nhn security division

43
NHN Security Division NHN Security Division NHN security analysis team, ์ „ ์ „์ „ 2007.04 ([email protected]) Web 2.0 Security

Upload: senwe

Post on 01-Feb-2016

60 views

Category:

Documents


0 download

DESCRIPTION

Web 2.0 Security. NHN security analysis team, ์ „ ์ƒํ›ˆ 2007.04 ([email protected]). NHN Security Division. Web 2.0 ? ์œ„ํ—˜์š”์†Œ ์œ„ํ—˜์˜ ๋ฐœ์ „๊ณผ ๋ฐฉํ–ฅ Web 2.0 threat? Countermeasure ๊ฒฐ๋ก ๊ณผ ์˜ˆ์ƒ. Contents. Web 2.0 ์ด๋ž€ ? ์‚ฌ์šฉ์ž์˜ ์ ๊ทน์ ์ธ ์ฐธ์—ฌ ๊ฐœ๋ฐฉ์„ฑ ์ง‘๋‹จ์ง€์„ฑ์˜ ์ถœํ˜„๊ณผ ํ™œ์šฉ ( ์‚ฌ์šฉ์ž์— ์˜ํ•œ ์ง€์‹์˜ ์ง‘๋Œ€์„ฑ ) ์‚ฌ์šฉ์ž์— ์˜ํ•œ ์ •๋ณด ๋ฐ ๋„คํŠธ์›Œํฌ ์ฐฝ์กฐ์™€ ๊ณต์œ  - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: NHN Security Division

NHN Security DivisionNHN Security Division

NHN security analysis team, ์ „ ์ƒํ›ˆ2007.04 ([email protected])

Web 2.0 Security

Page 2: NHN Security Division

NHN Security Division

Contents

โ€ข Web 2.0 ?โ€ข ์œ„ํ—˜์š”์†Œโ€ข ์œ„ํ—˜์˜ ๋ฐœ์ „๊ณผ ๋ฐฉํ–ฅโ€ข Web 2.0 threat?โ€ข Countermeasureโ€ข ๊ฒฐ๋ก ๊ณผ ์˜ˆ์ƒ

Page 3: NHN Security Division

NHN Security Division

Web 2.0 ?

โ€ข Web 2.0 ์ด๋ž€ ? โ€“ ์‚ฌ์šฉ์ž์˜ ์ ๊ทน์ ์ธ ์ฐธ์—ฌโ€“ ๊ฐœ๋ฐฉ์„ฑ โ€“ ์ง‘๋‹จ์ง€์„ฑ์˜ ์ถœํ˜„๊ณผ ํ™œ์šฉ ( ์‚ฌ์šฉ์ž์— ์˜ํ•œ ์ง€์‹์˜ ์ง‘๋Œ€์„ฑ )โ€“ ์‚ฌ์šฉ์ž์— ์˜ํ•œ ์ •๋ณด ๋ฐ ๋„คํŠธ์›Œํฌ ์ฐฝ์กฐ์™€ ๊ณต์œ โ€“ ๋ฉ€ํ‹ฐ ๋””๋ฐ”์ด์Šค ( Ubiquitous )โ€“ ์‚ฌ์šฉ์ž ์ ‘๊ทผ์„ฑ์˜ ํ–ฅ์ƒ ( RSS , Atom , AJAX , Open API โ€ฆ)

โ€ข Web 2.0 ๋น„์ฆˆ๋‹ˆ์Šคโ€“ ์‚ฌ์šฉ์ž์˜ ์˜๊ฒฌ์„ ์ ๊ทน์ ์œผ๋กœ ํ™œ์šฉ ํ•˜๊ณ  ์‚ฌ์šฉ์ž์˜ ์ ‘๊ทผ์„ฑ์„

๊ฐœ์„ ํ•˜์—ฌ ์ง์ ‘์ ์ธ ์‚ฌ์šฉ์ž์˜ ์ฐธ์—ฌ๋ฅผ ํ†ตํ•œ ์ด์ต๋ชจ๋ธ ์ฐฝ์ถœ

Page 4: NHN Security Division

NHN Security Division

Web 2.0 ?

โ€ข Web ์˜ paradigm shiftโ€“ Web 2.0 ์€ ํŠน๋ณ„ํ•œ ์šฉ์–ด๋‚˜ ํ˜„์ƒ์ธ๊ฐ€ ?โ€“ ๋„๊ตฌ๋กœ์„œ์˜ Web ์—์„œ ์ƒํ™œ ์†์˜ Webโ€“ Network ๋ฅผ ํ†ตํ•œ ๊ฐ€์ƒ์˜ ์‚ฌํšŒ -> ํ˜„์‹ค ์†์œผ๋กœ ( second life , blo

g , avatar )

Page 5: NHN Security Division

NHN Security Division

Web 2.0 ?

โ€ข UCC ( User Created Contents) โ€“ UCC ์˜ ์ •์˜

โ€ข ์ผ๋ฐ˜์ ์œผ๋กœ ๋™์˜์ƒ ๊ฒŒ์‹œ๋ฌผ์„ UCC ๋ผ ์นญํ•˜๋‚˜ ๋ชจ๋“  ๋ถ€๋ถ„์—์„œ ์‚ฌ์šฉ์ž๊ฐ€ ์ž‘์„ฑํ•˜๋Š” ์œ ํ˜•์˜ ์ธํ„ฐ๋„ท ํ™œ๋™์„ UCC ๋ผ ํ•  ์ˆ˜ ์žˆ๋‹ค .

