Ä®¸®! µµÄ¿¸¦ ÇØÅ·ÇÏ´Ù 1ºÎ
- ÀúÀÚ¹®¼ºÈ£ Àú
- ÃâÆÇ»çºêÀ̸ÞÀÌÄ¿½º
- ÃâÆÇÀÏ2019-03-19
- µî·ÏÀÏ2020-01-31
- SNS°øÀ¯
- ÆÄÀÏÆ÷¸ËPDF
- °ø±Þ»çYES24
-
Áö¿ø±â±â
PC
PHONE
TABLET
ÇÁ·Î±×·¥ ¼öµ¿¼³Ä¡
ÀüÀÚÃ¥ ÇÁ·Î±×·¥ ¼öµ¿¼³Ä¡ ¾È³»
¾ÆÀÌÆù, ¾ÆÀÌÆеå, ¾Èµå·ÎÀ̵åÆù, ÅÂºí¸´,
º¸À¯ 2, ´ëÃâ 0,
¿¹¾à 0, ´©Àû´ëÃâ 16, ´©Àû¿¹¾à 0
Ã¥¼Ò°³
ÀÌ Ã¥Àº ÃÑ 3ºÎ·Î ±âȹÇß´Ù. ÀÔ¹®ÀÚ³ª ÃʱÞÀÚ°¡ Áß±Þ Á¤µµÀÇ ¼öÁرîÁö ²ø¾î¿Ã¸± ¼ö ÀÖµµ·Ï ´Ù¼Ò ¿å½ÉÀ» ºÎ·È´Ù. 1ºÎ´Â ÀÔ¹®ÀÚ³ª ÃʱÞÀÚ¿¡°Ô ¸ÂÃè°í, 2ºÎ¿Í 3ºÎ´Â Ãʱ޿¡¼ Áß±ÞÀ¸·Î ¼ºÀåÇÏ°í ½ÍÀº ºÐµéÀÇ ´«³ôÀÌ¿¡ ¸ÂÃè´Ù. 1ºÎ´Â µµÄ¿ ÄÁÅ×À̳ʷΠDVWA¸¦ ½ÇÇàÇؼ ½Ç½ÀÇÏ°í, 2ºÎ´Â ´Ù¾çÇÑ ¾ÖÇø®ÄÉÀ̼ÇÀ» µµÄ¿ ÄÁÅ×À̳ʷΠ½ÇÇàÇؼ ½Ç½ÀÇÑ´Ù. ±×¸®°í 3ºÎ´Â Ä®¸®¸®´ª½ºÀÇ ÇÙ½É µµ±¸ÀÎ ¸ÞŸ½ºÇ÷ÎÀÕÀ¸·Î Ãë¾àÁ¡ Áø´ÜÀ» Çغ»´Ù. ÀÔ¹®ÀÚ³ª ÃʱÞÀÚ¶ó¸é, ¡®ÀÌ Ã¥¿¡ ³ª¿ÍÀÖ´Â ³»¿ëÀÌ¶óµµ Àß ¾ËÀÚ.¡¯´Â ¸¶À½À¸·Î ÇнÀÀ» ÇßÀ¸¸é ÁÁ°Ú°í, Áß±ÞÀÚ¶ó¸é, ¡®±âÃʺÎÅÍ ´Ù½Ã ´ÛÀÚ.¡¯´Â ¸¶À½À¸·Î ÇнÀÀ» ÇßÀ¸¸é ÇÑ´Ù.Ã¥¿¡¼ ¡®µµÄ¿'¿Í ¡®Ä®¸® ¸®´ª½º'¸¦ ´Ù·é ÀÌÀ¯´Â ±×¸¸Å µÑÀÇ Á¶ÇÕÀÌ ½Ç½À¿¡ À¯¸®Çϱ⠶§¹®ÀÌ´Ù. ÇØÅ·À» °øºÎÇÏ´Ù º¸¸é, ½Ç½À ȯ°æ ±¸Ãà¿¡¼ ¸¹Àº ½Ã°£À» »¯±â´Âµ¥, µµÄ¿´Â ±× ½Ã°£À» »ó´ç ºÎºÐ ´ÜÃàÇØ ÁØ´Ù. ½Ã°£ÀÌ ´ÜÃàµÈ´Ù´Â °ÍÀº ´Ù¸¥ °ÍÀ» ¿¬±¸ÇÒ ½Ã°£À» ´õ È®º¸ÇØ Áشٴ °ÍÀ» ÀǹÌÇÑ´Ù. ³»°¡ °æÇèÇÑ µµÄ¿¿Í Ä®¸® ¸®´ª½ºÀÇ À¯¿ëÇÔÀ» µ¶ÀÚ¿¡°Ô Àü´ÞÇÏ°í ½Í¾ú´Ù.
