Skip to Content
웹 애플리케이션 보안: 정찰, 공격, 방어 세 단계로 배우는 웹 애플리케이션 보안의 모든 것
book

웹 애플리케이션 보안: 정찰, 공격, 방어 세 단계로 배우는 웹 애플리케이션 보안의 모든 것

by 최용, 앤드루 호프먼
February 2021
Beginner to intermediate
372 pages
6h 48m
Korean
Hanbit Media, Inc.
Content preview from 웹 애플리케이션 보안: 정찰, 공격, 방어 세 단계로 배우는 웹 애플리케이션 보안의 모든 것
355
28
3부를 마치며
애플리케이션 보안 아키텍처는 해커가 어느 애플리케이션에 노력을 집중할지 평가할 때
매우 진지하게 받아들이는 신호라는 점에서 애플리케이션 코드 품질을 드러낸다.
28.3
공격
사이트 간 스크립팅(
XSS
)
애플리케이션이 사용자가 제공한 입력을 부적절한 방식으로 활용해 스크립트를 실행할
XSS
공격이 가능하다.
전통적 형태의
XSS
DOM
엘리먼트를 정제하거나
API
수준에서 적절히 완화하더라도
XSS
취약점 발생 가능성을 완전히 없애지 못한다. 브라우저
DOM
사양의 버그나 서드파
티 통합이 부적절하게 구현되어서
XSS
싱크가 존재한다.
사이트 간 요청 위조(
CSRF
)
CSRF
공격은 브라우저와 사용자 사이의 신뢰 관계를 이용한다. 애플리케이션을 올바로
구성하지 않으면 링크를 클릭하거나 웹 폼에 입력한 사용자를 대신한 높은 권한의 요청을
허용할 가능성이 있다.
손쉬운 먹잇감 (상태를 변경하는
HTTP
GET
요청 )을 이미 걸렀다면 웹 폼과 같은 대체
공격을 고려해야 한다.
XML
외부 엔티티(
XXE
)
XML
사양의 약점 때문에 부적절하게 구성된
XML
파서는 유효한
XML
요청 페이로드에
대한 응답으로 민감한 서버 파일을 유출할 수 있다.
이러한 취약점은 요청이
XML
이나 그와 비슷한 페이로드를 클라이언트로부터 직접 수용
할 때 종종 눈에 띄지만 더 복잡한 애플리케이션에서는 간접
XXE
가 가능할 수 있다. 서
버가
XML
객체를 직접 수용하지 않고 사용자로부터 페이로드를 받아
XML
파일을 ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

미술관에 GAN 딥러닝 실전 프로젝트: GAN으로 쓰기, 그리기, 게임하기, 작곡하기

미술관에 GAN 딥러닝 실전 프로젝트: GAN으로 쓰기, 그리기, 게임하기, 작곡하기

박해선, 데이비드 포스터
쿠버네티스 모범 사례: 쿠버네티스 창시자가 알려주는 최신 쿠버네티스 개발 및 배포 기법

쿠버네티스 모범 사례: 쿠버네티스 창시자가 알려주는 최신 쿠버네티스 개발 및 배포 기법

장정호, 브렌던 번스, 에디 비얄바, 데이브 스트레벨, 라클런 이븐슨

Publisher Resources

ISBN: 9791162243930