โ€ข ๊ฒŒ์‹œ๋ฌผ , ๋ง๊ธ€ , ๋™์˜์ƒ , ์ด๋ฏธ์ง€ , ๋ฉ”์ผ๊ณผ ๊ฐ™์€ ์˜๊ฒฌ ๋ฐ ์ •๋ณด๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ๋ชจ๋“  ์œ ํ˜•์ด UCC

Page 6: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ํ™˜๊ฒฝ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ Web ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ํ˜„์žฌ์˜ ํ™˜๊ฒฝ ์ดํ•ด

โ€ข ๋‹ค์–‘ํ•œ online client method , ๋‹ค์–‘ํ•œ ์ ‘๊ทผ ๋ฐฉ๋ฒ• , ์‚ฌ์šฉ์ž ์ฐธ์—ฌ ์ผ๋ฐ˜ํ™”

โ€ข Ref: http://web2.wsj2.com

Page 7: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ํ™˜๊ฒฝ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข ๊ด‘๊ณ  (ActiveX) , ํ”ผ์‹ฑโ€ข ์•…์„ฑ์ฝ”๋“œ ์œ ํฌ โ€ข ๊ฐœ์ธ์ •๋ณด ๊ด€๋ จ ( ์ •๋ณด ์œ ์ถœ , ์š•์„ค , ๋น„๋ฐฉ , ํ—ˆ์œ„์‚ฌ์‹ค ) , ํ”ผ์‹ฑโ€ข Service Hacking

โ€“ XSS ( ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„์˜ XSS ๊ณต๊ฒฉ ), SQL Injection , XML , Request ์œ„์กฐ , DOM , script attack

โ€“ ๋งค๊ฐœ์ฒด ๋ณ„ โ€ข ๊ฒŒ์‹œ๋ฌผ โ€ข ๋ง๊ธ€ , RSS โ€ข ๋™์˜์ƒ , ์ด๋ฏธ์ง€ , Flash , Music โ€ฆ

โ€“ ๊ตฌ์กฐ๋ณ„ โ€ข Open API ( Mashup) ๋ฐ ๋‹ค์–‘ํ•œ ์ ‘๊ทผ ํ™˜๊ฒฝ ์ทจ์•ฝ์„ฑ ( Ajax , SOAP , DoM )โ€ข ์„œ๋น„์Šค๋ณ„ ๊ตฌ์„ฑ์š”์†Œ ๋ถ„์„์— ๋”ฐ๋ฅธ ์œ„ํ—˜ โ€“ ex )Myspace Attack

Page 8: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข ๊ด‘๊ณ  (ActiveX)

Page 9: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข ๊ด‘๊ณ  (RSS Advertising) ์ž๋™ํ™”๋œ RSS ๊ด‘๊ณ ์˜ ๋ฒ”๋žŒ

Page 10: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข Phishing ( ์‚ฌํšŒ ๊ณตํ•™์ ์ธ ๊ธฐ๋ฒ• โ€“ ์†์ž„์ˆ˜์™€ ๊ฒฐํ•ฉ ) ์—ฌ๋Ÿฌ ์œ ํ˜•์œผ๋กœ ๋ฐœ์ „

Page 11: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข ์•…์„ฑ์ฝ”๋“œ ์œ ํฌ ( 2006 ๋…„ 10 ์›” ์ดํ›„ )

07.3 ์›” ANI ํŒŒ์ผ ์ทจ์•ฝ์„ฑ

Page 12: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข Service Hacking - ex) Html / Script Injection โ€“ XSS Attackโ€“ XSS ( ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„์˜ XSS ๊ณต๊ฒฉ ), SQL Injection , XML , Request

์œ„์กฐ , DOM , script attack

RSS Example:

<item rdf:about="http://host/about.foo"><title> <script>alert(โ€˜Item

Title')</script> </title><link>http://host/?<script>alert('Item

Link')</script> </link><description><script>alert(โ€˜Item

Description')</script></description><author><script>alert(โ€˜Item

Author')</script> </author></item>

Atom Example

<entry xmlns="http://www.w3.org/2005/Atom">

<author><name> <script>alert('Entry Author Name')</script></name>

</author><published>2005-09-15T06:27:00-07:00</

published><updated>2005-09-15T13:33:06</updated><id>tag:url.com,1999:blog-6356614.post-

112679118286717848<script>alert('Entry ID')</script></id>

<title type="html"> <script>alert('Entry Title')</script> </title>

<content type="xhtml" xml:base="http://url"xml:space="preserve">

<div xmlns="http://www.w3.org/1999/xhtml"><script>alert('Entry Div

XMLNS')</script></div></content><draft

xmlns="http://purl.org/atom-blog/ns#">false</draft></entry>

Page 13: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข Service Hacking โ€“ XSS ( ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„์˜ XSS ๊ณต๊ฒฉ )( RSS โ€“security www.spidynamic.com ์ฐธ์กฐ )โ€“ Feedback attack

RSS Example

<item rdf:about="http://host/about.foo"><title> &lt;script&gt;alert(โ€˜Item

Title')&lt;/script&gt; </title><link>http://host/?&lt;script&gt;alert(โ€˜Item

Link')&lt;/script&gt; </link><description>&lt;script&gt;alert(โ€˜Item

Description')&lt;/script&gt;</description><author> &lt;script&gt;alert(โ€˜Item

Author')&lt;/script&gt; </author></item>

Atom Example

<entry xmlns="http://www.w3.org/2005/Atom"><author><name>&lt;script&gt;alert('Entry Author

Name')&lt;/script&gt;</name></author><published>2005-09-15T06:27:00-07:00</

published><updated>2005-09-15T13:33:06</updated><link href="http://url/?

