JAKARTAPROJECT
JAKARTA TIPJSP TIPJSP Áú¹®&´äº¯DATABASE TIPJAVASCRIPT TIPWEBHACKING TIP±âŸ TIP
JSP ÆÁ
JSP ÆÁ
JSP ÆÁ °Ô½ÃÆÇ ÀÔ´Ï´Ù
JSP Á÷Á¢ Á¢±Ù ÆäÀÌÁö ¸·±â
GoodBug
À̹ÌÁö ½½¶óÀÌ´õ º¸±â

Àß Á¤¸®µÈ ArticleÀÔ´Ï´Ù

 

URLÀ» ÅëÇؼ­ JSP ÆäÀÌÁö¿¡ Á÷Á¢ Á¢±ÙÇÏ´Â °ÍÀ» Â÷´ÜÇؾßÇÏ´Â °æ¿ì°¡ ÀÖ½À´Ï´Ù.

ƯÈ÷ ½ºÆ®·¯Ã÷ó·³ ÇÁ·ÐÆ® ÄÜƲ·Ñ·¯ ÆÐÅÏÀ» Àû¿ëÇÑ ½Ã½ºÅÛ¿¡¼­´Â ¼­ºí¸´ ÄÜÆ®·Ñ·¯¸¸ÀÌ

JSP¸¦ ½ÇÇàÇÒ ¼ö ÀÖ¾î¾ßÇÏÁÒ. 

 

±×·±µ¥ JSP ÆäÀÌÁö¸¦ ÀÏ¹Ý HTML ÆäÀÌÁö¿Í µ¿ÀÏÇÏ°Ô Ãë±ÞÇÏ¿© ¹èÄ¡ÇÏ°Ô µÇ¸é,

¿µ¸®ÇÑ(?) »ç¿ëÀÚ°¡ JSP °æ·Î¸¦ ¾Ë¾Æ³»¾î ¼­ºí¸´À» ÅëÇÏÁö ¾Ê°í ½ÇÇàÇÒ ¼ö°¡ ÀÖ½À´Ï´Ù.

 

JSP ÆäÀÌÁö¸¦ ¸ÅÇÎµÈ °æ·Î(*.do)¸¦ ÅëÇØ È£ÃâÇÏ´Â °ÍÀÌ Á¤»óÀÌÁö¸¸, ¿©ÀüÈ÷ JSPÆäÀÌÁö´Â

URIÁ¢±Ù¿¡ ³ëÃâµÇ¾î Àֱ⠶§¹®¿¡ »ç¿ëÀÚ°¡ ¸ÅÇΰæ·Î¸¦ ÅëÇÏÁö ¾Ê°í JSP ÆäÀÌÁö¸¦

½ÇÇàÇÏ´Â °ÍÀ» ¸·Áö´Â ¸øÇÑ´Ù´Â ¾ê±é´Ï´Ù.

 

À̸¦ ÇØ°áÇÒ ¿©·¯ °¡Áö ¹æ¹ýÀÌ ÀÖ½À´Ï´Ù.

 

(1) JSP¸¦ WEB-INF µð·ºÅ丮 ¹Ø¿¡ µÎ´Â ¹æ¹ý
¸ðµç JSP ÆäÀÌÁö¸¦ WEB-INF µð·ºÅ丮 ¾Æ·¡¿¡ µÎ´Â ¹æ¹ýÀÔ´Ï´Ù. WEB-INF µð·ºÅ丮´Â Ŭ¶óÀ̾ðÆ®¿¡°Ô´Â Á¢±ÙÀÌ ±ÝÁöµÇ¾î ÀÖÀ¸³ª, ÄÁÅ×À̳ʴ Á¢±ÙÀÌ Çã¿ëµË´Ï´Ù. ´Ù½Ã ¸»ÇÏ¸é »ç¿ëÀÚ´Â WEB-INF ¾Æ·¡ÀÇ JSP ÆäÀÌÁö¸¦ URI ·Î Á¢±ÙÇÏ¿© ½ÇÇàÇÒ ¼ö ¾øÀ¸³ª ÄÁÅ×À̳ʴ ½ÇÇà °¡´ÉÇÏ´Ù´Â °ÍÀÔ´Ï´Ù. ½ºÆ®·¯Ã÷ÀÇ °æ¿ì´Â ¾Æ·¡Ã³·³ JSP ÆäÀÌÁö¸¦ /WEB-INF ¾Æ·¡¿¡ ¹èÄ¡ÇÏ¿© ¸ÅÇÎÀ» Á¤ÀÇÇÏ¸é µË´Ï´Ù.

