SonarQube를 brew에서 Docker로 옮겼다
SonarQube Java 분석의 .class 요구 에러를 빌드로 풀고, brew 없이도 돌도록 서버와 Scanner를 Docker로 옮긴 기록
SonarQube Java 분석의 .class 요구 에러를 빌드로 풀고, brew 없이도 돌도록 서버와 Scanner를 Docker로 옮긴 기록
앞서 ModSecurity에 대해 간단히 다뤘다. 이번에는 우분투 컨테이너 생성부터 ModSecurity 구성과 테스트까지 진행했고 그 과정을 기록했다.
부제: Docker를 사용한 ModSecurity WAF 사용기 Web Application Firewall (WAF): 웹 서비스를 통해서 공격을 시도하는 XSS, SQL Injection, Command Execute과 같은 공격을 효과적으로 차단하는 역할을 수행하는 보안 모듈
❓Injetion : 보안 취약점을 이용하여, 임의의 SQL 문을 주입하여 데이터베이스가 비정상적인 동작을 하도록 조작하는 행위 ** 📜 Content** 🗡️ Injection 공격 예시 /* 어떠한 POST방식 API에 아래와 같은 인자값을 넘기는 것이 정상적인 방법일 때*/ { testKey : "testValue" } /* 악의적인 사용자는 다음과 같이 인자값을 설정하여 쿼리를 조작할 수 있다. */ { testKey : "testValue' and '해킹'='해킹" } 위 인자값이 SQL Query에 적용될 때 정상적인 인자값을 넘겨받은 쿼리 select * from testTable where key = 'testValue' Injection 공격을 시도된 쿼리 select * from testTable where key = 'testValue' and '해킹'='해킹' 🛡️ python에 대한 injection 방어 코드 실무에서 사용된 DB 호출 코드 방식 (Injection 대응 전) import psycopg2 from psycopg2.extras import RealDictCursor # DB 연결 준비 conn = psycopg2.connect("dbname={} user={} host={} password={}".format(db_name, db_user, db_host, db_pass)) # DB 호출함수 선언 def fetch(conn, query): result = [] cursor = conn.cursor(cursor_factory=RealDictCursor) cursor.execute(query) # SQL 실행 # DB조회 결과값 담기 raw = cursor.fetchall() for line in raw: result.append(line) return result # SQL 쿼리 선언 query = "select pjt_no, item_type from testTable " query += "where pjt_no = '" + pjt_no + "' " query += "and item_type = '" + type_cd2 + "'" # DB 호출함수 실행 result = fetch(conn=conn, query=query) Injection 대응 (Type 1) import psycopg2 from psycopg2.extras import RealDictCursor # DB 연결 준비 conn = psycopg2.connect("dbname={} user={} host={} password={}".format(db_name, db_user, db_host, db_pass)) # DB 호출함수 선언 def fetch(conn, query, sql_arg): result = [] cursor = conn.cursor(cursor_factory=RealDictCursor) cursor.execute(query, sql_arg) # SQL 실행 # DB조회 결과값 담기 raw = cursor.fetchall() for line in raw: result.append(line) return result # SQL 쿼리 선언 query = "select pjt_no, item_type from testTable " query += "where pjt_no = %(pjt_no)s" query += "and item_type = %(item_type)s" sql_arg = { 'pjt_no' : pjt_no, 'item_type' : item_type, } # DB 호출함수 실행 result = fetch(conn=conn, query=query, sql_arg=sql_arg) Injection 대응 (Type 2) (딕셔너리 타입(X) → tuple 타입으로 넘기는 것도 가능) ...