¾È±Ô °øºÎ¹æ

security > multipart/form-data;boundary=--------------------7d8f...

µî·ÏÀÏ : 2017-06-30 16:02 Á¶È¸¼ö : 53,130

Possible SQL injection in headers ¶ó´Â ¸Þ½ÃÁö´Â Çì´õ°ª Áß SQL injection °ø°ÝÀÌ °¡´ÉÇÑ Å°¿öµå°¡ ¸ÅÄ¡µÇ¾úÀ» ¶§ ¹ß»ýÇÕ´Ï´Ù.
 
SQL injection °ø°Ý ŽÁö´Â WebKnight.xml ÆÄÀÏÀÇ "SQL injection ¼½¼Ç"¿¡¼­ °ü¸®ÇÏ´Â Å°¿öµå°¡ µÎ°³ ÀÌ»ó ¸ÅÄ¡µÇ¾úÀ»¶§ 

AlertÀÌ ¹ß»ýÇϴµ¥, ÃÖ±Ùµé¾î Mass SQL injection °ø°Ý¿¡ ´ëÇÑ ´ëºñ·Î ÄíÅ° ¹× Çì´õ¸¦ ÅëÇÑ °ø°ÝÀ» ¹æÁöÇϱâ À§ÇØ 'Deny Header SQL injection' 

¿É¼ÇÀ» È°¼ºÈ­ Çؾ߸¸ ÇÕ´Ï´Ù.

±×·¯´Ù º¸´Ï ÆÄÀϾ÷·Îµå½Ã ºÙ°Ô µÇ´Â Çì´õ°ª ¶§¹®¿¡ SQL injection °ø°ÝÀ¸·ÎÀÇ ¿ÀŽÀÌ ¹ß»ýÇÏ´Â ¹®Á¦°¡ »ý°å½À´Ï´Ù.

÷ºÎµÈ À̹ÌÁö¸¦ º¸¸é "Content-type: multipart/form-data; boundary=--------------------7d8f..." ¶ó´Â ³»¿ëÀÌ ÀÖ½À´Ï´Ù.

WebKnight Á¤Ã¥¿¡¼­ SQL injection ¼½¼Ç¿¡´Â ±âº»ÀûÀ¸·Î ´ÙÀ½ÀÇ Å°¿öµå°¡ µî·ÏµÇ¾î Àִµ¥

';(¼¼¹ÌÄÝ·Ð)',  '--(ÇÏÀÌÇÂ2°³)'

ÀÌ Å°¿öµå ¶§¹®¿¡ ÆÄÀϾ÷·Îµå ÀÛ¾÷À» ÇÏ°Ô µÉ °æ¿ì Â÷´ÜÀÌ µÇ¾î ¿ÀŽÀÌ ¹ß»ýÇÏ´Â °ÍÀÔ´Ï´Ù. 

Å°¿öµå¸¦ ';--' ·Î ¼öÁ¤ÇÏ°í ´Ù¸¥ Çϳª¸¦ »èÁ¦ÇϽðųª ÀÚ½ÅÀÇ ¼­¹ö ¼³Á¤¿¡ ¸Â°Ô º¯°æÇϼž߸¸ ¿Ã¹Ù¸£°Ô »ç¿ëÀÌ °¡´ÉÇÕ´Ï´Ù.

¡Ø ÀÌ¿Í °°ÀÌ ÇÏ¿©µµ ÇØ°áµÇÁö ¾ÊÀ» ¶§´Â ·Î±× ³»¿ë¿¡¼­ SQL injection ¼½¼Ç¿¡ µî·ÏµÇ¾î ÀÖ´Â Å°¿öµå Áß ¸ÅÄ¡µÈ °ÍÀ» ã¾Æ ¼öÁ¤ÇÏ¼Å¾ß ÇÕ´Ï´Ù.

º°µµ·Î ÀÏÄ¡µÈ Å°¿öµå°¡ Ç¥½ÃµÇÁö ¾Ê±â ¶§¹®¿¡ ÇϳªÇϳª ãÀ¸¼Å¾ß ÇÕ´Ï´Ù.


"Headers" ¼½¼Ç¿¡¼­ "Allowed Content Types" ºÎºÐ¿¡ “multipart/form-data"¸¦ Ãß°¡ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.

ù ¹ø° ¶óÀÎÀº °ø¹éÀ¸·Î ³²°ÜµÎ¼Å¾ß ÇÕ´Ï´Ù.
¡Ø Ȥ½Ã µµ¿òÀÌ µÇ¼Ì´Ù¸é ´ñ±Û¿¡ ÇѸ¶µð ³²°ÜÁÖ¼¼¿ä!
ÀÛ¼ºÀÚ   ºñ¹Ð¹øÈ£
ÀÚµ¿±Û ¹æÁö     (ÀÚµ¿±Û ¹æÁö ±â´ÉÀÔ´Ï´Ù.)
³»¿ë   ´ñ±Û´Þ±â 
À̸ÞÀÏ ¹®ÀÇ : cak0280@nate.com  
Copyright 2000 By ENTERSOFT.KR All Rights Reserved.