Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

**Cookie bomb**๋Š” ์‚ฌ์šฉ์ž๋ฅผ ๋Œ€์ƒ์œผ๋กœ ๋„๋ฉ”์ธ ๋ฐ ๊ทธ ํ•˜์œ„ ๋„๋ฉ”์ธ์— ๋งŽ์€ ์–‘์˜ ํฐ ์ฟ ํ‚ค๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. ์ด ํ–‰๋™์€ ํ”ผํ•ด์ž๊ฐ€ ์„œ๋ฒ„์— ๊ณผ๋„ํ•œ HTTP ์š”์ฒญ์„ ์ „์†กํ•˜๊ฒŒ ํ•˜๋ฉฐ, ์ด๋Š” ์ดํ›„ ์„œ๋ฒ„์— ์˜ํ•ด ๊ฑฐ๋ถ€๋ฉ๋‹ˆ๋‹ค. ์ด๋กœ ์ธํ•ด ํ•ด๋‹น ๋„๋ฉ”์ธ ๋ฐ ๊ทธ ํ•˜์œ„ ๋„๋ฉ”์ธ ๋‚ด์˜ ์‚ฌ์šฉ์ž๋ฅผ ํŠน์ •ํ•˜์—ฌ ์„œ๋น„์Šค ๊ฑฐ๋ถ€(DoS)๊ฐ€ ๋ฐœ์ƒํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

์ข‹์€ ์˜ˆ์‹œ๋Š” ์ด ๊ธ€์—์„œ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: https://hackerone.com/reports/57356

๋” ๋งŽ์€ ์ •๋ณด๋Š” ์ด ํ”„๋ ˆ์  ํ…Œ์ด์…˜์„ ํ™•์ธํ•˜์„ธ์š”: https://speakerdeck.com/filedescriptor/the-cookie-monster-in-your-browsers?slide=26

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