๐Ÿ“— CS

[Security] SQL Injection, SSL/TLS, CORS, HTTPS, XSS, CSRF, DoS/DDoS, JWT

jcowwk 2025. 2. 14. 11:02

SQL Injection, SSL/TLS, CORS, HTTPS, XSS, CSRF, DoS/DDoS, JWT


1. SQL Injection

2. SSL/TLS

3. CORS

4. HTTPS

5. XSS

6. CSRF

7. DoS/DDoS

8. JWT


1. SQL Injection

์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ์ ์ ˆํžˆ ํ•„ํ„ฐ๋งํ•˜์ง€ ์•Š๊ณ  SQL ์ฟผ๋ฆฌ์— ์ง์ ‘ ์‚ฝ์ž…ํ•  ๊ฒฝ์šฐ ๋ฐœ์ƒํ•˜๋Š” ๋ณด์•ˆ ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

๊ณต๊ฒฉ์ž๋Š” ์•…์˜์ ์ธ SQL ๋ฌธ์„ ์‚ฝ์ž…ํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ์ •๋ณด๋ฅผ ์œ ์ถœํ•˜๊ฑฐ๋‚˜ ์กฐ์ž‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

SELECT * FROM users WHERE username = 'admin' OR 1=1 --' AND password = '์•„๋ฌด ๊ฐ’'

 

1=1์€ ํ•ญ์ƒ ์ฐธ์ด๋ฏ€๋กœ ๋ชจ๋“  ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

2. SSL/TLS

์ธํ„ฐ๋„ท์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์•”ํ˜ธํ™”ํ•˜์—ฌ ์•ˆ์ „ํ•˜๊ฒŒ ์ „์†กํ•˜๋Š” ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค.

SSL(Secure Sockets Layer)์˜ ๊ฐœ์„ ๋œ ๋ฒ„์ „์œผ๋กœ TLS(Transport Layer Security)๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

 

3. CORS

CORS(Cross-Origin Resource Sharing)์€ ๊ต์ฐจ ์ถœ์ฒ˜ ๋ฆฌ์†Œ์Šค ๊ณต์œ ๋กœ ๋‹ค๋ฅธ ๋„๋ฉ”์ธ์—์„œ ์š”์ฒญํ•˜๋Š” ๋ฆฌ์†Œ์Šค๋ฅผ ์ฐจ๋‹จํ•˜๋Š” ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ž…๋‹ˆ๋‹ค. ์„œ๋ฒ„์—์„œ Access-Control-Allow-Origin ํ—ค๋”๋ฅผ ์ ์ ˆํžˆ ์„ค์ •ํ•˜๊ฑฐ๋‚˜ CORS ๋ฏธ๋“ค์›จ์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

4. HTTPS

HTTPS๋Š” HTTP์— SSL/TLS ์•”ํ˜ธํ™”๋ฅผ ์ ์šฉํ•œ ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค.

๊ธฐ์กด์˜ HTTP์— ๋ณด์•ˆ์ด ์ ์šฉ๋˜์–ด ๋ฐ์ดํ„ฐ ๋ฌด๊ฒฐ์„ฑ์„ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค.

 

5. XSS

XSS(Cross-Site Scripting)๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ ์›น ์‚ฌ์ดํŠธ์— ์•…์„ฑ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฝ์ž…ํ•˜์—ฌ ์‚ฌ์šฉ์ž์˜ ๋ธŒ๋ผ์šฐ์ €์—์„œ ์‹คํ–‰๋˜๋„๋ก ํ•˜๋Š” ๊ณต๊ฒฉ์ž…๋‹ˆ๋‹ค.

 

6. CSRF

CSRF(Cross-Site Request Forgery)๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์ธ์ฆ๋œ ์ƒํƒœ์—์„œ ๊ณต๊ฒฉ์ž๊ฐ€ ์•…์˜์ ์ธ ์š”์ฒญ์„ ์ž๋™์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๊ฒŒ ๋งŒ๋“œ๋Š” ๊ณต๊ฒฉ์ž…๋‹ˆ๋‹ค.

 

7. DoS/DDoS

DoS(Denial of Service)๋Š” ํ•œ ์‹œ์Šคํ…œ์ด ๊ณผ๋ถ€ํ•˜๋ฅผ ์ผ์œผํ‚ค๋„๋ก ๋งŒ๋“ค์–ด ์ •์ƒ์ ์ธ ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•˜์ง€ ๋ชปํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.

DDoS(Distributed Denial of Service)๋Š” ์—ฌ๋Ÿฌ ๋Œ€์˜ ๊ฐ์—ผ๋œ ๊ธฐ๊ธฐ๋ฅผ ์ด์šฉํ•˜์—ฌ ๋™์‹œ ๋‹ค๋ฐœ์ ์ธ ๊ณต๊ฒฉ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

 

8. JWT

JWT(JSON Web Token)๋Š” ์‚ฌ์šฉ์ž ์ธ์ฆ ๋ฐ ๊ถŒํ•œ ๋ถ€์—ฌ๋ฅผ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ํ† ํฐ ๊ธฐ๋ฐ˜ ์ธ์ฆ ๋ฐฉ์‹์ž…๋‹ˆ๋‹ค.


์ฐธ๊ณ  ์‚ฌ์ดํŠธ

 

[CS/๊ธฐ์ˆ ๋ฉด์ ‘] ๋ณด์•ˆ ๊ด€๋ จ ๋ฌธ์ œ

๋ณด์•ˆ (Security)๊ณผ ๊ด€๋ จ๋œ ๋ฌธ์ œ๋“ค์€ ์–ด๋–ค ๊ฒƒ์ด ์žˆ๋‚˜์š”? [2023.04.21.๊ธˆ] ๋ฉ˜ํ† ๋ง (๋ฐ•์„ธ๋ช… ๊ธฐ์ˆ  ๋ฉ˜ํ† ๋‹˜) ๋ณด์•ˆ (Security)๊ณผ ๊ด€๋ จ๋œ ๋ฌธ์ œ๋“ค์€ ์–ด๋–ค ๊ฒƒ์ด ์žˆ๋‚˜์š”? ๋ฐฑ์—”๋“œ ๊ด€๋ จ์œผ๋กœ๋Š” HTTPS, SQL INJECTION, ์•…์„ฑ ์Šคํฌ

boleesystem.tistory.com

 

๋ฌธ์ œ๊ฐ€ ์žˆ์œผ๋ฉด ๋Œ“๊ธ€ ๋‚จ๊ฒจ์ฃผ์„ธ์š” !

ํ”ผ๋“œ๋ฐฑ์€ ์–ธ์ œ๋‚˜ ํ™˜์˜์ž…๋‹ˆ๋‹ค <3