๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

์›น ๋ชจ์˜ํ•ดํ‚น_4(DVWA๋ฅผ ํ™œ์šฉํ•œ File Upload, Insecure CAPTCHA)

์‹œํ๋ฆฌํ‹ฐ์ง€ํ˜ธ 2026. 1. 5.

์˜ค๋Š˜์€ File Upload, Insecure CAPTCHA์— ๋Œ€ํ•ด ์‹ค์Šตํ•˜๊ณ  ์ •๋ฆฌํ•˜์—ฌ ๋ฐœํ‘œ๋ฅผ ์ง„ํ–‰ํ–ˆ์Šต๋‹ˆ๋‹ค.

 

[๋ฐœํ‘œ ์ž๋ฃŒ]

[40แ„Œแ…ฎแ„Žแ…ก] แ„‹แ…ฐแ†ธ แ„†แ…ฉแ„‹แ…ดแ„’แ…ขแ„แ…ตแ†ผ_4(File Upload, Insecure CAPTCHA).pdf
1.81MB

 

*์ž์„ธํ•œ ์‹ค์Šต ๋‚ด์šฉ์€ ๋ฐœํ‘œ ์ž๋ฃŒ์— ์žˆ์Šต๋‹ˆ๋‹ค.

 

[4์ค„ ์š”์•ฝ]

 

1. File Upload ์ทจ์•ฝ์ ์€ ํ™ˆํŽ˜์ด์ง€ ๊ฒŒ์‹œํŒ์— ํ—ˆ์šฉ๋œ ํŒŒ์ผ(์ด๋ฏธ์ง€ ๋“ฑ) ์™ธ ์„œ๋ฒ„ ์‚ฌ์ด๋“œ ์Šคํฌ๋ฆฝํŠธ ํŒŒ์ผ(PHP, JSP, ASP ๋“ฑ)์ด ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๋Š” ์›น์„œ๋ฒ„์—์„œ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰์‹œ์ผœ ์ž„์˜์˜ ํŒŒ์ผ์„ ์—…๋กœ๋“œ ํ•ด ์›น ์ฝ˜ํ…์ธ ๋ฅผ ๋ณ€์กฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

2. ๋Œ€์‘๋ฐฉ์•ˆ

  • PHP ์œ„ํ—˜ ํ•จ์ˆ˜ ๋น„ํ™œ์„ฑํ™”(system, exec)
  • ์—…๋กœ๋“œ ํŒŒ์ผ ์‹คํ–‰ ๊ถŒํ•œ ์ œ๊ฑฐ ๋˜๋Š” ์ตœ์†Œํ™”
  • ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ ๊ธฐ๋ฐ˜ ์ •์ฑ… ์ ์šฉ
  • Egress ๋ฐฉํ™”๋ฒฝ ์ •์ฑ… ํ•„์ˆ˜ ์ ์šฉ
  • ์‹œ์Šคํ…œ ๋กœ๊ทธ ๋ฌด๊ฒฐ์„ฑ ๋ชจ๋‹ˆํ„ฐ๋ง

3. Insecure CAPTCHA๋Š” CAPTCHA ์ธ์ฆ์„ ์šฐํšŒํ•˜์—ฌ ๊ฐœ์ธ์ •๋ณด๋ฅผ ๋ณ€๊ฒฝํ•˜๊ฑฐ๋‚˜ ํƒˆ์ทจํ•˜๋Š” ๋“ฑ์˜ ๊ณต๊ฒฉ ์œ„ํ—˜์ด ์žˆ๋Š” ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

 

4. ๋Œ€์‘๋ฐฉ์•ˆ

  • ์š”์ฒญ ๋‹จ๊ณ„ ๋‹จ์ˆœํ™”
  • ์ถ”๊ฐ€ ์ธ์ฆ ๊ตฌํ˜„

๋Œ“๊ธ€