&lt;script&gt;alert('Entry Link')&lt;/script&gt;"

rel="alternate" title="&lt;script&gt;alert('Entry Link Title')&lt;/script&gt;"type="text/html"/>

<id>tag:url.com,1999:blog-6356614.post-112679118286717848&lt;script&gt;alert('Entry ID')&lt;/script&gt;</id>

<div xmlns="http://www.w3.org/1999/xhtml">&lt;script&gt;alert('Entry Div XMLNS')

&lt;/script&gt;</div></content><draft

xmlns="http://purl.org/atom-blog/ns#">false</draft></entry>

Page 14: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข Service Hacking โ€“ XSS ( ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„์˜ XSS ๊ณต๊ฒฉ ) 2006 ๋…„ 7 ์›” Google RSS Reader XSS

์ทจ์•ฝ์„ฑ http://ha.ckers.org/blog/20060704/cross-site-scripting-vulnerability-in-google/

Page 15: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ๊ธฐ์ˆ ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ์œ ํ˜•๋ณ„

โ€ข Service Hacking ( XSS , SQL Injection)

Page 16: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ํ™˜๊ฒฝ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ๋งค๊ฐœ์ฒด ๋ณ„

โ€ข ๊ฒŒ์‹œ๋ฌผ โ€“ ๊ฒŒ์‹œํŒ์— ์•…์„ฑ์ฝ”๋“œ ์„ค์น˜ ๋ฃจํ‹ด์ด๋‚˜ ์‚ฌ์šฉ์ž ์ •๋ณด ์œ ์ถœ ํ•˜๋Š” XSS ์ทจ์•ฝ์„ฑ ๊ณต๊ฒฉ

๋ฃจํ‹ด์„ ์ž‘์„ฑ ํ•˜์—ฌ ์˜ฌ๋ฆผ โ€“ ์•…์„ฑ์ฝ”๋“œ ์‹คํ–‰ ๋ฃจํ‹ด์ด ํฌํ•จ๋œ ๊ฒŒ์‹œ๋ฌผ ํด๋ฆญ ์‹œ์— ์„ค์น˜ ๋˜๊ฑฐ๋‚˜ ์ •๋ณด ์œ ์ถœ

Page 17: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ํ™˜๊ฒฝ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ๋งค๊ฐœ์ฒด ๋ณ„

โ€ข ๋™์˜์ƒ , ์ด๋ฏธ์ง€ , Flash , Music โ€“ Ex) mp3 ํŒŒ์ผ์— ํฌํ•จ๋œ ์•…์„ฑ์ฝ”๋“œ example

Page 18: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ํ™˜๊ฒฝ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ๋งค๊ฐœ์ฒด ๋ณ„

โ€ข ๋™์˜์ƒ , ์ด๋ฏธ์ง€ , Flash , Musicโ€“ Ex) Apple ์˜ quicktime ๋™์˜์ƒ์„ ์ด์šฉํ•œ ์•…์„ฑ์ฝ”๋“œ ์„ค์น˜

ยป 2006.12 ์›” Myspace Attack ์— ์‚ฌ์šฉ

Page 19: NHN Security Division

NHN Security Division

์œ„ํ—˜์š”์†Œ

โ€ข Web ํ™˜๊ฒฝ์˜ ๋ฐœ์ „์— ๋”ฐ๋ฅธ ์œ„ํ—˜์š”์†Œ โ€“ ๋งค๊ฐœ์ฒด ๋ณ„

โ€ข ๋™์˜์ƒ , ์ด๋ฏธ์ง€ , Flash , Musicโ€“ Ex) Flash ๋ฅผ ํ†ตํ•œ ์•…์„ฑ์ฝ”๋“œ ์œ ํฌ , ๋™์˜์ƒ์ค‘๊ฐ„์— ์‚ฝ์ž…๋œ ์•…์„ฑ์ฝ”๋“œ

Page 20: NHN Security Division

NHN Security Division

์œ„ํ—˜์˜ ๋ฐœ์ „๊ณผ ๋ฐฉํ–ฅ

โ€ข Application Attack

Page 21: NHN Security Division

NHN Security Division

์œ„ํ—˜์˜ ๋ฐœ์ „๊ณผ ๋ฐฉํ–ฅ

โ€ข Application Attack Flow

Page 22: NHN Security Division

NHN Security Division

์œ„ํ—˜์˜ ๋ฐœ์ „๊ณผ ๋ฐฉํ–ฅ

โ€ข Application Attack ( Ubiquitous service Attack) โ€“ platform์— ๊ด€๊ณ„ ์—†๋Š” Application Attack์˜ ์ผ๋ฐ˜ํ™”โ€“ ์ผ๋ฐ˜ Application ๋ฐ ํ‘œ์ค€๊ทœ๊ฒฉ์˜ ๋‹ค์–‘ํ•œ ํ”Œ๋žซํผ ํƒ‘์žฌ ( TV , PDA , ๊ฐ€์ •์šฉ ๊ธฐ๊ธฐ ,Handphone โ€ฆ ) ex) Java , web , xml โ€ฆ

Page 23: NHN Security Division

NHN Security Division

Web 2.0 threat?

โ€ข Web 2.0 threat ํŠน์ง• ?

โ€“ Application worm โ€“ ํŠน์ • ์„œ๋น„์Šค์— ํŠนํ™”๋œ Worm โ€“ Ubiquitous service attack ( ๋‹ค์–‘ํ•œ ์ ‘์† ๋งค๊ฐœ์ฒด )โ€“ ๋‹ค์–‘ํ•œ platform attack

โ€ข ์—ฌ๋Ÿฌ ์ข…๋ฅ˜์˜ ํ†ต์‹  ๊ทœ์•ฝ , ์—ฌ๋Ÿฌ ์ข…๋ฅ˜์˜ Application ๊ณต๊ฒฉํ•˜๋Š” ์œ ํ˜•์˜ Monster application attack ์ถœํ˜„ ๊ฐ€๋Šฅ์„ฑ

Page 24: NHN Security Division

NHN Security Division

Web 2.0 threat?

