Select the product you need help with
Microsoft Source Code Analyzer for SQL Injection µµ±¸¸¦ »ç¿ëÇÏ¿© ASP Äڵ忡¼ SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡À» ãÀ» ¼ö ÀÖ´Ù±â¼ú ÀÚ·á: 954476 - ÀÌ ¹®¼°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â. ÀÌ ÆäÀÌÁö¿¡¼¼Ò°³
ÀÌ ¹®¼¿¡¼´Â Microsoft Source Code Analyzer for SQL Injection µµ±¸¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. ÀÌ Á¤Àû ÄÚµå ºÐ¼® µµ±¸¸¦ »ç¿ëÇÏ¿© ASP Äڵ忡¼ SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡À» ãÀ» ¼ö ÀÖ½À´Ï´Ù. Ãß°¡ Á¤º¸
Microsoft Source Code Analyzer for SQL Injection µµ±¸´Â ASP(Active Server Pages) Äڵ忡¼ SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡À» ãµµ·Ï µµ¿ÍÁÖ´Â Á¤Àû ÄÚµå ºÐ¼® µµ±¸ÀÔ´Ï´Ù. ÀÌ ¹®¼¿¡¼´Â ÀÌ µµ±¸¸¦ »ç¿ëÇÏ´Â ¹æ¹ý, µµ±¸¿¡¼ »ý¼ºµÇ´Â °æ°í ¹× µµ±¸ÀÇ Á¦ÇÑ »çÇ׿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù. ÀÚ¼¼ÇÑ ³»¿ëÀº µµ±¸ Ãß°¡ Á¤º¸ ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
ÀüÁ¦ Á¶°ÇÀÌ ¸í·ÉÁÙ µµ±¸¸¦ »ç¿ëÇÏ·Á¸é ´ÙÀ½ ¼ÒÇÁÆ®¿þ¾î°¡ ÇÊ¿äÇÕ´Ï´Ù.
ASP ÄÚµåÀÇ SQL »ðÀÔ °ø°Ý ¹®Á¦ASP ÄÚµåÀÇ Request.Form ¶Ç´Â Request.Querystring Ä÷º¼Ç¿¡¼ »ç¿ëÀÚ°¡ Á¦°øÇÑ µ¥ÀÌÅͰ¡ µ¥ÀÌÅÍ À¯È¿¼º °Ë»ç ¾øÀÌ µ¿Àû SQL ¹®À» ¸¸µå´Â µ¥ »ç¿ëµÇ´Â °æ¿ì °ø°ÝÀÚ°¡ SQL ¸í·ÉÀ» SQL ¹®¿¡ »ðÀÔÇÏ°í ¾Ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. À̸¦ ÀϹÝÀûÀ¸·Î 1Â÷ SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡À̶ó°í ÇÕ´Ï´Ù.ÇÑ ASP ÆäÀÌÁö¸¦ »ç¿ëÇÏ¿© µ¥ÀÌÅͺ£À̽º¿¡ ÀúÀåµÈ »ç¿ëÀÚ ÀÔ·ÂÀÌ µ¥ÀÌÅͺ£À̽º¿¡¼ °Ë»öµÈ ´ÙÀ½ ´Ù¸¥ ASP ÆäÀÌÁö¿¡¼ µ¿Àû SQL ¹®À» ¸¸µå´Â µ¥ »ç¿ëµÇ´Â °æ¿ì °ø°ÝÀÚ°¡ SQL ¸í·ÉÀ» SQL ¹®¿¡ »ðÀÔÇÏ°í ¾Ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù. À̸¦ ÀϹÝÀûÀ¸·Î 2Â÷ SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡À̶ó°í ÇÕ´Ï´Ù. ÀÌ·¯ÇÑ Ãë¾àÁ¡À» ÁÙÀÌ·Á¸é ¸Å°³ º¯¼ö°¡ ÀÖ´Â SQL Äõ¸®¸¦ »ç¿ëÇÏ´Â °ÍÀÌ °¡Àå ÁÁ½À´Ï´Ù. ASPÀÇ SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡°ú ÀÌ·¯ÇÑ Ãë¾àÁ¡À» ÁÙÀÌ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ. http://msdn.microsoft.com/en-us/library/cc676512.aspx
Microsoft Source Code Analyzer for SQL Injection µµ±¸´Â ÀÌ·¯ÇÑ ¹®Á¦ Áß ÀϺθ¦ ÀÚµ¿À¸·Î ã´Â µ¥ µµ¿òÀÌ µË´Ï´Ù.
