English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210183
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÄíÅ°°¡ secure Ç÷¡±×¾øÀÌ ¼³Á¤µÇ¾ú½À´Ï´Ù. Áï, ¾ÏȣȭµÇÁö ¾ÊÀº ¿¬°áÀ» ÅëÇØ ÄíÅ°¿¡ ¾×¼¼½º ÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÄíÅ°¿¡ Áß¿äÇÑ Á¤º¸°¡ Æ÷ÇԵǾî Àְųª ¼¼¼Ç ÅäÅ« ÀÏ ¶§´Â Ç×»ó ¾Ïȣȭ µÈ ä³ÎÀ» »ç¿ëÇÏ¿© Àü´ÞÇؾßÇÕ´Ï´Ù. ÀÌ·¯ÇÑ Áß¿äÇÑ Á¤º¸°¡ Æ÷ÇÔ µÈ ÄíÅ°¿¡ ´ëÇØ secure Ç÷¡±×°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.

* Âü°í »çÀÌÆ®:
https://www.owasp.org/index.php/SecureFlag
http://www.owasp.org/index.php/Testing_for_cookies_attributes_(OWASP-SM-002)

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Any operating system Any version
ÇØ°áÃ¥ *Java
Servlet 3.0 (Java EE 6)Àº ¼¼¼Ç ÄíÅ°ÀÇ º¸¾È ¼Ó¼ºÀ» ±¸¼ºÇϴ ǥÁØ ¹æ¹ýÀ» µµÀÔÇß½À´Ï´Ù. ÀÌ´Â web.xml¿¡ ´ÙÀ½ ±¸¼ºÀ» Àû¿ëÇÏ¿© ¼öÇà ÇÒ ¼ö ÀÖ½À´Ï´Ù.

[web.xml]
<session-config>
<cookie-config>
<secure>true</secure>
</cookie-config>
</session-config>


*Tomcat
Tomcat 6¿¡¼­ ¼¼¼Ç¿¡ ´ëÇÑ Ã¹ ¹ø° ¿äûÀÌ https¸¦ »ç¿ëÇÏ´Â °æ¿ì ¼¼¼Ç ÄíÅ°¿¡ º¸¾È ¼Ó¼ºÀ» ÀÚµ¿À¸·Î ¼³Á¤ÇÕ´Ï´Ù.

[»ç¿ëÀÚ Á¤ÀÇ Çì´õ·Î ¼³Á¤]
String sessionid = request.getSession().getId();
response.setHeader("SET-COOKIE", "JSESSIONID=" + sessionid + "; secure");

*PHP
PHP°¡ °ü¸®ÇÏ´Â ¼¼¼Ç ÄíÅ°ÀÇ °æ¿ì secure Ç÷¡±×´Â ´ÙÀ½ ¸Å°³ º¯¼ö¸¦ ÅëÇØ ¿µ±¸ÀûÀ¸·Î ¼³Á¤µË´Ï´Ù.

session.cookie_secure = True
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)