ¡®¼Ö¶ó¸®½º ÇØÅ·°ú º¸¾È¡¯À» Àú¼úÇÑ È²¼øÀϾ¾¿Í ¾Èö¼ö¿¬±¸¼Ò Ãâ½Å ±è±¤Áø¾¾°¡ °øµ¿À¸·Î Çß´Ù. @
µ¶ÀÚÀÇ°ß ³²±â±â (·Î±×ÀÎ ÈÄ µ¶ÀÚ ÀǰßÀ» ³²±â½Ç ¼ö ÀÖ½À´Ï´Ù.)
¾ÆÀ̵ð ºñ¹Ð¹øÈ£
µ¶ÀÚÀǰß(Talkback)
±è±¤Áø¾¾´Â ³Ø½¼ÀÌ ¾Æ´Ñµ¥¿ä. ¼öÁ¤ÇØÁÖ¼¼¿ä.
º¸¾Èº¸¾È[ 2008/01/22 ]  
¼öÁ¤ÇØÁÖ¼¼¿ä.
 
 
°³¹ßÀÚ ½Ç·ÂÇâ»ó À§ÇÑ ¿ø¸Ç ÇÁ·ÎÁ§...
[Ã¥¼Ò°³] À¥ °³¹ßÀÚ¸¦ À§ÇÑ ½ºÇÁ...
À©µµ¿ìCE °³¹ßÅø¿¡ °üÇÑ 12°¡Áö...
[±â°í] °¡»óÈ­ ½ÃÀåÀÇ Çö ÁÖ¼Ò
½ãÀÇ Java DB »ç¿ë¹ý
[±â°í] IT ¿¡³ÊÁö »ç¿ë ÃÖÀûÈ­...
¡¸BSP¿¡¼­ OS±îÁö¡¹¡¤¡¤¡¤À©µµ¿ì...
[ÇöÀ彺ÄÉÄ¡]Å× ¹Ý¼Ä ¾¾°ÔÀÌÆ® ºÎ»çÀå ¡°³ëÆ®ºÏ¿ë SSD ¼º´É°³¼± ´õµð³ª 2³â ÈÄ¿£ ¸ðµÎ äÅá± [00:03:03]
ÁøÇà ·ùÁØ¿µ ±âÀÚ, Á¦ÀÛ À¯È¸Çö PD
[¼­¹ü±ÙÀÇ À¯ÄèÇÑ ¸®ºä]ÄÞÆÑÆ® µðÄ« '¾ó±¼Àνıâ´É ÀÚ¿õ°¡¸®ÀÚ'¡¦»ï¼º ºí·ç i8 VS ¼Ò´Ï »çÀ̹ö¼¦ W300 [00:04:20]
ÁøÇà ·ùÁØ¿µ ±âÀÚ, Á¦ÀÛ À¯È¸Çö PD
¸óÇå2G, ÀϺ»¼­ ´ë¹Ú¡¦ Çѱ¹¼± ...
À¥2.0 ½Ã´ë, À̸ÞÀÏÀÇ Á¸ÀçÀÌÀ¯...
¿À¼®ÁÖ ¾È·¦ ´ëÇ¥ ¡°¹«·á¹é½Å¸¸ ¹Ï...
½ÇÆÐÇÏÁö ¾Ê´Â Á¦¾ÈÀÇ ¹ýÄ¢
Çö´ë °úÇбâ¼úÀÇ '7´ë ºÒ°¡»çÀÇ'
[News Blog] Áö±¸ ¹Ý´ëÆí...
¹æÅëÀ§, ¹«¼±¼³ºñ ±â¼ú±âÁØ Á¦Á¤ ...
·¹µåÇÞ, ´º¿åÁõ±Ç°Å·¡¼Ò À¯·Î³Ø½ºÆ®...
ÄÉÀ̺íTV, Ȩ³×Æ®¿öÅ© ¼­ºñ½º µµ...
KTF, ±è¿¬¾Æ ¸ð¹ÙÀÏ »ýÁß°è
[Àλç]»ï¼ºSDS¡¤»ï¼º³×Æ®¿÷½º¡¤¿¡...
 
 
The Korean edition of 'ZDNet' is published under license from CNET Networks, Inc., San Francisco, CA, USA. Editorial items appearing in 'ZDNet Korea' that were originally published in the US Edition of 'ZDNet', 'CNET', and 'CNET News.com' are the copyright properties of CNET Networks, Inc. or its suppliers.
Copyright ¨Ï 2008 CNET Networks, Inc. All Rights Reserved. 'ZDNet', 'CNET' and 'CNET News.com' are trademarks of CNET Networks, Inc.