โ€ข Application wormโ€ข ์ตœ์ดˆ santy worm ( 2004 ๋…„ 12 ์›” )

์ทจ์•ฝ Application ์„œ๋ฒ„Attacker

1. APP ์ทจ์•ฝ์„ฑ์„ ์ด์šฉ ์ตœ์ดˆ๊ณต๊ฒฉ

Worm Process

Application Worm( ex โ€“Santy worm)

2. ๊ฒ€์ƒ‰์—”์ง„ ์ด์šฉ ์ทจ์•ฝํ•œ ์„œ๋ฒ„ ๊ฒ€์ƒ‰ ํ›„ ๊ณต๊ฒฉ

์ทจ์•ฝ Application ์„œ๋ฒ„

์ทจ์•ฝ Application ์„œ๋ฒ„

์ทจ์•ฝ Application ์„œ๋ฒ„

Page 25: NHN Security Division

NHN Security Division

Web 2.0 threat?

โ€ข Application wormโ€ข ๊ณต๊ฐœ์šฉ ๊ฒŒ์‹œํŒ ์ทจ์•ฝ์„ฑ์„ ์ด์šฉํ•œ Application worm

Web Server Application ServerAttacker

1. APP ์ทจ์•ฝ์„ฑ์„ ์ด์šฉ ์™ธ๋ถ€ ํŒŒ์ผ ์‹คํ–‰ ๋ช…๋ น

์•…์„ฑ์ฝ”๋“œ ์—…๋กœ๋“œ ์‚ฌ์ดํŠธ

PHP Web Server

3. Option ์— ๋”ฐ๋ฅธ ๋ช…๋ น ์‹คํ–‰

2. ์™ธ๋ถ€ ์‚ฌ์ดํŠธ์˜ ์ฝ”๋“œ๊ฐ€ ๋Œ€์ƒ์„œ๋ฒ„์—์„œ ์‹คํ–‰๋จ

Reverse Backdoor

Local root exploit

์•…์„ฑ ์ฝ”๋“œ ์˜ต์…˜. Option ์—์„œ Exploit ์„ ์„ ํƒ ํ•  ๋•Œ์›น์„œ๋ฒ„๋‚ด์— Local exploit ํŒŒ์ผ์„ํŒŒ์ผ๋กœ ์“ฐ๊ณ  ์ƒ์„ฑ์„ ์‹œํ‚ด

. ์•…์„ฑ์ฝ”๋“œ๋‚ด ๋ช…๋ น ์ž…๋ ฅ์ฐฝ์—์„œ Exploit์‹คํ–‰

. ์›น์ƒ์—์„œ root ๊ถŒํ•œ ํš๋“

Page 26: NHN Security Division

NHN Security Division

Web 2.0 threat?

โ€ข Service Application wormโ€ข ex) myspace , ๋‹ค๋ฅธ ์„œ๋น„์Šค๋“ค๋„ ์œ ์‚ฌํ•œ ํ˜•ํƒœ์˜ ๊ณต๊ฒฉ ์œ„ํ—˜์„ฑ

Page 27: NHN Security Division

NHN Security Division

Web 2.0 threat?

โ€ข Service Application wormโ€ข ex) yahoo messenger attack (YH032.explr)

Yahoo ChattingAttacker

1. Yahoo Messenger Attack Code Insert

2. ์•…์„ฑ์ฝ”๋“œ ์‚ฌ์šฉ์ž ๋…ธ์ถœ๋ฐ ๊ฐ์—ผ

์ฑ„ํŒ… ์‚ฌ์šฉ์ž

3. ๊ฐ€์งœ IE Icon ์ƒ์„ฑ

์•…์„ฑ์ฝ”๋“œ ๋ฐฐํฌ์‚ฌ์ดํŠธ

4. ์ŠคํŒŒ์ด ์›จ์–ด ์„ค์น˜5. ๋“ฑ๋ก์ž List ์—์„œ Script base worm ์žฌ์ „์†ก

Page 28: NHN Security Division

NHN Security Division

Countermeasure

โ€ข Web 2.0 ์€ ํŒจ๋Ÿฌ๋‹ค์ž„์˜ ๋ณ€ํ™” ์ด๋ฏ€๋กœ ๋‹จ์ˆœ ์š”์†Œ ๊ธฐ์ˆ ๋กœ๋Š” ๋Œ€์‘์ด ์–ด๋ ค์›€

โ€ข Technical Base โ€“ Filtering

โ€ข ์‚ฌ์šฉ์ž ์ž…๋ ฅ์˜ Filtering ( ๊ธฐ์ˆ ์  , ์ •์ฑ…์  ์ด์Šˆ )โ€ข ์œ„ํ—˜์š”์†Œ ํŒ๋ณ„์„ ์œ„ํ•œ ์ž๋™ ํŒ๋ณ„ ์‹œ์Šคํ…œ์˜ ๊ตฌ์ถ• ๋ฐ ์šด์šฉ

โ€“ Platform ์˜ ์ฒด๊ณ„ํ™”โ€ข Filtering system ์˜ ์ฒด๊ณ„ํ™” ๋ฐ ๊ตฌ์กฐํ™”โ€ข ์ „๋ฌธ ๋ณด์•ˆ ์ธ๋ ฅ์˜ ์šด์šฉ๊ณผ ํ•ฉ๋ฆฌ์ ์ธ ํ”„๋กœ์„ธ์Šค ์ˆ˜๋ฆฝ

โ€“ Monitoringโ€ข ์ธ๋ ฅ์„ ์ด์šฉํ•œ ์ด์Šˆ ๋ชจ๋‹ˆํ„ฐ๋งโ€ข ์ž๋™ Filtering ์˜ˆ์™ธ ์‚ฌ์•ˆ์˜ ์ˆ˜์‹œ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ Rule Updateโ€ข ์‹ ๊ทœ ์ทจ์•ฝ์„ฑ์— ๋Œ€ํ•œ ๋ชจ๋‹ˆํ„ฐ๋ง