(http://msdn.microsoft.com/en-us/library/cc676512.aspx)
(¿µ¹®)»ç¿ë¹ýÀÌ Àý¿¡¼´Â ÀÌ µµ±¸¸¦ »ç¿ëÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ ¼³¸íÇÕ´Ï´Ù.±¸¹®ÀÌ µµ±¸´Â ´ÙÀ½ ±¸¹®À» »ç¿ëÇÕ´Ï´Ù.msscasi_asp.exe [/nologo] [/quiet] [/suppress=num;..;num] [/GlobalAsaPath=path] [/IncludePaths=path;..;path] /Input=file.asp ¼³¸íÀÌ µµ±¸´Â ASP Äڵ带 ºÐ¼®ÇÏ¿© SQL »ðÀÔ °ø°Ý Ãë¾àÁ¡À» ã½À´Ï´Ù.¸Å°³ º¯¼ö ¸ñ·ÏÇ¥ Ãà¼Ò
¿¹Á¦Ãâ·Â °ËÅäÀÌ µµ±¸´Â ´ÙÀ½°ú °°Àº °æ°í¸¦ »ý¼ºÇÕ´Ï´Ù.Ç¥ Ãà¼Ò
http://msdn.microsoft.com/en-us/library/cc676512.aspx
(http://msdn.microsoft.com/en-us/library/cc676512.aspx)
(¿µ¹®)Á¦ÇÑ »çÇ×ÀÌ µµ±¸¿¡´Â ´ÙÀ½°ú °°Àº ¾Ë·ÁÁø Á¦ÇÑ »çÇ×ÀÌ ÀÖ½À´Ï´Ù.
ÂüÁ¶
Microsoft Source Code Analyzer for SQL Injection µµ±¸¸¦ ´Ù¿î·ÎµåÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
http://www.microsoft.com/downloads/details.aspx?FamilyId=58A7C46E-A599-4FCB-9AB4-A4334146B6BA
´Ù¾çÇÑ ¸ð¹ü »ç·Ê ¼³¸í¼¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ.
(http://www.microsoft.com/downloads/details.aspx?FamilyId=58A7C46E-A599-4FCB-9AB4-A4334146B6BA)
(¿µ¹®)http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx
ASP¿¡¼ SQL »ðÀÔ °ø°ÝÀ» ¹æÁöÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ.
(http://blogs.technet.com/swi/archive/2008/05/29/sql-injection-attack.aspx)
(¿µ¹®) http://msdn.microsoft.com/en-us/library/cc676512.aspx
SQL »ðÀÔ °ø°Ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ.
(http://msdn.microsoft.com/en-us/library/cc676512.aspx)
(¿µ¹®)http://blogs.msdn.com/sdl/archive/2008/05/15/giving-sql-injection-the-respect-it-deserves.aspx
ÀÌ µµ±¸¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ.
(http://blogs.msdn.com/sdl/archive/2008/05/15/giving-sql-injection-the-respect-it-deserves.aspx)
(¿µ¹®) http://blogs.msdn.com/sqlsecurity
MSDN SQL º¸¾È Æ÷·³¿¡¼ µµ±¸¿¡ ´ëÇØ ³íÀÇÇÏ·Á¸é ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ¹æ¹®ÇϽʽÿÀ.
(http://blogs.msdn.com/sqlsecurity)
(¿µ¹®)http://forums.microsoft.com/msdn/ShowForum.aspx?ForumID=92&SiteID=1
(http://forums.microsoft.com/msdn/ShowForum.aspx?ForumID=92&SiteID=1)
(¿µ¹®)¼Ó¼º±â¼ú ÀÚ·á: 954476 - ¸¶Áö¸· °ËÅä: 2008³â 6¿ù 27ÀÏ ±Ý¿äÀÏ - ¼öÁ¤: 1.0
| ±â¼ú ÀÚ·á ¹ø¿ª
|


À§·Î °¡±â








