Recent posts

(bWAPP)Denial-of-Service (XML Bomb)

์ทจ์•ฝ์  ์„ค๋ช… XML Bomb DoS๋Š” XML์„ ์ด์šฉํ•˜์—ฌ ์„œ๋ฒ„์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ณผ๋„ํ•˜๊ฒŒ ์†Œ๋ชจ์‹œ์ผœ ์„œ๋น„์Šค๋ฅผ ๋งˆ๋น„์‹œํ‚ค๋Š” DoS ๊ณต๊ฒฉ์˜ ์ผ์ข…์ด๋‹ค. ์ด๋Š” ์„œ๋ฒ„์˜ CPU ๋ฐ MEMORY ๋ถ€ํ•˜๋ฅผ ๋ฐœ์ƒ์‹œํ‚จ๋‹ค. ์•„ํŒŒ์น˜ ์›น ์„œ๋ฒ„๊ฐ€ ๋™์ž‘ ์ค‘์ด๋ฉฐ, xml dos์— ์ทจ์•ฝํ•˜๋‹ค๊ณ  ํ•œ๋‹ค. ...

(bWAPP)Denial-of-Service (Slow HTTP DoS)

์ทจ์•ฝ์  ์„ค๋ช… HTTP ์š”์ฒญ์—์„œ Header์™€ Body๋ถ€๋ถ„์„ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•ด header์˜ ๋งˆ์ง€๋ง‰ ๋ถ€๋ถ„์„ ํ‘œ์‹œํ•˜์—ฌ์•ผ ํ•œ๋‹ค. ์ด ๋•Œ ์‚ฌ์šฉ๋˜๋Š” ๊ฒƒ์ด CRLF์ธ๋ฐ ์ด๋Ÿฌํ•œ CRLF๋ฅผ 2๋ฒˆ ๋ณด๋‚ด์–ด ๋ฉ”์‹œ์ง€์˜ Header์˜ ๋งˆ์ง€๋ง‰์„ ์„ ์–ธํ•ด์•ผํ•˜์ง€๋งŒ, CRLF๋ฌธ์ž๋ฅผ 1๋ฒˆ๋งŒ ๋ณด๋‚ด empty lin...

(bWAPP)Denial-of-Service (SSL-Exhaustion)

์ทจ์•ฝ์  ์„ค๋ช… DoS๊ณต๊ฒฉ์ค‘ ํ•˜๋‚˜์ธ SSL-Exhaustion์€ SSL/TLS ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•œ ์„œ๋ฒ„์˜ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ณ ๊ฐˆ์‹œ์ผœ ์„œ๋น„์Šค๋ฅผ ์ค‘๋‹จ์‹œํ‚ค๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ์ด๋Ÿฌํ•œ ๊ณต๊ฒฉ์€ ์„œ๋ฒ„๊ฐ€ SSL/TLS ํ•ธ๋“œ์…ฐ์ดํฌ๋ฅผ ์ฒ˜๋ฆฌํ•˜๋Š” ๋™์•ˆ ์ƒˆ๋กœ์šด ์—ฐ๊ฒฐ์„ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์—†์–ด ์„œ๋น„์Šค๋ฅผ ์ค‘๋‹จ์‹œํ‚ค๋Š” ์ ์„ ์•…์šฉํ•œ๋‹ค...

Cross-site Tracing (XST)

ํ•ด๋‹น ์ทจ์•ฝ์ ์€ ๋ฌด์—‡์ธ๊ฐ€? XSS ๊ณต๊ฒฉ์˜ ์ข…๋ฅ˜์ค‘ ํ•˜๋‚˜๋กœ์„œ, XSS ๊ณต๊ฒฉ์„ ๋ฐฉ์–ดํ•˜๊ฑฐ ์œ„ํ•ด ๋งŒ๋“ค์–ด์ง„ ์ฟ ํ‚ค ์†์„ฑ ์ค‘ ํ•˜๋‚˜์ธ HTTPOnly ์†์„ฑ์„ ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋ฒ•์ด๋‹ค. HTTPOnly?? HTTPOnly๋Š” XSS ๊ณต๊ฒฉ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ์ฟ ํ‚ค ๊ฐ’์ด JavaScript๋ฅผ ํ†ต...

(bWAPP)Denial-of-Service (Large Chunk Size)

์ทจ์•ฝ์  ์„ค๋ช… DoS๋Š” ์„œ๋น„์Šค ๊ฑฐ๋ถ€ ๊ณต๊ฒฉ์œผ๋กœ, ๋Œ€์ƒ ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ๊ฐ€์šฉ์„ฑ์„ ๋ฌด๋„ˆ๋œจ๋ฆฌ๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ๋Œ€ํ‘œ์ ์œผ๋กœ ๋Œ€์—ญํญ ๊ณต๊ฒฉ, ๋ฆฌ์†Œ์Šค ๊ณ ๊ฐˆ, ํ”„๋กœํ† ์ฝœ ๊ณต๊ฒฉ, ๊ณต๊ฒฉ์ž ์ž์› ๊ณ ๊ฐˆ๋“ฑ์ด ์กด์žฌํ•œ๋‹ค. 8080/8443 ํฌํŠธ๋กœ Nginx ์›น ์„œ๋ฒ„๊ฐ€ ๋™์ž‘์ค‘์ด๋ฉฐ, ํ•ด๋‹น ์›น ์„œ๋ฒ„๋Š” chun...