CSTI(Client Side Template Injection) ์ทจ์•ฝ์ 

CSTI ๋ž€? Client Side Template Injection์œผ๋กœ ํด๋ผ์ด์–ธํŠธ ์ธก์—์„œ ์‚ฌ์šฉ๋˜๋Š” ํ…œํ”Œ๋ฆฟ์— ์ž„์˜ ๊ตฌ๋ฌธ์„ ์ฃผ์ž…ํ•œ๋‹ค๋Š” ์˜๋ฏธ๋ฅผ ๊ฐ€์ง‘๋‹ˆ๋‹ค. ๋ธŒ๋ผ์šฐ์ € ์ƒ์—์„œ ์ž…๋ ฅ๋œ ํ…œํ”Œ๋ฆฟ ํ‘œํ˜„์‹์„ ํ”„๋ก ํŠธ ์ธก์—์„œ ์ดํ•ดํ•˜๊ณ  ์›ํ•˜๋Š” ๊ฒฐ๊ณผ๋ฅผ ๋ณด์—ฌ์ค€๋‹ค๋Š” ๊ฒƒ์€ ๊ณต๊ฒฉ์ž ๊ด€์ ์—์„œ ํ…œํ”Œ๋ฆฟ ํ‘œํ˜„์‹ + ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ ๊ตฌ๋ฌธ ์กฐํ•ฉ์„ ํ†ตํ•ด XSS๋ฅผ ์‹œ๋„ํ•  ๊ฐ€์น˜๊ฐ€ ์žˆ๋Š” ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ XSS ์ทจ์•ฝ์ ์˜ ์˜ํ–ฅ๋„์™€ ์œ ์‚ฌํ•˜์ง€๋งŒ ์˜จ์ „ํžˆ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ ๊ตฌ๋ฌธ์œผ๋กœ ์‹คํ–‰์‹œํ‚ค๋Š๋ƒ ํ…œํ”Œ๋ฆฟ ํ‘œํ˜„์‹์— ๋‹ด์•„์„œ ์‹คํ–‰ํ•˜๋Š๋ƒ์˜ ์ฐจ์ด๊ฐ€ ์กด์žฌํ•ฉ๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์ƒŒ๋“œ๋ฐ•์Šค์—์„œ ํ—ˆ์šฉ๋˜๋Š” ํ•จ์ˆ˜($eval ์ œ๊ณต)์™€ ๊ฐ์ฒด(toString(), charAt(), trim(), prototype, and constructor)์™€ ํ‘œํ˜„์‹ "{{}}" ๋˜๋Š” "[]"๋ฅผ ํ†ตํ•ด ์ƒŒ๋“œ๋ฐ•์Šค๋ฅผ ..

WEB