Hamutaro - Hamtaro 4

Infra/Security

[Security] CSRF ๋ž€?

carsumin 2026. 2. 10. 15:48
CSRF (Cross-Site Request Forgery)
  • ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธ ์ƒํƒœ๋ฅผ ์•…์šฉํ•ด์„œ ๊ณต๊ฒฉ์ž๊ฐ€ ์˜๋„ํ•œ ์š”์ฒญ์„ ์„œ๋ฒ„์— ๋Œ€์‹  ๋ณด๋‚ด๊ฒŒ ๋งŒ๋“œ๋Š” ๊ณต๊ฒฉ

 

์–ด๋–ป๊ฒŒ ๊ณต๊ฒฉ์ด ๋˜๋Š”์ง€?

1. ์‚ฌ์šฉ์ž๊ฐ€ ์„œ๋น„์Šค์— ๋กœ๊ทธ์ธ (์ฟ ํ‚ค๋กœ ์ธ์ฆ)

2. ์‚ฌ์šฉ์ž๊ฐ€ ๊ณต๊ฒฉ์ž ์‚ฌ์ดํŠธ๋ฅผ ๋ฐฉ๋ฌธ

3. ๊ณต๊ฒฉ์ž ์‚ฌ์ดํŠธ์— ์ด๋Ÿฐ ์ฝ”๋“œ๊ฐ€ ์žˆ์Œ

<form action="https://our-service.com/api/users/withdraw" method="POST">
  <input type="hidden" name="amount" value="1000000">
</form>
<script>document.forms[0].submit()</script>

4. ๋ธŒ๋ผ์šฐ์ €๋Š” ์ฟ ํ‚ค๋ฅผ ์ž๋™์œผ๋กœ ๊ฐ™์ด ์ „์†ก

5. ์„œ๋ฒ„๋Š” ์ •์ƒ ๋กœ๊ทธ์ธ ์‚ฌ์šฉ์ž ์š”์ฒญ์œผ๋กœ ์˜คํ•ด

 

CSRF ์„ฑ๋ฆฝ ์กฐ๊ฑด
  • ์ธ์ฆ ์ˆ˜๋‹จ์ด ์ฟ ํ‚ค ๊ธฐ๋ฐ˜์ผ ๊ฒƒ
  • ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ์ž๋™์œผ๋กœ ์ธ์ฆ ์ •๋ณด ์ „์†กํ•  ๊ฒƒ
์„ธ์…˜ + ์ฟ ํ‚ค โœ… ๋ฐ˜๋“œ์‹œ ํ•„์š”
JWT + Header โŒ ๋ถˆํ•„์š”
์ˆœ์ˆ˜ REST API โŒ disable

'Infra > Security' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Security] JWT + HttpOnly Cookie + SameSite ์ „๋žต ์ •๋ฆฌ  (0) 2026.02.14