URL ์ •๊ทœํ™”๊ฐ€ ํ™œ์„ฑํ™”๋œ lighttpd 1.4.54 http ์„œ๋ฒ„ ์ถœ์‹œ

๊ฒŒ์‹œ ๋จ ๊ฒฝ๋Ÿ‰ http ์„œ๋ฒ„ ์ถœ์‹œ ๋ผ์ดํŠธ 1.4.54. ์ƒˆ ๋ฒ„์ „์—๋Š” 149๊ฐ€์ง€ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฉฐ, ํŠนํžˆ ๊ธฐ๋ณธ์ ์œผ๋กœ URL ์ •๊ทœํ™” ํฌํ•จ, mod_webdav ์žฌ์ž‘์—… ๋ฐ ์„ฑ๋Šฅ ์ตœ์ ํ™” ์ž‘์—…์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

lighttpd 1.4.54๋ถ€ํ„ฐ ๋ณ€๊ฒฝ๋จ HTTP ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•  ๋•Œ URL ์ •๊ทœํ™”์™€ ๊ด€๋ จ๋œ ์„œ๋ฒ„ ๋™์ž‘์ž…๋‹ˆ๋‹ค. ํ˜ธ์ŠคํŠธ ํ—ค๋”์˜ ๊ฐ’์„ ์—„๊ฒฉํ•˜๊ฒŒ ๊ฒ€์‚ฌํ•˜๋Š” ์˜ต์…˜์ด ํ™œ์„ฑํ™”๋˜๊ณ  ํ—ค๋”๋กœ ์ „์†ก๋œ ๋งํฌ์˜ ์ •๊ทœํ™” ๋ฐ ์ด์Šค์ผ€์ดํ”„๋˜์ง€ ์•Š์€ ์ œ์–ด ๋ฌธ์ž๊ฐ€ ์žˆ๋Š” ๋งํฌ ์ฐจ๋‹จ๋„ ํ™œ์„ฑํ™”๋ฉ๋‹ˆ๋‹ค. ์ •๊ทœํ™” ํ”„๋กœ์„ธ์Šค์—๋Š” '\'๋ฅผ '/'๋กœ, '%2F'๋ฅผ '/'๋กœ, '%20'์„ '+'๋กœ ์ž๋™ ๋ณ€ํ™˜ํ•˜๊ณ , '.' ๋ฐ '..' ๋””๋ ‰ํ† ๋ฆฌ๊ฐ€ ์žˆ๋Š” ํŒŒ์ผ ๊ฒฝ๋กœ์˜ ์ผ๋ถ€๋ฅผ ํ™•์ธํ•˜๊ณ  ์ œ๊ฑฐํ•˜๋Š” ์ž‘์—…์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ', ์ด์Šค์ผ€์ดํ”„ ๋ฌธ์ž '-', '.', '_' ๋ฐ '~'๋ฅผ ๋””์ฝ”๋”ฉํ•ฉ๋‹ˆ๋‹ค.

์›ํ•˜๋Š” ๊ฒฝ์šฐ "header-strict", "host-strict", "host-normalize", "url-normalize", "url-normalize-unreserved", "url" ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์ •์—์„œ URL ์ฒ˜๋ฆฌ ๋™์ž‘์„ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -์ •๊ทœํ™”-ํ•„์ˆ˜โ€ ",
"url-ctrls-reject", "url-path-2f-decode", "url-path-dotseg-remove" ๋ฐ "url-query-20-plus"๋Š” ์ด์ œ "enable"๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.

๋‹ค๋ฅธ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์—๋Š” mod_webdav ๋ชจ๋“ˆ์˜ ์™„์ „ํ•œ ์žฌ์ž‘์—…์ด ํฌํ•จ๋˜์–ด ์žˆ์–ด ์‚ฌ์–‘๊ณผ์˜ ์™„์ „ํ•œ ํ˜ธํ™˜์„ฑ์„ ๋‹ฌ์„ฑํ•˜๊ณ  ์„ฑ๋Šฅ๊ณผ ์•ˆ์ •์„ฑ์„ ํ–ฅ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. mod_webdav์˜ ํ˜ธํ™˜์„ฑ์„ ๊นจ๋œจ๋ฆฌ๋Š” ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์ค‘์—๋Š” ๋ถˆ์™„์ „ํ•œ PUT ์š”์ฒญ ์ฐจ๋‹จ์ด ์žˆ์Šต๋‹ˆ๋‹ค. Mod_auth๋Š” ํ•ด์‹œ ์ธ์ฆ ๋งค๊ฐœ๋ณ€์ˆ˜(HTTP Auth Digest)๋ฅผ ์œ„ํ•œ SHA-256 ์•Œ๊ณ ๋ฆฌ์ฆ˜์— ๋Œ€ํ•œ ์ง€์›์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
mod_geoip๋ฅผ ๋Œ€์ฒดํ•˜๊ธฐ ์œ„ํ•ด ์ƒˆ๋กœ์šด ๋ชจ๋“ˆ์ธ mod_maxminddb๊ฐ€ ์ œ์•ˆ๋˜์—ˆ์Šต๋‹ˆ๋‹ค(mod_geoip๋Š” ์ด์ œ ๋” ์ด์ƒ ์‚ฌ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค).

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€