Á¦°ÅÇÏ°í ¼³Ä¡¸¦ ÇØÁ¦Çϰųª ¹«´ÉÇÏ°Ô ÇϽʽÿÀ ModSecurity (mod_security)¸¦
ModSecurity´Â À¥ ¾ÖÇø®ÄÉÀ̼ÇÀ» À§ÇÑ ¿ÀÇ ¼Ò½º embeddable À¥ ¾ÖÇø®ÄÉÀÌ¼Ç ¹æÈ£º®, ¶Ç´Â ¹«Àü¸ÁħÀÔ Å½Áö ¹× ¿¹¹æ ¿£ÁøÀÌ´Ù. ModSecurity´Â À¥ ¾ÖÇø®ÄÉÀ̼ǿ¡ ´ëÇÏ¿© °ø°ÝÀÇ ¹üÀ§¿¡¼ º¸È£ÇØÁÖ°í HTTP ¼ÒÅë·® °¨½Ã¿Í ¼ø°£ ºÐ¼®À» ±âÁ¸ÇÏ´Â ±â¹Ý¿¡ º¯È ¾øÀÌ ¿î¿µÇؼ Apache Web Server ´ÜÀ§ mod_security·Î, ¶Ç´Â µ¶¸³, ÀÌ·¸°Ô À¥ ¾ÖÇø®ÄÉÀÌ¼Ç ¾ÈÀüÀ» Áõ°¡ÇÑ´Ù. ±×·¯³ª, À߸ø ¼³Á¤ÇÏ´Â Àü¸éÀ¸·Î ÁؾöÇÑ ±ÔÄ¢ ¼¼Æ®, ModSecurity´Â ´ç½ÅÀÇ À¥»çÀÌÆ®¸¦ HTTP 403 ±ÝÁöÇÑ °ú½Ç°ú °°Àº °¢Á¾ °ú½ÇÀ» µ¹·Áº¸³»°Å³ª ºÎÁ¤ÇÑ °ú½Ç ·Î±×ÀÎ ¹®Á¦, ¶Ç´Â HTTP 412 ÀüÁ¦ Á¶°Ç¿¡ ÀÇÇÏ¿© ½ÇÆÐµÈ °ú½Ç, ¶Ç´Â HTTP 406 ¼ö¶ô°¡´ÉÇÑ °ú½Ç ¹× ´Ù¸¥ Ʋ¸° È®½Ç¼º ÁõÈĸ¦ Á¢±ÙÇÏ´Â ¿øÀÎÀÌ µÉÁöµµ ¸ð¸¥´Ù.
»çÁ¤À» ´õ ³ª»Û ½Ã۱â À§ÇÏ¿©´Â, ModSecurity ±ÔÄ¢ÀÇ À±°û ¹× ¿©°ú±â´Â ¼öµ¿À¸·Î ÇàÇØÁ®¾ß ÇÑ´Ù. ³õÀÎ »óÀÚ¿¡¼ ModSecurity¿Í ÇÔ²² »ç¿ëµÉ ¼ö ÀÖ´Â ÀÚÀ¯·Ó°Ô ¹Ì¸® Á¤ÀÇÇÑ Áõ¸íÇÑ ±ÔÄ¢ÀÌ ÀÖ´õ¶óµµ, ±ÔÄ¢ ¼¼Æ®°¡ °¢ ȯ°æÀ» À§ÇØ Àû´çÇÒÁöµµ À¥»çÀÌÆ® blogs, ÁÖ¹®À» ¹Þ¾Æ¼ ¸¸µé°í º¯°æÀÇ °¡µ¿°ú ¹æÇØÇÒÁöµµ ¸ð¸¥´Ù ±×·¯³ª ±ÔÄ¢Àº ¸î¸î »ç¿ëÀÚ¸¦ À§ÇØ ³Ê¹« Á¤±³Çϰųª º¹ÀâÇÒÁöµµ ¸ð¸¥´Ù. ±×¸®°í °øµ¿ È£½ºÆ® ¼ºñ½º¿¡ Á¢´ëÇÑ ¸î¸î À¥»çÀÌÆ®¸¦ À§ÇØ, mod_security´Â ¼±ÅÃ±Ç ¾øÀÌ ºÎÀü½ÂÀ¸·Î °¡´ÉÇÏ°Ô ÇÑ´Ù ÀÏÁöµµ ¸ð¸¥´Ù. ÀÌ·¸°Ô ÀÌ °æ¿ì¿¡´Â, mod ¾ÈÀü º¸Àå¿¡ °ü°èµÇ´Â ¹®Á¦Á¡À» À§ÇÑ Á¦ÀÏ ÇØ°áÃ¥ ¶Ç´Â workaround´Â °Å¸£´Â mod_security¸¦ ¹«´ÉÇÏ°Ô Çϱâ À§ÇÑ °ÍÀ̰í Áö¹èÇÑ´Ù.
