Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -83,3 +83,8 @@
**Vulnerability:** ์ •์  HTML ์ƒ์„ฑ ๋„๊ตฌ์—์„œ ๋งค๋ฒˆ ๋‹ค๋ฅธ Nonce๋ฅผ ๋™์ ์œผ๋กœ ์ƒ์„ฑํ•˜์—ฌ CSP์— ์ ์šฉํ•˜๋Š” ๊ฒƒ์€, ์บ์‹ฑ ํšจ์œจ์„ ์ €ํ•˜์‹œํ‚ฌ ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์ •์  ๋ฐฐํฌ ํ™˜๊ฒฝ(์˜ˆ: GitHub Pages ๋“ฑ)์—์„œ ์˜ฌ๋ฐ”๋ฅธ ๋ณด์•ˆ ์ •์ฑ… ์ˆ˜๋ฆฝ์„ ๋ฐฉํ•ดํ•  ์ˆ˜ ์žˆ๋Š” ์•ˆํ‹ฐ ํŒจํ„ด์ž…๋‹ˆ๋‹ค.
**Learning:** ์ •์ ์œผ๋กœ ๊ณ ์ •๋œ ์ธ๋ผ์ธ ์Šคํƒ€์ผ์ด๋‚˜ ์Šคํฌ๋ฆฝํŠธ์—๋Š” ๋‚œ์ˆ˜ํ™”๋œ Nonce๋ณด๋‹ค ์ฝ˜ํ…์ธ  ์ž์ฒด์˜ ํ•ด์‹œ(SHA-256 ๋“ฑ)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์•ˆ์ „ํ•˜๊ณ  ์ผ๊ด€๋œ ๋ฐฉ์‹์ž„์„ ๋ฐฐ์› ์Šต๋‹ˆ๋‹ค.
**Prevention:** ์ž๋™ ์ƒ์„ฑ๋˜๋Š” ์ •์  HTML์˜ ์ฝ˜ํ…์ธ  ๋ณด์•ˆ ์ •์ฑ…(CSP)์—๋Š” `style-src 'sha256-<HASH>'` ๋ฐฉ์‹์„ ์ ์šฉํ•˜๊ณ , `<style>` ํƒœ๊ทธ์—์„œ ๋ถˆํ•„์š”ํ•œ `nonce` ์†์„ฑ์„ ์ œ๊ฑฐํ•˜์—ฌ ๋ธŒ๋ผ์šฐ์ €์˜ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๊ธฐ๋Šฅ์„ ์ ๊ทน ํ™œ์šฉํ•˜์‹ญ์‹œ์˜ค.