โ€“ ๋ณด์•ˆ์„ฑ ๊ฒ€์ˆ˜ (Black box Test)โ€ข ์ „๋ฌธ ์ธ๋ ฅ์„ ์ด์šฉํ•œ ์›น ์„œ๋น„์Šค ๋ฐ Application ์— ๋Œ€ํ•œ ๋ณด์•ˆ์„ฑ ๊ฒ€์ˆ˜โ€ข ์ทจ์•ฝ์„ฑ ๋ชจ๋‹ˆํ„ฐ๋ง์„ ํ†ตํ•œ ์ทจ์•ฝ๋ถ€๋ถ„ ์ผ๊ด„ ์ ์šฉ ๋ฐ ๋ฌธ์ œ ํ•ด๊ฒฐ ํ”„๋กœ์„ธ์Šคโ€ข Open Api ์ทจ์•ฝ์„ฑ์— ๋Œ€ํ•œ ๊ฒ€์ฆ

Page 29: NHN Security Division

NHN Security Division

Countermeasure

โ€ข Technical Base

โ€“ Filtering ( ๊ฒŒ์‹œํŒ , ๊ฒŒ์‹œ๋ฌผ , ๋ง๊ธ€ , ์ด๋ฏธ์ง€ , Flash , ๋™์˜์ƒ โ€ฆ )

โ€ข ๊ด‘๊ณ  Filteringโ€ข ActiveX ์™ธ ์•…์„ฑ์ฝ”๋“œ ์„ค์น˜ ์œ ํ˜• Fiteringโ€ข ์•…์„ฑ์ฝ”๋“œ ํฌํ•จ๋œ ์ด๋ฏธ์ง€์— ๋Œ€ํ•œ Filtering ( string)โ€ข Flash , ๋™์˜์ƒ์— ๋Œ€ํ•œ Pop up ์ด์Šˆ ํŒ๋ณ„์„ ํ†ตํ•œ filteringโ€ข ์š•์„ค , ์„ฑ์ธ ๊ด€๋ จ๋ฌผ์— ๋Œ€ํ•œ Filteringโ€ข ์•…์„ฑ์ฝ”๋“œ , ํ•ดํ‚นํˆด , Virus ์˜ File Upload ์— ๋Œ€ํ•œ Filtering

Page 30: NHN Security Division

NHN Security Division

Countermeasure โ€“ service owner

โ€ข Technical Base

โ€“ Platform ์˜ ์ฒด๊ณ„ํ™”โ€ข Filtering ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ์ฒด๊ณ„์ ์ธ ๊ตฌ์„ฑโ€ข ์ „์ฒด ์‚ฌ์šฉ์ž ์ž…๋ ฅ์— ๋Œ€ํ•œ Filtering ๊ตฌ์กฐ ์ˆ˜๋ฆฝโ€ข ์ „๋ฌธ ์ธ๋ ฅ์˜ ์—ฐ๊ตฌ์— ์˜ํ•œ Filtering Rule ๊ฐฑ์‹  ๋ฐ ์ถ”๊ฐ€โ€ข ์‚ฌ์šฉ์ž์˜ ์ง์ ‘ ์ž…๋ ฅ์— ๋Œ€ํ•œ ๋น ๋ฅธ ๋ชจ๋‹ˆํ„ฐ๋ง ๊ตฌ์กฐ ์ˆ˜๋ฆฝโ€ข ์‹ ๊ทœ Filtering issue ๋ฐœ์ƒ์‹œ์˜ ์—…๋ฌด ๋ถ„๋‹ด ๋ฐ ์ฒด๊ณ„์ ์ธ ๋Œ€์‘ ๊ตฌ์กฐ

์ˆ˜๋ฆฝ

Page 31: NHN Security Division

NHN Security Division

Countermeasure โ€“ service owner

โ€ข Technical Base

โ€“ Monitoringโ€ข ๋™์˜์ƒ์— ๋Œ€ํ•œ ๋ชจ๋‹ˆํ„ฐ๋ง ( ์„ฑ์ธ๋ฌผ , ์•…์„ฑ์ฝ”๋“œ ํŒ์—… , ์„ค์น˜ ์œ ํ˜• )โ€ข ๋น„์ •์ƒ ํ–‰์œ„์— ๋Œ€ํ•œ ํŠน์ด์‚ฌํ•ญ ๋ชจ๋‹ˆํ„ฐ๋ง โ€“ ์‹ ๊ทœ ์œ ํ˜• ํƒ์ง€โ€ข ๊ฐœ์ธ์ •๋ณด ์นจํ•ด ์‚ฌ์•ˆ์— ๋Œ€ํ•œ ์ง์ ‘ ๋ชจ๋‹ˆํ„ฐ๋งโ€ข Filtering ์ดํ›„์˜ ๊ฒฐ๊ณผ์— ๋Œ€ํ•œ Sample ๋ชจ๋‹ˆํ„ฐ๋งโ€ข ์ „๋ฌธ ์ธ๋ ฅ์— ์˜ํ•œ ์‹ ๊ทœ ์ทจ์•ฝ์„ฑ ์ „๋‹ด ๋ชจ๋‹ˆํ„ฐ๋ง โ€ข Customer service ์ด์ƒ ์ง•ํ›„ ์‹ ๊ณ ์— ๋Œ€ํ•œ ๋ชจ๋‹ˆํ„ฐ๋ง ๊ฐ•ํ™”โ€ข Service Abusing ๋ฐœ๊ฒฌ์„ ์œ„ํ•œ ๋กœ๊ทธ ๋ชจ๋‹ˆํ„ฐ๋งโ€ข RSS ,Atom ๊ณผ ๊ฐ™์€ ์ „๋‹ฌ method ์™€ ๊ธฐ์ˆ ์  ์ด์Šˆ ๋ชจ๋‹ˆํ„ฐ๋ง

Page 32: NHN Security Division

NHN Security Division

Countermeasure โ€“ service owner

โ€ข Technical Baseโ€“ ๋ณด์•ˆ์„ฑ ๊ฒ€์ˆ˜ (Web , Application ์ทจ์•ฝ์„ฑ ์ œ๊ฑฐ )

โ€ข secure coding & secure inspection

๊ฐœ๋ฐœ ๋ถ€์„œProject Owner SubmitsRequest

Perform Assessment

Generate Report Project Approved

์œ„ํ—˜๊ฐ์ˆ˜์ •์ฑ…์ ์ธ ์˜ˆ์™ธ

ReviewRequest

Review Report

CriticalVulnerabilities?