 

<action  path="/saveSubscription" 

         type="example.SaveSubscriptionAction">

   <forward="/WEB-INF/jsp/subscription.jsp"/>

</action>

 

ÀÌ ¹æ¹ýÀº ±×·¯³ª JSP ÆäÀÌÁö¿Í HTML/À̹ÌÁö ÆÄÀÏÀÌ ºÐ¸®µÇ¾î Á¸ÀçÇϹǷΠ´Ù¼Ò

È¥¶õ½º·´°í, È­¸é°³¹ß½Ã »ó´ë°æ·Î¸¦ È®ÀÎÇϱâ À§ÇØ JSP ÆäÀÌÁöÀÇ ¸ÅÇΰæ·Î¸¦ ¾Ë¾Æ¾ßÇÏ´Â

 ºÒÆíÀÌ ÀÖ½À´Ï´Ù.

 

¡Ø WebLogic 6.1¿¡¼­´Â WEB-INF ¹ØÀÇ JSPÆÄÀÏÀº ¼­ºí¸´¿¡¼­ Æ÷¿öµùÇÏ´Â °ÍÀÌ ºÒ°¡´ÉÇÏ´õ±º¿ä.(À¥·ÎÁ÷ 6.1ÀÇ ¹ö±×·Î »ý°¢µË´Ï´Ù.)

 

(2) web.xml¿¡¼­ JSPÆäÀÌÁö¿¡ º¸¾È¼³Á¤À» ÇÏ´Â ¹æ¹ý
web.xml¿¡ *.jsp ÆÐÅÏÀÇ ¸ðµç URL¿¡ ´ëÇؼ­ ´©±¸µµ ½ÇÇàÀ» ÇÒ ¼ö ¾ø°Ô ¼³Á¤ÇØÁÙ ¼ö

ÀÖ½À´Ï´Ù. ¾Æ·¡ ó·³ ¼¼ÆÃÇÏ¸é µË´Ï´Ù.

 

<security-constraint>

  <display-name>JSP Protection</display-name>

  <web-resource-collection>

    <web-resource-name>SecureJSPPages</web-resource-name>

      <url-pattern>*.jsp</url-pattern>

  </web-resource-collection>

  <auth-constraint>

    <role-name>nobody</role-name>

  </auth-constraint>

</security-constraint>

 

<security-role>

<description>

Nobody should be in this role so JSP files are protected

from direct access.

</description>

<role-name>nobody</role-name>

</security-role>

 

¾î¶² Àǵµ¸¦ °¡Áø »ç¿ëÀÚ°¡ JSP ÆäÀÌÁö¸¦ URL·Î Á÷Á¢ Á¢±ÙÇÏ°Ô µÇ¸é ¼­¹ö´Â

HTTP ÀÀ´äÄÚµå 401¹ø(Unauthorized) ÆäÀÌÁö¸¦ º¸¿©ÁÝ´Ï´Ù.

Á»´õ ¿ì¾ÆÇÏ°Ô Ã³¸®ÇÏ·Á¸é 401¹ø ÀÀ´ä ÆäÀÌÁö¸¦ ¿¹»Ú°Ô ¸¸µé¾î¼­ µî·ÏÇÏ¸é µÇ°ÚÁÒ.

 

<!-- Á¢±Ù ±ÇÇѾøÀ½ : UNAUTHORIZED-->

<error-page>

  <error-code>401</error-code>

  <location>/error/unauthorized.html</location>

</error-page>

 

from http://www.okjsp.pe.kr/bbs?act=VIEW&seq=33603&bbs=bbs4&keyfield=content&keyword=error-page&pg=0

2006-01-22 13:31:26
220.70.88.***

 

