CSP ( Content Security Policy )

2022. 6. 10. 19:22ยท๐Ÿ–Œ๏ธ Theory/WEB

What is CSP?

XSS, ๋ฐ์ดํ„ฐ ์‚ฝ์ž… ๋“ฑ์˜ ๊ณต๊ฒฉ์„ ๋ฐฉ์ง€ํ•˜๊ณ  ๊ณต๊ฒฉ์„ ๋ณด๊ณ ๋ฐ›์„ ์ˆ˜ ์žˆ๋„๋ก ์ƒˆ๋กญ๊ฒŒ ์ถ”๊ฐ€๋œ ๋ณด์•ˆ ๊ณ„์ธต ( XSS์™€ CSP๊ฐ€ ๋ณ‘ํ–‰๋˜์–ด์•ผ ํ•จ )

 

Basic policy of CSP

1. Inline-code๋ฅผ ์œ ํ•ดํ•˜๋‹ค๊ณ  ๊ฐ„์ฃผ

Inline-code๋ž€ ํƒœ๊ทธ์˜ src ์†์„ฑ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ๋กœ๋“œํ•˜์ง€ ์•Š๊ณ  ๋ฐ”๋กœ ์‚ฝ์ž…ํ•˜๋Š” ์ฝ”๋“œ๋“ค์„ ๋œปํ•œ๋‹ค. ex) <script>alert(1);</script>

๋˜ํ•œ on* ์œผ๋กœ ์‹œ์ž‘ํ•˜๋Š” ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ, javascript: ์Šคํ‚ค๋งˆ๊นŒ์ง€ ํฌํ•จ๋œ๋‹ค.

 

2. ํ…์ŠคํŠธ๋ฅผ ์‹คํ–‰ ๊ฐ€๋Šฅํ•œ ์ฝ”๋“œ๋ฅด ๋ณ€ํ™˜ํ•˜๋Š” ๋งค์ปค๋‹ˆ์ฆ˜์„ ์œ ํ•ดํ•˜๋‹ค๊ณ  ๊ฐ„์ฃผ

ex) eval() , settimeout(), new Function() ๋“ฑ

 

์ง€์‹œ๋ฌธ.                   ์„ค๋ช…

default-src -src๋กœ ๋๋‚˜๋Š” ๋ชจ๋“  ๋ฆฌ์†Œ์Šค์˜ ๊ธฐ๋ณธ ๋™์ž‘์„ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค. ๋งŒ์•ฝ CSP ๊ตฌ๋ฌธ ๋‚ด์—์„œ ์ง€์ •ํ•˜์ง€ ์•Š์€ ์ง€์‹œ๋ฌธ์ด ์กด์žฌํ•œ๋‹ค๋ฉด default-src์˜ ์ •์˜๋ฅผ ๋”ฐ๋ผ๊ฐ‘๋‹ˆ๋‹ค.
img-src ์ด๋ฏธ์ง€๋ฅผ ๋กœ๋“œํ•  ์ˆ˜ ์žˆ๋Š” ์ถœ์ฒ˜๋ฅผ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค.
script-src ์Šคํฌ๋ฆฝํŠธ ํƒœ๊ทธ ๊ด€๋ จ ๊ถŒํ•œ๊ณผ ์ถœ์ฒ˜๋ฅผ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค.
style-src ์Šคํƒ€์ผ์‹œํŠธ ๊ด€๋ จ ๊ถŒํ•œ๊ณผ ์ถœ์ฒ˜๋ฅผ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค.
child-src ํŽ˜์ด์ง€ ๋‚ด์— ์‚ฝ์ž…๋œ ํ”„๋ ˆ์ž„ ์ปจํ…์ธ ์— ๋Œ€ํ•œ ์ถœ์ฒ˜๋ฅผ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค.
base-uri ํŽ˜์ด์ง€์˜ <base> ํƒœ๊ทธ์— ๋‚˜ํƒ€๋‚  ์ˆ˜ ์žˆ๋Š” URL์„ ์ œ์–ดํ•ฉ๋‹ˆ๋‹ค.

 

CSP Examples

https://learn.dreamhack.io/321#7 

 

CSP ์ทจ์•ฝ์  ๋ถ„์„ ์‚ฌ์ดํŠธ

https://csp-evaluator.withgoogle.com/

 

 

 

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ ๋ณ€๊ฒฝ๊ธˆ์ง€ (์ƒˆ์ฐฝ์—ด๋ฆผ)
'๐Ÿ–Œ๏ธ Theory/WEB' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • Advanced Tips For SSRF Attack
  • Small Tip
  • Mass Assignment Vulnerability
  • SOP & CORS
Cronus
Cronus
Offensive Security Researcher
  • Cronus
    Cronus
    Striving to be the best.
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (251)
      • AboutMe (1)
      • Portfolio (1)
        • Things (1)
      • Bug Report (1)
      • ๐Ÿšฉ CTF (23)
        • Former Doc (9)
        • 2023 (9)
      • ๐Ÿ’ป Security (5)
      • ๐Ÿ–Œ๏ธ Theory (22)
        • WEB (9)
        • PWN (13)
      • ๐Ÿ“„ Project (6)
        • Edu_Siri (6)
      • Dreamhack (156)
        • WEB (95)
        • PWN (41)
        • Crypto (14)
        • ETC (6)
      • Wargame (22)
        • HackCTF (22)
      • Bug Bounty (1)
        • Hacking Zone (1)
      • Tips (7)
      • Development (2)
        • Machine Learning & Deep Lea.. (1)
      • Offensive Tools (1)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
  • ๋งํฌ

  • ๊ณต์ง€์‚ฌํ•ญ

  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    Ubuntu ๊ธฐ์ดˆ
    Text Summarization
    GPNCTF
    Ubuntu ๊ธฐ์ดˆ ์…‹ํŒ…
    Deep learning
    cache
    TFCCTF2022
    sqli
    python
    bug hunter
    Remote Code Execution
    ubuntu ๋ช…๋ น์–ด
    justCTF
    cache poisoning
    RCE
    Machine Learning
    TsukuCTF2022
    Crypto
    pwntools
    bug report
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • ์ตœ๊ทผ ๊ธ€

Cronus
CSP ( Content Security Policy )
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”