No

Review Report

Yes

ApplyFixes

Fix orgo live?

Go liveFix

AssessmentApproved?

RequestDeferred or Rejected

Yes

No

Risk Discovery

๊ฒฝ์˜์ธต

IT Security

์‚ฌ์—…๋ถ€์„œ

App ๋ณด์•ˆ์„ฑ ๊ฒ€์ˆ˜ ๋ฐ˜๋ณต

Page 33: NHN Security Division

NHN Security Division

Countermeasure โ€“ service owner

โ€ข Technical Baseโ€“ ๋ณด์•ˆ์„ฑ ๊ฒ€์ˆ˜์™€ SDLC ( secure development life cycle)

โ€ข ์—ญ๋Ÿ‰ ์žˆ๋Š” ๋ณด์•ˆ ์ „๋ฌธ๊ฐ€ ์ง‘๋‹จ ์ด๋‚˜ ์กฐ์ง์„ ํ™œ์šฉํ•œ ์ทจ์•ฝ์„ฑ ์ ๊ฒ€

Page 34: NHN Security Division

NHN Security Division

Countermeasure โ€“ user

โ€ข ์‚ฌ์šฉ์ž์˜ ๋Œ€์‘ โ€“ ๊ฐœ์ธ PC ์ฐจ์›์˜ ๋ณดํ˜ธ ๋ฐฉ์•ˆ ์ˆ˜๋ฆฝ

โ€ข Phishing ์ฃผ์˜ ( ๋ฉ”์ผ , ๋งํฌ โ€ฆ )โ€ข ์ฒจ๋ถ€ํŒŒ์ผ ์ฃผ์˜ ( Zeroday worm โ€ฆ)โ€ข ์•Œ๋ ค์ง„ ์œ„ํ—˜์š”์†Œ์˜ ์ตœ์†Œํ™” ( ๋ณด์•ˆ ํŒจ์น˜ , AV )โ€ข ActiveX ์˜ ์‹œ์Šคํ…œ ์„ค์น˜ ์ œํ•œโ€ข ์ฃผ๊ธฐ์ ์ธ ๋ณด์•ˆ ์„ค์ • ํ™•์ธ ( ๋ณด์•ˆํŒจ์น˜ , AV update)โ€ข ์ฃผ๊ธฐ์  ํŒจ์Šค์›Œ๋“œ ๋ณ€๊ฒฝโ€ข ์‹ ๋ขฐ ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๊ด€์˜ ๋ณด์•ˆ ์„ค์ • ์„ค์น˜โ€ข ์‚ฌ์ดํŠธ๋ณ„ ์ค‘์š”๋„์— ๋”ฐ๋ฅธ ๋ณด์•ˆ ๋งˆ์ธ๋“œ ( ํŒจ์Šค์›Œ๋“œ , ๊ฐ€์ž… ์—ฌ๋ถ€ )

Page 35: NHN Security Division

NHN Security Division

Countermeasure

โ€ข ์ •์ฑ…์ ์ธ ๋Œ€์‘ โ€“ ISO27001 , ISMS ์˜ ์‹คํšจ์ ์ธ ๊ด€๋ฆฌ ( ์‹ค๋ฌด์ ์ธ ๋ณด์•ˆ์„ฑ ์ธก๋ฉด )โ€“ White list ์˜ ๊ด€๋ฆฌ ( site , program โ€ฆ )โ€“ ๋ณด์•ˆ ์ „๋ฌธ ์ธ๋ ฅ์˜ ํšจ์œจ์ ์ธ ์œก์„ฑ๋ฐฉ์•ˆ ์ˆ˜๋ฆฝโ€“ ๋ชจ๋‹ˆํ„ฐ๋ง ์ฒด์ œ ๋ฐ Filtering ์— ๋Œ€ํ•œ ๋ฐฉ์•ˆ ์ˆ˜๋ฆฝ ๊ถŒ๊ณ 

Page 36: NHN Security Division

NHN Security Division

๊ฒฐ๋ก ๊ณผ ์˜ˆ์ƒ

โ€ข ์œ„ํ˜‘์€ ์ง€์†๋œ๋‹ค .โ€ข โ€œ ์ธ๊ฐ„์ ์ธ ๋„ˆ๋ฌด๋‚˜ ์ธ๊ฐ„์ ์ธโ€ ์ฐธ์—ฌ๋Š” ํ˜„์žฌ ์ง„ํ–‰ํ˜•โ€ข Service Application attack ์˜ ์ผ๋ฐ˜ํ™”โ€ข ํŠนํ™”๋œ ์กฐ๊ฑด์˜ Attack ( service ๋ณ„ ๊ณต๊ฒฉ )โ€ข ๊ธฐ์ˆ ์ ์ธ ๋ณด์•ˆ์˜ ์ค‘์š”์„ฑโ€ข Web 2.0 ์€ ๋ณ€ํ™”์˜ ๊ณผ์ •์ด๋ฉฐ ํ–ฅํ›„๋ฅผ ๋Œ€๋น„ํ•˜์—ฌ ์ถฉ๋ถ„ํ•œ

๋ชจ๋‹ˆํ„ฐ๋ง๊ณผ ํ”„๋กœ์„ธ์Šค์˜ ์ˆ˜๋ฆฝ์ด ํ•„์š” .