ÁÁÀº»ý°¢ ^^

0Á¡ (0¸í)
µ¡±Û 2°³ | ÅÂ±× 0°³ | °ü·Ã±Ûº¸±â
ű×ÀÔ·Â
½±Ç¥(,)±¸ºÐÀ¸·Î Çѹø¿¡ ¿©·¯ ű׸¦ ÀÔ·ÂÇÒ¼ö ÀÖ½À´Ï´Ù
¼­¿µ¾Æºü
(0) (0)
¿¡¼­ À» ºñ¿ì´Â°Ô ÈξÀ ½ÉÇÃÇÏ´õ±º¿ä. role-name¿¡ ¾Æ¹«°ªµµ ¾ÈÁÖ¸é ¼¼Æõµ ÇÊ¿ä¾ø°í jspÁ¢±Ù½Ã ¹Ù·Î FORBIDDEN 403 ¿¡·¯È­¸éÀÌ º¸¿©Áö³×¿ä. »ç½Ç À§ ±ÛÀ» okjsp¿¡ ¿Ã¸° »ç¶÷ÀÌ ¼­¿µ¾Æºü=¹ÚÁ¾Áø, Á¢´Ï´Ù. ±× ¶© Àß ¸ô¶ú´ø°ÔÁö¿ä... ^^;
203.247.145.*** 2006-02-10 11:51:52
GoodBug
(0) (0)
¾Æ ±×·¸±º¿ä Àúµµ º°»ý°¢ ¾øÀÌ role-nameÀ» Àû¾îÁÖ°ï Çߴµ¥ ±»ÀÌ ¾È½áÁà¿ä µÇ´Â±º¿ä ÁÁÀº³»¿ëÀÔ´Ï´Ù °¨»çÇÕ´Ï´Ù
211.189.124.*** 2006-03-23 17:46:46
À̸§ ºñ¹Ð¹øÈ£
JSP ÆÁ
JSP ÆÁ °Ô½ÃÆÇ ÀÔ´Ï´Ù
! ¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ ÀÏÀÚ Á¶È¸
114 STS Spring MVC on STS 2.8, 2.9 ¹öÀü¿¡¼­ ÇÁ·ÎÁ§Æ® »ý¼º½Ã ¿¡·¯¹ß»ý ÇÒ °æ¿ì 1 GoodBug 2012-03-08 8,112
113 dbcp DBCP »ç¿ë½Ã DBÁ¤º¸ ¾Ïȣȭ 1 GoodBug 2012-02-08 5,617
112 ½ºÆ®·µÃ÷ action alert ¸Þ½ÃÁö Ãâ·Â ÈÄ ÆäÀÌÁö À̵¿ & µÚ·Î°¡±â ¿¹¹æ ÇູÇѱ¤´ë 2009-01-14 11,643
111 spring spring ÀÚµ¿¹­±â 1 kaiser 2007-03-12 11,853
110 spring Spring ºó¹­±â- »ý¼ºÀÚ¸¦ ÅëÇÑ ÀÇÁ¸¼º ÁÖÀÔ 2 1 kaiser 2007-02-21 21,611
109 spring Spring ºó¹­±â-¼¼Å͸޼ҵ带 ÅëÇÑ ÀÇÁ¸¼º ÁÖÀÔ 1 kaiser 2007-02-21 11,909
108 spring Spring - xml·Î ¹­±â 1 kaiser 2007-02-07 12,406
107 spring Spring ºó¹­±â-±âº»¹­±â 1 kaiser 2007-02-05 8,817
106 spring spring ºó¹­±â-2 1 kaiser 2007-01-29 9,683
105 spring Spring ºó¹­±â-1 1 kaiser 2007-01-29 9,748
104 spring Spring 1Â÷ ¿ä¾à 1 kaiser 2007-01-23 10,869
103 spring spring ½ÃÀÛÇϱâ-2 1 1 kaiser 2007-01-22 9,970
102 spring Spring ½ÃÀÛÇϱâ-1 4 1 kaiser 2007-01-22 11,687
101 spring Spring ¼­·Ð - spring ¼³Ä¡ 1 1 kaiser 2007-01-19 13,361
100 clob »ç¿ëÇϱâ kaiser 2008-08-21 7,679
99 span ±Û¾²±â ÈÄ »ç¿ëÇÒ protoload 1 1 °í°í½Ì 2008-05-09 7,185
98 log4sql log4sql 1 1 Aki 2008-04-30 8,403
97 ¼ýÀÚ ¼¼ÀÚ¸®¸¶´Ù ÄÞ¸¶ Âï±â 1 °ö½½´ë¸¶¿Õ 2008-03-21 8,527
96 iBatis iBatis ¿¡¼­ SQL ·Î±ë½Ã ÀÌ»Ñ°Ô º¸À̱â 6 1 GoodBug 2007-10-26 22,610
95 log4sql¿äÁò ¸¹ÀÌ ¾²´Â°Í °°´øµ¥.... ¿µÀ̳²Ç¦ 2008-10-17 8,132
copyright 2005-2024 by Unicorn