Recent posts

(bWAPP)Insecure FTP Configuration

์ทจ์•ฝ์  ์„ค๋ช… FTP ์„œ๋ฒ„์˜ ๊ตฌ์„ฑ์ด ์•ˆ์ „ํ•˜์ง€ ์•Š๋‹ค๋Š” ์‹œ๋‚˜๋ฆฌ์˜ค์ด๋ฉฐ, FTP ๋Š” ํŒŒ์ผ ์ „์†ก ํ”„๋กœํ† ์ฝœ๋กœ ์„œ๋ฒ„์™€ ํด๋ผ์ด์–ธํŠธ ๊ฐ„์— ์ „์†กํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋„คํŠธ์›Œํฌ ํ”„๋กœํ† ์ฝœ์ด๋‹ค. ์ด๋Ÿฌํ•œ FTP ํ”„๋กœํ† ์ฝœ์˜ ๋Œ€ํ‘œ์ ์ธ ๋ณด์•ˆ์  ์ด์Šˆ๋Š” โ€œ์•”ํ˜ธํ™” ๋˜์ง€ ์•Š์€ ํ‰๋ฌธ ์ „์†ก์œผ๋กœ ์ธํ•œ ์ค‘๊ฐ„์ž ๊ณต๊ฒฉ, Anonym...

Flawed Broadcast Receivers

Flawed Broadcast Receivers Broadcast Receivers๋ž€ ๋ฌด์—‡์ธ๊ฐ€? ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ 4๋Œ€ ๊ตฌ์„ฑ ๋‹จ์œ„์ค‘ ํ•˜๋‚˜๋กœ์„œ ์•ˆ๋“œ๋กœ์ด๋“œ ์•ฑ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์‹œ์Šคํ…œ ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ๋ฉ”์‹œ์ง€๋ฅผ ์ˆ˜์‹ ํ•˜์—ฌ ์ฒ˜๋ฆฌํ•˜๋Š” ๊ตฌ์„ฑ ์š”์†Œ์ด๋‹ค. ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ๋ฆฌ์‹œ๋ฒ„๋Š” ์•ˆ๋“œ๋กœ์ด๋“œ ์•ฑ์˜ ๋‹ค๋ฅธ ๊ตฌ...

(bWAPP)Denial-of-Service (XML Bomb)

์ทจ์•ฝ์  ์„ค๋ช… XML Bomb DoS๋Š” XML์„ ์ด์šฉํ•˜์—ฌ ์„œ๋ฒ„์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ณผ๋„ํ•˜๊ฒŒ ์†Œ๋ชจ์‹œ์ผœ ์„œ๋น„์Šค๋ฅผ ๋งˆ๋น„์‹œํ‚ค๋Š” DoS ๊ณต๊ฒฉ์˜ ์ผ์ข…์ด๋‹ค. ์ด๋Š” ์„œ๋ฒ„์˜ CPU ๋ฐ MEMORY ๋ถ€ํ•˜๋ฅผ ๋ฐœ์ƒ์‹œํ‚จ๋‹ค. ์•„ํŒŒ์น˜ ์›น ์„œ๋ฒ„๊ฐ€ ๋™์ž‘ ์ค‘์ด๋ฉฐ, xml dos์— ์ทจ์•ฝํ•˜๋‹ค๊ณ  ํ•œ๋‹ค. ...

(bWAPP)Denial-of-Service (Slow HTTP DoS)

์ทจ์•ฝ์  ์„ค๋ช… HTTP ์š”์ฒญ์—์„œ Header์™€ Body๋ถ€๋ถ„์„ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•ด header์˜ ๋งˆ์ง€๋ง‰ ๋ถ€๋ถ„์„ ํ‘œ์‹œํ•˜์—ฌ์•ผ ํ•œ๋‹ค. ์ด ๋•Œ ์‚ฌ์šฉ๋˜๋Š” ๊ฒƒ์ด CRLF์ธ๋ฐ ์ด๋Ÿฌํ•œ CRLF๋ฅผ 2๋ฒˆ ๋ณด๋‚ด์–ด ๋ฉ”์‹œ์ง€์˜ Header์˜ ๋งˆ์ง€๋ง‰์„ ์„ ์–ธํ•ด์•ผํ•˜์ง€๋งŒ, CRLF๋ฌธ์ž๋ฅผ 1๋ฒˆ๋งŒ ๋ณด๋‚ด empty lin...

(bWAPP)Denial-of-Service (SSL-Exhaustion)

์ทจ์•ฝ์  ์„ค๋ช… DoS๊ณต๊ฒฉ์ค‘ ํ•˜๋‚˜์ธ SSL-Exhaustion์€ SSL/TLS ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•œ ์„œ๋ฒ„์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ณ ๊ฐˆ์‹œ์ผœ ์„œ๋น„์Šค๋ฅผ ์ค‘๋‹จ์‹œํ‚ค๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ์ด๋Ÿฌํ•œ ๊ณต๊ฒฉ์€ ์„œ๋ฒ„๊ฐ€ SSL/TLS ํ•ธ๋“œ์…ฐ์ดํฌ๋ฅผ ์ฒ˜๋ฆฌํ•˜๋Š” ๋™์•ˆ ์ƒˆ๋กœ์šด ์—ฐ๊ฒฐ์„ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์—†์–ด ์„œ๋น„์Šค๋ฅผ ์ค‘๋‹จ์‹œํ‚ค๋Š” ์ ์„ ์•…์šฉํ•œ๋‹ค...