¸ñÂ÷
01 ¹è°æ Áö½Ä ¹× ½Ç½À ȯ°æ ±¸Ãà 171.1 ÁÖ¿ä ¸®´ª½º ¸í·É¾î 17
02 Ä®¸® ¸®´ª½º ¼Ò°³ ¹× ¼³Ä¡ 32
2.1 Ä®¸® ¸®´ª½º¶õ? 32
2.2 Ä®¸® ¸®´ª½º °ø½Ä ȨÆäÀÌÁö 34
2.3 Ä®¸® ¸®´ª½º ´Ù¿î·Îµå ¹× ¼³Ä¡ 35
2.4 ¾ð¾î ¼³Á¤ 61
2.5 Ä®¸® ¸®´ª½ºÀÇ ÀúÀå¼Ò °æ·Î : /etc/apt/source s.list 65
2.5.1 Ä®¸® ¸®´ª½º¿¡¼ VirtualBox Guest Additions ¼³Ä¡ 67
2.5.2 ¹öÃß¾ó¹Ú½º ³×Æ®¿öÅ© ¼³Á¤ 68
03 Docker ¼Ò°³ ¹× ¼³Ä¡ 77
3.1 Docker ¼Ò°³ 77
3.2 Ä®¸® ¸®´ª½º¿¡ Docker Engine ¼³Ä¡ 84
3.3 Docker ¸í·É¾î 86
04 DVWA µµÄ¿ ÄÁÅ×ÀÌ³Ê Ãë¾àÁ¡ Å×½ºÆ® 94
4.1 Docker image ´Ù¿î·Îµå ¹× ÄÁÅ×ÀÌ³Ê ½ÇÇà 94
05 Brute Force 100
5.1 Burp Suite¶õ? 101
5.2 ¹öÇÁ½ºÀ§Æ® ȯ°æ ¼³Á¤ 103
5.3 ¹öÇÁ½ºÀ§Æ®·Î Bruteforce °ø°Ý ½ÇÇà 114
5.4 DVWA Bruteforce Ãë¾àÁ¡ ºÐ¼® 124
06 Command Injection 128
6.1 Command Injection ÆäÀÌÁö 128
6.2 Commix¸¦ ÀÌ¿ëÇÑ Command Injection 130
6.3 DVWA Command Injection Ãë¾àÁ¡ ºÐ¼® 134
07 XSS(Cross Site Scripting) °ø°Ý ÀÌÇØ 137
7.1 XSS¶õ? 137
7.2 XSS(DOM) 138
7.3 XSS(Reflected) 147
7.4 XSS(Stored) 155
08 CSRF(Cross-site request forgery) °ø°Ý ÀÌÇØ 159
8.1 CSRF¶õ? 159
8.2 DVWA CSRF °ø°Ý ½Ç½À 161
8.3 DVWA CSRF Ãë¾àÁ¡ ºÐ¼® 162
09 File Inclusion °ø°Ý ÀÌÇØ 168
9.1 File InclusionÀ̶õ? 168
9.2 DVWA File Inclusion ½Ç½À 170
9.3 DVWA File Inclusion Ãë¾àÁ¡ ºÐ¼® 172
10 File Upload °ø°Ý ÀÌÇØ 174
10.1 File Upload¶õ? 174
10.2 DVWA File Upload °ø°Ý ½Ç½À 175
10.3 DVWA File Upload Ãë¾àÁ¡ ºÐ¼® 183
11 Insecure Captcha °ø°Ý ÀÌÇØ 187
11.1 Captcha¶õ? 187
11.2 DVWA Insecure Captcha °ø°Ý ½Ç½À 192
11.3 DVWA Insecure Captcha Ãë¾àÁ¡ ºÐ¼® 196
12 SQL Injection °ø°Ý ÀÌÇØ 199
12.1 SQL InjectionÀ̶õ? 199
12.2 DVWA SQL Injection °ø°Ý ½Ç½À 201
12.3 DVWA SQL Injection Ãë¾àÁ¡ ºÐ¼® 206
12.4 Blind SQL Injection 214
13 Weak Session IDs °ø°Ý ÀÌÇØ 216
13.1 Session ID¶õ? 216
13.2 DVWA Weak Session ID Ãë¾àÁ¡ ºÐ¼® 218
14 CSP Bypass °ø°Ý ÀÌÇØ 224
14.1 CSP(Content Security Policy)¶õ? 224
14.2 DVWA CSP Bypass Ãë¾àÁ¡ ºÐ¼® 225
15 Javascript °ø°Ý ÀÌÇØ 233
15.1 Javascript¶õ? 233
15.2 DVWA Javascript Ãë¾àÁ¡ ºÐ¼® 234