## 2024-07-14 - [MEDIUM] TOCTOU ๋ฐ ์ž…์ถœ๋ ฅ ์˜ˆ์™ธ๋กœ ์ธํ•œ ํฌ๋กค๋Ÿฌ ์ค‘๋‹จ(DoS) ๋ฐฉ์ง€ ๋ฐ Fail Securely ๊ตฌํ˜„
**Vulnerability:** ํŒŒ์ผ ํŒŒ์‹ฑ ์ค‘ ๋ฐœ์ƒํ•˜๋Š” IO ์˜ˆ์™ธ(`FileNotFoundException`, `AccessDeniedException` ๋“ฑ)๋‚˜ ์ž˜๋ชป๋œ ํŒŒ์ผ ์ด๋ฆ„ ๋„๋ฐ”์ดํŠธ ๋“ฑ์œผ๋กœ ์ธํ•œ `InvalidPathException` ๋ฐœ์ƒ ์‹œ ์ „์ฒด ํฌ๋กค๋Ÿฌ๊ฐ€ ํฌ๋ž˜์‹œ(DoS)๋˜๋Š” ๋ฌธ์ œ. TOCTOU ์ƒํ™ฉ์—์„œ๋„ ํŒŒ์ผ ์ ‘๊ทผ ์˜ค๋ฅ˜๋กœ ํฌ๋ž˜์‹œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
**Learning:** ํŒŒ์ผ I/O๋‚˜ ๊ฒฝ๋กœ ์ฒ˜๋ฆฌ ์ค‘์—๋Š” ๋‹ค์–‘ํ•œ ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๋‹จ์ผ ํŒŒ์ผ์ด๋‚˜ ๋””๋ ‰ํ† ๋ฆฌ์— ๋Œ€ํ•œ ์˜ˆ์™ธ๊ฐ€ ์ „์ฒด ํ”„๋กœ์„ธ์Šค์˜ ์‹คํ–‰์„ ๋ง‰์•„์„  ์•ˆ ๋ฉ๋‹ˆ๋‹ค. ์˜ˆ์™ธ๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ์žก์•„๋‚ด์–ด ํฌ๋ž˜์‹œ๋ฅผ ๋ฐฉ์ง€ํ•˜๊ณ , ๊ธฐ๋ณธ ์„ค์ •(์˜ˆ: ๋ฏผ๊ฐํ•œ ํŒŒ์ผ ๋ฌด์‹œ)์„ ์œ ์ง€ํ•˜์—ฌ ์ง„ํ–‰ํ•˜๋Š” Fail Securely ์ „๋žต์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.
**Prevention:** ํฌ๋กค๋Ÿฌ์™€ ๊ฐ™์€ ์žฌ๊ท€์  I/O ํ”„๋กœ์„ธ์Šค์—์„œ๋Š” ๊ฐ ๋…ธ๋“œ(ํŒŒ์ผ/๋””๋ ‰ํ† ๋ฆฌ) ์ฒ˜๋ฆฌ ๋กœ์ง์„ `try-catch`๋กœ ๊ฐ์‹ธ ์˜ˆ์ƒ์น˜ ๋ชปํ•œ ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•˜๋”๋ผ๋„ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ณ„์† ์‹คํ–‰๋  ์ˆ˜ ์žˆ๋„๋ก ๋ฐฉ์–ด์  ํ”„๋กœ๊ทธ๋ž˜๋ฐ์„ ์ ์šฉํ•˜์‹ญ์‹œ์˜ค.
59 changes: 34 additions & 25 deletions src/main/kotlin/html4tree/main.kt
Original file line number Diff line number Diff line change
Expand Up @@ -181,35 +181,44 @@ fun process_ignore_file(curr_dir: File, dirFilesNames: Array<String>? = null): S
// ๋ณด์•ˆ ํ–ฅ์ƒ: .html4ignore ํŒŒ์ผ์ด ์ผ๋ฐ˜ ํŒŒ์ผ์ธ์ง€ ํ™•์ธํ•˜๊ณ , ์‹ฌ๋ณผ๋ฆญ ๋งํฌ์ธ ๊ฒฝ์šฐ ๋ฌด์‹œํ•˜์—ฌ DoS ๋ฐ ๊ฒฝ๋กœ ์กฐ์ž‘์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.
// ๋ณด์•ˆ ํ–ฅ์ƒ: ํŒŒ์ผ ํฌ๊ธฐ(1MB ์ œํ•œ) ๋ฐ ์ค„ ์ˆ˜(1000์ค„), ์ •๊ทœ์‹ ๊ธธ์ด(100์ž)๋ฅผ ์ œํ•œํ•˜์—ฌ ReDoS ๋ฐ ๋ฉ”๋ชจ๋ฆฌ ๊ณ ๊ฐˆ(OOM) ๋ฐฉ์ง€
// ๋ณด์•ˆ ํ–ฅ์ƒ: ๊ถŒํ•œ์ด ์—†๋Š” ํŒŒ์ผ ์ ‘๊ทผ ์‹œ ๋ฐœ์ƒํ•˜๋Š” ์˜ˆ์™ธ(DoS)๋ฅผ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด canRead() ์ถ”๊ฐ€ ํ™•์ธ
if(ignore_file.isFile && !Files.isSymbolicLink(ignore_file.toPath()) && ignore_file.canRead() && ignore_file.length() <= 1048576){
val ignored_matchers = mutableListOf<java.nio.file.PathMatcher>()

