security > multipart/form-data;boundary=--------------------7d8f... µî·ÏÀÏ : 2017-06-30 16:02 Á¶È¸¼ö : 53,130Possible SQL injection in headers ¶ó´Â ¸Þ½ÃÁö´Â Çì´õ°ª Áß SQL injection °ø°ÝÀÌ °¡´ÉÇÑ Å°¿öµå°¡ ¸ÅÄ¡µÇ¾úÀ» ¶§ ¹ß»ýÇÕ´Ï´Ù.
SQL injection °ø°Ý ŽÁö´Â WebKnight.xml ÆÄÀÏÀÇ "SQL injection ¼½¼Ç"¿¡¼ °ü¸®ÇÏ´Â Å°¿öµå°¡ µÎ°³ ÀÌ»ó ¸ÅÄ¡µÇ¾úÀ»¶§ AlertÀÌ ¹ß»ýÇϴµ¥, ÃÖ±Ùµé¾î Mass SQL injection °ø°Ý¿¡ ´ëÇÑ ´ëºñ·Î ÄíÅ° ¹× Çì´õ¸¦ ÅëÇÑ °ø°ÝÀ» ¹æÁöÇϱâ À§ÇØ 'Deny Header SQL injection' ¿É¼ÇÀ» È°¼ºÈ Çؾ߸¸ ÇÕ´Ï´Ù. ±×·¯´Ù º¸´Ï ÆÄÀϾ÷·Îµå½Ã ºÙ°Ô µÇ´Â Çì´õ°ª ¶§¹®¿¡ SQL injection °ø°ÝÀ¸·ÎÀÇ ¿ÀŽÀÌ ¹ß»ýÇÏ´Â ¹®Á¦°¡ »ý°å½À´Ï´Ù. ÷ºÎµÈ À̹ÌÁö¸¦ º¸¸é "Content-type: multipart/form-data; boundary=--------------------7d8f..." ¶ó´Â ³»¿ëÀÌ ÀÖ½À´Ï´Ù. WebKnight Á¤Ã¥¿¡¼ SQL injection ¼½¼Ç¿¡´Â ±âº»ÀûÀ¸·Î ´ÙÀ½ÀÇ Å°¿öµå°¡ µî·ÏµÇ¾î Àִµ¥ ';(¼¼¹ÌÄÝ·Ð)', '--(ÇÏÀÌÇÂ2°³)' ÀÌ Å°¿öµå ¶§¹®¿¡ ÆÄÀϾ÷·Îµå ÀÛ¾÷À» ÇÏ°Ô µÉ °æ¿ì Â÷´ÜÀÌ µÇ¾î ¿ÀŽÀÌ ¹ß»ýÇÏ´Â °ÍÀÔ´Ï´Ù. Å°¿öµå¸¦ ';--' ·Î ¼öÁ¤ÇÏ°í ´Ù¸¥ Çϳª¸¦ »èÁ¦ÇϽðųª ÀÚ½ÅÀÇ ¼¹ö ¼³Á¤¿¡ ¸Â°Ô º¯°æÇϼž߸¸ ¿Ã¹Ù¸£°Ô »ç¿ëÀÌ °¡´ÉÇÕ´Ï´Ù. ¡Ø ÀÌ¿Í °°ÀÌ ÇÏ¿©µµ ÇØ°áµÇÁö ¾ÊÀ» ¶§´Â ·Î±× ³»¿ë¿¡¼ SQL injection ¼½¼Ç¿¡ µî·ÏµÇ¾î ÀÖ´Â Å°¿öµå Áß ¸ÅÄ¡µÈ °ÍÀ» ã¾Æ ¼öÁ¤ÇÏ¼Å¾ß ÇÕ´Ï´Ù. º°µµ·Î ÀÏÄ¡µÈ Å°¿öµå°¡ Ç¥½ÃµÇÁö ¾Ê±â ¶§¹®¿¡ ÇϳªÇϳª ãÀ¸¼Å¾ß ÇÕ´Ï´Ù. "Headers" ¼½¼Ç¿¡¼ "Allowed Content Types" ºÎºÐ¿¡ “multipart/form-data"¸¦ Ãß°¡ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù. ù ¹ø° ¶óÀÎÀº °ø¹éÀ¸·Î ³²°ÜµÎ¼Å¾ß ÇÕ´Ï´Ù.
|