| xss ³ª ¹Ý»ç µÈ Å©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃÀ» Å×½ºÆ®ÇÏ´Â µ¥ »ç¿ëµÇ´Â Firefox ¾Öµå¿Â. |
Áö±Ý ´Ù¿î·Îµå |
xss ³ª ¼øÀ§ ¹× ¿ä¾à
- °Ô½ÃÀÚ À̸§:
- Security Compass
- °Ô½ÃÀÚ À¥»çÀÌÆ®:
- http://securitycompass.com/exploit_me/accessme/accessme_faq.shtml
- ¿î¿µÃ¼Á¦:
- Mac OS X 10.0 or later
xss ³ª ű×
xss ³ª ¼³¸í
¹Ý¿µµÈ ±³Â÷ »çÀÌÆ® ½ºÅ©¸³ÆÃÀ» Å×½ºÆ®ÇÏ´Â µ¥ »ç¿ëµÇ´Â Firefox ºÎ°¡ ±â´É. Cross-Site Scripting (XSS)Àº ¿À´Ã³¯ À¥ ÀÀ¿ë ÇÁ·Î±×·¥¿¡¼ ¹ß°ßµÇ´Â ÀϹÝÀûÀÎ °áÇÔÀÔ´Ï´Ù. XSS °áÇÔÀº À¥ ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ½É°¢ÇÑ ¼Õ»óÀ» ÁÙ ¼ö ÀÖ½À´Ï´Ù. °³¹ß ÇÁ·Î¼¼½º Ãʱ⿡ XSS Ãë¾à¼ºÀ» °¨ÁöÇÏ¸é ºÒÇÊ¿äÇÑ °áÇÔÀ¸·ÎºÎÅÍ À¥ ÀÀ¿ë ÇÁ·Î±×·¥À» º¸È£ÇÏ´Â µ¥ µµ¿òÀ̵˴ϴÙ. XSS-Me È®ÀåÀÚ´Â XSS Vulnerability¸¦ ¹ß°ßÇÏ´Â µ¥ µµ¿òÀ̵˴ϴ٠.xss-Me´Â ¹Ý¿µµÈ ±³Â÷ »çÀÌÆ® ½ºÅ©¸³Æà (XSS)À» Å×½ºÆ®ÇÏ´Â µ¥ »ç¿ëµÇ´Â Excloit-Me µµ±¸ÀÔ´Ï´Ù. ÇöÀç HTML ¾ç½ÄÀ» Á¦ÃâÇÏ°í Æû °ªÀ» XSS Attack.rnrnif¸¦ ³ªÅ¸³»´Â ¹®ÀÚ¿·Î Æû °ªÀ» ´ëüÇÏ¿© ÀúÀåµÈ XSS.RnrnThe µµ±¸°¡ ÇöÀç Å×½ºÆ®µÇÁö ¾Ê½À´Ï´Ù. °á°ú HTML ÆäÀÌÁö´Â ƯÁ¤ JavaScript °ª (document.vulnerable = true)À» ¼³Á¤ÇÕ´Ï´Ù. ÀÌ µµ±¸´Â ÁÖ¾îÁø xss string.rnrnthe µµ±¸°¡ ÁÖ¾îÁø ½Ã½ºÅÛÀÇ º¸¾ÈÀ» ¼Õ»ó½ÃÅ°Áö ¾ÊÀ¸·Á °í ½ÃµµÇÏÁö ¾Ê°í ÆäÀÌÁö¸¦ Ç¥½ÃÇÕ´Ï´Ù. ½Ã½ºÅÛ¿¡ ´ëÇÑ °ø°Ý¿¡ ´ëÇÑ °¡´ÉÇÑ ÁøÀÔ Á¡À» ãÀ¸½Ê½Ã¿À. µµ±¸°¡ ¼öÇà ÇÑ Æ÷Æ® ½ºÄµ, ÆÐŶ ½º´ÏÇÎ, ºñ¹Ð¹øÈ£ ÇØÅ· ¶Ç´Â ¹æȺ® °ø°ÝÀº ¾ø½À´Ï´Ù .RNRNYOU´ÂÀÌ µµ±¸ °¡ÀÌ ¸ðµç ¹®ÀÚ¿À» ¾ç½Ä Çʵ忡 ¼öµ¿À¸·Î ÀÔ·ÂÇÏ´Â QA Å×½ºÅÍ¿Í µ¿ÀÏÇÑ ÀÛ¾÷À» »ý°¢ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¿ä±¸ »çÇ× : ¡¤ Firefox 2.0.0.8 ÀÌ»ó. ÀÌ ¸±¸®½º¿¡¼´Â »õ·Î¿î ±â´É : ¡¤ ¹ö±× ¼öÁ¤ ¸±¸®½º. ¡¤ °æ¿ì¿¡ µû¶ó Å×½ºÆ®¸¦ ÁßÁö ÇÒ Á¤±Ô½Ä ¹®Á¦¸¦ ¼öÁ¤ÇÕ´Ï´Ù.
xss ³ª °ü·Ã ¼ÒÇÁÆ®¿þ¾î