´ç½ÅÀÌ Apache Web Server (ÁÖ·Î) »ç¿ëÇÏ´Â °æ¿ì¿¡, mod_security´Â .htaccess ÆÄÀÏ¿¡ Àִ Ư¼ºÀ» Ãß°¡Çؼ ¹«´ÉÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. Á¸ÀçÇÏÁö ¾ÊÀ¸¸ç, .htaccessÀ̶ó°í Áö¸íµÈ »õ ÆÄÀÏÀ» âÁ¶ÇÏÁö ¾ÊÀ¸¸ç °æ¿ì¿¡, µÚ¿¡ ¿À´Â ºÎÈ£¿¡¼ µ¡ºÙÀÌÁö ¾ÊÀ¸¸é, ¾ÆÆÄÄ¡ À¥ ·çÆ® µð·ºÅ丮¿¡ ÀÖ´Â .htaccess ÆÄÀÏÀ» (public_html ¶Ç´Â /var/www/ ¶Ç´Â ´Ù¸¥ »ç¶÷) ã¾Æ³»½Ê½Ã¿À:
¶³¾îÁ® SecFilterEngine
¶³¾îÁ® SecFilterScanPOST
.htaccess¿¡ ÀÖ´Â À§ ÀÔÀåÀº ¿µ¿ªÀ» À§ÇÑ ModSecurity (mod_security) ´ÜÀ§¸¦ ¹«´ÉÇÏ°Ô ÇÒ °ÍÀÌ´Ù.
¾ÆÆÄÄ¡ ´ÜÀ§¿¡¼ ModSecurity (mod_security)ÀÇ »èÁ¦
mod_security¸¦ Á¦°ÅÇÏ°í ¼³Ä¡¸¦ ÇØÁ¦ÇÏ´Â ½¬¿î ¹æ¹ýÀº ¼³¸íÇϰųª httpd.conf ¾ÆÆÄÄ¡ ±¸¼º ÆÄÀÏ¿¡¼ °ü·Ã mod_security ÀÔÀåÀ» »èÁ¦Çϱâ À§ÇÑ °ÍÀÌ´Ù. Á¦°ÅµÇ¾î¾ß ÇÏ´Â ¼±Àº ´ÙÀ½À» Æ÷ÇÔÇÑ´Ù:
AddModule mod_security.c
LoadModule security_module ´ÜÀ§ ¶Ç´Â mod_security.so
Æ÷ÇÔÇϽʽÿÀ "/usr/local/apache/conf/modsec.conf"¸¦ ÀÌ ¼±Àº ¸®´ª½º À¯´Ð½ºÀÇ ¹«½¼ ÀÌü¸¦ ´ç½ÅÀÌ ±×¸®°í ÀÓ¸í À§Ä¡ »ç¿ëÇÑ¿¡ µû¶ó¼ ´Ù¸¦Áöµµ ¸ð¸¥´Ù
httpd.conf¸¦ ÀúÀåÇÏ°í ¾ÆÆÄÄ¡¸¦ ÀçÃâ¹ßÇϽʽÿÀ. ModSecurity´Â ¼³Ä¡¸¦ ÇØÁ¦ÇØ Ã³·³ ÀûÀçµÇÁö ¾ÊÀ¸¸ç.
´ç½ÅÀÌ WebHost ¸Å´ÏÀú (WHM)¸¦ »ç¿ëÇÏ´Â °æ¿ì¿¡, »èÁ¦´Â ´õ °£´ÜÇÏ´Ù Á¶Â÷. cPanel ´Ü¸éµµ¿¡ Á¤´çÇÑ ÀÏÆøÀº, Addon ´ÜÀ§¸¦ Ŭ¸¯ÇÑ´Ù. ±× ¶§ ´ÜÀ§¿¡ ÀÏÆøÀº modsecurity¸¦ Áö¸íÇß´Ù. ¼³Ä¡Çϰí À¯ÁöÇÑ´Ù ÇöÀç »õ·Ó°Ô ÇØ °Ë»çµÇ¾î¾ß ÇÑ´Ù. ´Ù¸¸ À§¿¡ Apache Web Server¿¡¼ mod ¾ÈÀü Ư¡À» Á¦°ÅÇϱâ À§ÇÏ¿© ¼³Ä¡¸¦ ÇØÁ¦ÇÑ´Ù ´©¸£½Ê½Ã¿À.
Áß¿äÇÑ : This is a machine translated page which is provided "as is" without warranty. Machine translation may be difficult to understand. Please refer to original English article whenever possible.
Share and contribute or get technical support and help at My Digital Life Forums.
Related Articles
- Remove and Uninstall Microsoft Office Activation Assistant - Fix Office Must Be Installed Error
- Disable and Remove URGE Online Store in Windows Media Player 11 (WMP11)
- How to Disable (Remove and Uninstall) Windows Defender in Vista
- Vista Uninstall, Change or Repair Programs and Updates Button Disappear and Not Showing
- How to Uninstall and Remove Spb Wallet Toolbar in IE Browser
- Disable and Remove Yahoo! Messenger 9 Ads
- How to Uninstall Paradox Vista Activation Crack and Activator
- How to Remove and Uninstall Vista Activation Cracks with VOATK Tools
- Manually Uninstall and Delete Spb Wallet Toolbar from Firefox
- Alternative Windows Uninstaller MyUninstaller to Remove Hidden Programs




























July 7th, 2007 00:16
A BIG Thanks to You!
It really works! Thanks You!
February 2nd, 2008 00:51
Exactly what I was looking for, thanks
April 17th, 2008 17:13
Thanks alot! It works!
June 29th, 2008 23:47
Cheers, just what I needed, worked first time