Directory traversal

Introduction


Path Traversal, ๋˜๋Š” Directory Traversal ์ด๋ผ๊ณ ๋„ ๋ถˆ๋ฆฌ๋Š” ํ•ด๋‹น ์ทจ์•ฝ์ ์€, ๊ณต๊ฒฉ์ž๊ฐ€ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ URL์„ ๊ต๋ฌ˜ํžˆ ์กฐ์ž‘ํ•ด ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋ฃจํŠธ ํด๋” ๋ฐ–์— ์กด์žฌํ•˜๋Š” ํŒŒ์ผ์ด๋‚˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์ ‘๊ทผํ•˜๋„๋ก ๋งŒ๋“œ๋Š” ์›น์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค.

์ด๋ฏธ์ง€ยท์ •์  ํ…์ŠคํŠธยท์ฝ”๋“œ ๋“ฑ ๋‹ค์–‘ํ•œ ํŒŒ์ผ์„ ํฌํ•จ์‹œํ‚ค๋ฉด์„œ ์ž…๋ ฅ๊ฐ’ ๊ฒ€์ฆ์„ ์ œ๋Œ€๋กœ ๊ตฌํ˜„ํ•˜์ง€ ๋ชปํ•  ๋•Œ ๋ฐœ์ƒํ•˜๋ฉฐ,๊ณต๊ฒฉ์ž๋Š” ์ฃผ๋กœ ../(์ -์ -์Šฌ๋ž˜์‹œ)์™€ ๊ฐ™์€ ์‹œํ€€์Šค, ํ˜น์€ ์œ ์‚ฌํ•œ ๊ตฌ๋ฌธ์„ ์ž…๋ ฅ ํ•„๋“œ์— ์ฃผ์ž…ํ•ด ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๊ฒฝ๋กœ ์ œํ•œ์„ ์šฐํšŒํ•˜๊ณ  ์›ํ•˜๋Š” ์‹œ์Šคํ…œ ํŒŒ์ผ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค..

์ด ์ทจ์•ฝ์ ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด CVSS 7.3(High) ์œ„ํ—˜๋„๋กœ ๋ถ„๋ฅ˜๋ฉ๋‹ˆ๋‹ค.

  • CWE-22 : โ€œ์ œํ•œ๋œ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ๋Œ€ํ•œ ๊ฒฝ๋กœ๋ช…์„ ๋ถ€์ ์ ˆํ•˜๊ฒŒ ์ œํ•œ(โ€˜Path Traversalโ€™)โ€

  • CWE-35 : โ€œPath Traversal: โ€˜โ€ฆ/โ€ฆ//โ€™โ€

  • CWE-73 : โ€œDirectory Traversalโ€

  • CWE-200 : โ€œ๊ถŒํ•œ ์—†๋Š” ์ฃผ์ฒด์—๊ฒŒ ๋ฏผ๊ฐ ์ •๋ณด ๋…ธ์ถœโ€

๋˜ํ•œ OWASP Top 10 ์—์„œ๋Š” ์•„๋ž˜ ํ•ญ๋ชฉ๊ณผ ๊ด€๋ จ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

  • A05:2021 - Security Misconfiguration

  • A01:2021 - Broken Access Control

Linux Server Path Traversal Exploitation


chevron-rightImportant Linux Fileshashtag
  • ์šด์˜ ์ฒด์ œโ€ง์‹œ์Šคํ…œ ์ •๋ณด

  • ํ”„๋กœ์„ธ์Šค ๊ด€๋ จ

  • ๋„คํŠธ์›Œํฌ ์ƒํƒœ

  • ํ˜„์žฌ ์ž‘์—… ๋””๋ ‰ํ„ฐ๋ฆฌ

  • ์ธ๋ฑ์Šค(DB) ํŒŒ์ผ

  • ์ž๊ฒฉ ์ฆ๋ช…โ€งํžˆ์Šคํ† ๋ฆฌ

  • Kubernetes ์„œ๋น„์Šค์–ด์นด์šดํŠธ

Windows Server Path Traversal Exploitation


chevron-rightImportant Windows Fileshashtag
  • ์šด์˜ ์ฒด์ œ ๋ฐ ์‹œ์Šคํ…œ ์ •๋ณด

  • ์‚ฌ์šฉ์ž ๋ฐ ์ž๊ฒฉ ์ฆ๋ช… ๊ด€๋ จ

  • ์‹œ์Šคํ…œ ์„ค์ • ๋ฐ ์ธ์ฆ ๊ด€๋ จ

  • ํ”„๋กœ์„ธ์Šค ๋ฐ ํ™˜๊ฒฝ ๊ด€๋ จ

  • ๋„คํŠธ์›Œํฌ ๊ด€๋ จ

  • ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๋ฐ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์„ค์ •

  • Kubernetes / Docker ํ™˜๊ฒฝ

Mitigation


Last updated