µî·ÏÀÏ | 2006-05-19 11:19:25 | Á¶È¸¼ö | 2284 |
Á¦¸ñ | [º¸¾È°øÁö] Á¦·Îº¸µå ÆÐÄ¡¸¦ ¿äûµå¸³´Ï´Ù. | ||
¾È³çÇϼ¼¿ä. ¿ì¶ß³ÝÀÔ´Ï´Ù. Á¦·Îº¸µå pl8 ÀÌ 3¿ù 15ÀÏÀÚ·Î ³ª¿Ô½À´Ï´Ù. ÀúÈñ°¡ ÀÚü Å×½ºÆ® ÇÑ°á°ú, ±âÁ¸ Á¦·Îº¸µå ¼Ò½º ¼öÁ¤ÀÌ ¾øÀ¸½Å °í°´´ÔÀÎ °æ¿ì, Å« ¹®Á¦ ¾øÀÌ ÆÐÄ¡°¡ °¡´ÉÇÕ´Ï´Ù. º¸¾È¹ö±×·Î ÀÎÇÏ¿©, ¸ðµç Á¦·Îº¸µå »ç¿ëÀÚ ºÐµéÀº ÆÐÄ¡¸¦ ²À ÇÏ¿© Áֽñ⠹ٶø´Ï´Ù. ¹æ¹ýÀº ¾Æ·¡ÀÇ Á¦·Îº¸µå »çÀÌÆ®ÀÇ ³»¿ëÀ» ±×·¡µµ ¿Ã·Áµå¸³´Ï´Ù. -------------------------------------------------------------------------------- ±âÁ¸ Á¦·Îº¸µå 4.1 pl7¿¡¼ º¸¾È¹ö±×¸¦ ¼öÁ¤ÇÏ¿´½À´Ï´Ù. ±âÁ¸¿¡ 4.1 pl7À» »ç¿ëÁßÀ̽ŠºÐµéÀº ¾Æ·¡ ÆÄÀϵ鸸 µû·Î »Ì¾Æ¼ µ¤¾î¾º¿ì½Ã¸é µË´Ï´Ù. === ¹ö±× ¼öÁ¤ ÆÄÀÏ ¸ñ·Ï ========= image_box.php member_join_ok.php member_modify_ok.php login_check.php lib.php member_memo.php member_memo2.php member_modify_ok.php license.txt =============================== ¼öÁ¤µÈ ¹ö±× ³»¿ëÀº ´ÙÀ½°ú °°½À´Ï´Ù. - À̹ÌÁö ÆÄÀÏ ¾÷·Îµå ÇÏ´Â ºÎºÐ¿¡¼ È®ÀåÀÚ(gif/jpg)¸¦ ¹«½ÃÇÏ°í ÀÓÀÇÀÇ ½ºÅ©¸³Æ® ÆÄÀÏÀ» ¿Ã¸± ¼ö ÀÖ´ø ¹ö±× ¼öÁ¤ - sql injection Ãë¾à¼º Á¦°Å - XSS(Å©·Î½º »çÀÌÆ® ½ºÅ©¸³ÆÃ) Ãë¾à¼º Á¦°Å ÀÔ´Ï´Ù. ps. °ü·Ã ³»¿ëÀ» ¾Ë·ÁÁֽŠÇѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA) ÇØÅ·´ëÀÀÆÀ ¹× Ãë¾àÁ¡ º¸°íÇØÁֽŠºÐ²² °¨»çÀÇ ¸»¾¸À» µå¸³´Ï´Ù. - À̹ÌÁö ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ - ±èÁøÈ«¾¾ - SQL Injection Ãë¾àÁ¡ - ÇÔÁö¸¸¾¾, Ãֹμº¾¾ - XSS Ãë¾àÁ¡((iframe Ãë¾àÁ¡) - À¯µ¿Èƾ¾ °¨»çÇÕ´Ï´Ù. |