P4ssion is never fade away

Page 37: NHN Security Division

NHN Security Division

Q & A

Page 38: NHN Security Division

NHN Security Division

๋ณ„์ฒจ ( SQL Injection & XSS ๋Œ€์ฑ… )

ํ…์ŠคํŠธ ๋ฌธ์žฅ์˜ ๊ฐ€์šด๋ฐ์— ํŠน์ˆ˜ ๋ฌธ์ž๊ฐ€ ๋‚˜์˜ฌ๊ฒฝ์šฐ ( HTML ๋กœ ๋ฌธ์žฅ์ด ํ‘œํ˜„๋  ๊ฒฝ์šฐ )โ€œ<โ€ ํƒœ๊ทธ๋ฅผ ์‹œ์ž‘ํ•˜๋Š” ๋ฌธ์ž , โ€œ&โ€ ๋ฌธ์ž ์†์„ฑ์„ ๋‚˜ํƒ€๋‚ด๋Š” ๋ฌธ์ž , โ€œ>โ€ ํƒœ๊ทธ์˜ ๋์„ ๋‚˜ํƒ€๋‚ด๋Š” ๋ฌธ์ž์˜ ๊ฒฝ์šฐ ์ฒ˜๋ฆฌ๊ฐ€ ํ•„์š”ํ•˜๋‹ค . โ€“

<script> </script> ์˜ body ๋ถ€๋ถ„์— ์œ„์น˜ํ•˜๋Š” ๋ฌธ์ž์˜ ๊ฒฝ์šฐ์„ธ๋ฏธ์ฝœ๋ก ๊ณผ {} , [] ๋ฌธ์ž๋“ค์€ ํ•„ํ„ฐ๋ง์ด ์ด๋ฃจ์–ด ์ ธ์•ผ ํ•œ๋‹ค .

< , > ๋ฌธ์ž์— ๋Œ€ํ•œ ์น˜ํ™˜ ํ˜น์€ <script , </script> ๋ฌธ์žฅ์ด HTML ์ž…๋ ฅ ํ•„๋“œ ๋‚ด์— ์ถœํ˜„ํ•  ๊ฒฝ์šฐ์—๋Š” ๋ฐ˜๋“œ์‹œ ์น˜ํ™˜์ด ๋˜์–ด < = &lt , > =&gt ๋“ฑ์˜ ๋ฌธ์ž๋กœ ์น˜ํ™˜ํ•˜์—ฌ ํ–‰์œ„๊ฐ€ ๋ฐœ์ƒํ•˜์ง€ ์•Š๋„๋ก ์ฒ˜๋ฆฌํ•  ๊ฒƒ์„ ๊ถŒ๊ณ ํ•œ๋‹ค .

๋ณ€ํ™˜ ๋Œ€์ƒ(From)

๋ณ€ํ™˜๊ฐ’ (To)

< &lt;

> &gt;

( &#40;

) &#41;

# &#35;

& &#38;

Page 39: NHN Security Division

NHN Security Division

โ€ข Web Application ์ธ์ž์˜ ์œ ํšจ์„ฑ ์ฒดํฌ ( RSS ,Atom ๋“ฑ์— ๋Œ€ํ•ด์„œ๋Š” ๋ณ„๋„ ๊ตฌ์„ฑ ํ•„์š” )

โ€“ DB ์ฟผ๋ฆฌ์— ๋ณ€์ˆ˜๋กœ ์‚ฌ์šฉ๋˜๋Š” ๋ชจ๋“  ์ธ์ž์— ๋Œ€ํ•ด ์ž…๋ ฅ๊ฐ’ ๊ฒ€์ฆ์ด ์ˆ˜ํ–‰ ๋˜์–ด์•ผ ํ•จโ€ข single quote ํ•˜๋‚˜๋ฅผ single quote ๋‘ ๊ฐœ๋กœ replace ํ•˜๊ฑฐ๋‚˜ \'๋กœ replace

data = replace(data, "'", "''") , data = replace(data, "'", "\'") โ€ข semi colon ๊ณผ double dash ์ œ๊ฑฐโ€ข ์ •์ˆ˜์ด์—ฌ์•ผ๋งŒํ•˜๋Š” ์ž…๋ ฅ๊ฐ’์— ๋Œ€ํ•ด ์ •์ˆ˜๊ฐ’ ์—ฌ๋ถ€ ์ฒดํฌ

Use IsNumeric Functionโ€ข ๊ธธ์ด ์ฒดํฌ : DB์ปฌ๋Ÿผ์˜ ํฌ๊ธฐ์™€ ๊ฐ™๊ฑฐ๋‚˜ ์ž‘์€์ง€ ์ฒดํฌ โ€ข ' , <,>,; ,-- ์™€ ๊ฐ™์€ ๋ฌธ์ž๊ฐ€ ๋ณ€์ˆ˜์— ์กด์žฌ ํ•˜์ง€ ์•Š๋„๋ก ๊ฐ•๋ ฅํ•œ ์ฒดํฌ ํ•„์š”

โ€“ SQL Injection ๋ฐ Validation Checking program ์˜ ์‚ฌ์šฉ ๋ฐ ์ฃผ๊ธฐ์  ์ ๊ฒ€ ํ•„์š”โ€“ Application ๊ฐœ๋ฐœ์ž์˜ ๋ณด์•ˆ ๋ฌธ์ œ ์ธ์‹์„ ํ†ตํ•œ ์Šต๊ด€ํ™”๋œ ์ธ์ž ์œ ํšจ์„ฑ ์ฒดํฌ ํ•„์š”

โ€ข DB ์˜ ๊ถŒํ•œ ์ถ•์†Œ ๋ฐ ๋ถˆํ•„์š”ํ•œ Stored Procedure ์ œ๊ฑฐโ€“ db_owner ๊ถŒํ•œ์˜ ์ œ๊ฑฐ๊ฐ€ ํ•„์š”ํ•˜๋ฉฐ ์ผ๋ฐ˜ user ๊ถŒํ•œ ๋ถ€์—ฌ ํ•„์š”ํ•จ . ( ๋ฐ์ดํ„ฐ์˜ ๋ณด๊ธฐ๋Š” ๊ฐ€๋Šฅํ•˜๋‚˜ ์‹œ์Šคํ…œ

๋ช…๋ น์–ด ์‹คํ–‰์€ ๋ถˆ๊ฐ€๋Šฅํ•˜๋„๋ก )โ€“ xp_cmdshell xp_dirtree xp_regdeletekey xp_regenumvalues xp_regread xp_regw

rite sp_makewebtask sp_adduser โ€ฆ

๋ณ„์ฒจ ( SQL Injection & XSS ๋Œ€์ฑ… )

Page 40: NHN Security Division

NHN Security Division

โ€ข IDS ๋ฅผ ์ด์šฉํ•œ ์นจ์ž… ํƒ์ง€โ€“ Ruleset ์„ ์—…๋ฐ์ดํŠธ ํ•˜์—ฌ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ฌธ์ž์—ด์„ ๊ฐ์ง€ ํ•  ์ˆ˜ ์žˆ๋„๋ก

์กฐ์ •ํ•œ๋‹ค .

โ€ข IS_SRVROLEMEMBER , IS_MEMBER('db_owner') , db_name() ,%5Bsysobjects%5D , drop , delete ๋“ฑ์˜ ๊ฒฝ์šฐ False alarm ์˜ ๊ฒฝ์šฐ๋„ ๋‹ค์ˆ˜ ์žˆ์„ ์ˆ˜ ์žˆ์œผ๋‚˜ ์†์‰ฝ๊ฒŒ ํ•„ํ„ฐ๋ง ๊ฐ€๋Šฅํ•  ๊ฒƒ์ด๋‹ค . ๋˜ํ•œ IDS_Evasion ๊ณผ ๊ด€๋ จํ•˜์—ฌ์„œ๋„ ๋Œ€์ฑ…์ด ํ•„์š” ํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ๋ณธ๋‹ค .

โ€“ ์นจ์ž… ํƒ์ง€ ์ดํ›„์— Firewall ํ˜น์€ switch ์ƒ์—์„œ์˜ ๊ณต๊ฒฉ IP ์ฐจ๋‹จ

โ€“ ๋ชฉ์ ์ง€๋ฅผ ํ™•์ธํ•˜์—ฌ ์กด์žฌํ•˜๋Š” ์ทจ์•ฝ์„ฑ์— ๋Œ€ํ•œ ๊ฐ•๋ ฅํ•œ ์ˆ˜์ • ํ•„์š” .โ€ข ๋น„์ •์ƒ ํ–‰์œ„์— ๋Œ€ํ•œ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ Alert ๊ฐ•ํ™” ํ•„์š”

โ€ข DB ๋ฐ ์›น์„œ๋ฒ„ ๋‹จ์œ„์˜ ๋น„์ •์ƒ ํ–‰์œ„์— ๋Œ€ํ•œ ์‹ฌ๊ฐํ•œ ์ฃผ์˜ ํ•„์š”โ€ข ์‹œ์Šคํ…œ์˜ ์žฅ์•  ๋ฐœ์ƒ์‹œ์˜ ์›์ธ ํŒŒ์•… ๋ช…ํ™•ํžˆ ์ „๋‹ฌโ€ข IN/Out port ์— ๋Œ€ํ•œ ์ ‘๊ทผ์ œ์–ด ๊ฐ•ํ™” ๋ฐ ๋ชจ๋‹ˆํ„ฐ๋ง ๊ฐ•ํ™”โ€ข ์‚ฌ์šฉ์ž ์ ‘๊ทผ์— ๋Œ€ํ•œ ํ†ต์ œ ๊ฐ•ํ™”

๋ณ„์ฒจ ( SQL Injection & XSS ๋Œ€์ฑ… )

Page 41: NHN Security Division

NHN Security Division

Web Page crawling ์ดํ›„Validation ์ฒดํฌ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š”

์ž์ฒด ์ง„๋‹จ ํ”„๋กœ๊ทธ๋žจ

Web Application Validation ์ฒดํฌ โ€“ ๋‹ค์ˆ˜์˜ ์›น ์ง„๋‹จ ํ”„๋กœ๊ทธ๋žจ์ด ์กด์žฌ ํ•˜๊ณ  ์žˆ์Œ

๋ณ„์ฒจ ( SQL Injection & XSS ๋Œ€์ฑ… )

Page 42: NHN Security Division

NHN Security Division

Secure Programming & Secure Inspection For Web๋‹ค์ˆ˜์˜ ์›น ์ทจ์•ฝ์„ฑ ์Šค์บ๋„ˆ๋ฅผ ํ†ตํ•ด ์ทจ์•ฝ์„ฑ ๋ณด์™„ โ€“ ์ƒ์šฉ ๊ณต๊ฐœ์šฉ Web Validation check scanner โ€“ Gamja [ download at http://blog.naver.com/p4ssion ]

Check problem & correcting[ XSS , SQL Injection โ€ฆ]

Problem Clear[ XSS , SQL Injection โ€ฆ]

๋ณ„์ฒจ ( SQL Injection & XSS ๋Œ€์ฑ… )

Page 43: NHN Security Division

NHN Security Division

Secure Programming & Secure Inspection For WebGamja โ€“ Requirement: Wget [Windows] + Perl

๋ณ„์ฒจ ( SQL Injection & XSS ๋Œ€์ฑ… )