ignore_file.useLines { lines ->
for ((lineIndex, it) in lines.withIndex()) {
// ์ค„ ์ˆ˜ ์ œํ•œ์ด ํŒจํ„ด ์ˆ˜๋„ ํ•จ๊ป˜ ์ƒํ•œ(์ค„๋‹น ์ตœ๋Œ€ 1๊ฐœ ํŒจํ„ด)ํ•˜๋ฏ€๋กœ ๋ณ„๋„ ํŒจํ„ด ์นด์šดํ„ฐ๋Š” ๋ถˆํ•„์š”
if (lineIndex >= 1000) break
val pattern = it.trim()
if (pattern.isNotEmpty() && pattern.length <= 100) {
try {
ignored_matchers.add(java.nio.file.FileSystems.getDefault().getPathMatcher("glob:$pattern"))
} catch (_: java.util.regex.PatternSyntaxException) {
// ๋ณด์•ˆ ํ–ฅ์ƒ: TOCTOU(Time-of-Check to Time-of-Use) ์ทจ์•ฝ์ ์ด๋‚˜ ํŒŒ์ผ ์ฝ๊ธฐ ์ค‘ ๋ฐœ์ƒํ•˜๋Š” ์˜ˆ๊ธฐ์น˜ ๋ชปํ•œ Exception์œผ๋กœ ์ธํ•ด ์ „์ฒด ํฌ๋กค๋Ÿฌ๊ฐ€ ์ค‘๋‹จ(DoS)๋˜๋Š” ๊ฒƒ์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค. (Fail Securely)
try {
if(ignore_file.isFile && !Files.isSymbolicLink(ignore_file.toPath()) && ignore_file.canRead() && ignore_file.length() <= 1048576){
val ignored_matchers = mutableListOf<java.nio.file.PathMatcher>()

ignore_file.useLines { lines ->
for ((lineIndex, it) in lines.withIndex()) {
// ์ค„ ์ˆ˜ ์ œํ•œ์ด ํŒจํ„ด ์ˆ˜๋„ ํ•จ๊ป˜ ์ƒํ•œ(์ค„๋‹น ์ตœ๋Œ€ 1๊ฐœ ํŒจํ„ด)ํ•˜๋ฏ€๋กœ ๋ณ„๋„ ํŒจํ„ด ์นด์šดํ„ฐ๋Š” ๋ถˆํ•„์š”
if (lineIndex >= 1000) break
val pattern = it.trim()
if (pattern.isNotEmpty() && pattern.length <= 100) {
try {
ignored_matchers.add(java.nio.file.FileSystems.getDefault().getPathMatcher("glob:$pattern"))
} catch (_: java.util.regex.PatternSyntaxException) {
}
}
}
}
}

// โšก Bolt Performance Optimization: ๋””๋ ‰ํ† ๋ฆฌ ๋ชฉ๋ก์„ Set์— ์ถ”๊ฐ€ํ•˜๊ธฐ ์œ„ํ•ด ํ•„ํ„ฐ๋ง๋งŒ ํ•  ๋•Œ๋Š” ์ •๋ ฌ์ด ๋ถˆํ•„์š”ํ•˜๋ฏ€๋กœ .sorted()๋ฅผ ์ œ๊ฑฐํ•˜์—ฌ O(N log N) ์˜ค๋ฒ„ํ—ค๋“œ๋ฅผ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.
val list = dirFilesNames ?: curr_dir.list()
list?.forEach {
val current = it
val pathCurrent = java.nio.file.Paths.get(current)
for (matcher in ignored_matchers) {
if (matcher.matches(pathCurrent)) {
files_to_exclude.add(current)
break
}

// โšก Bolt Performance Optimization: ๋””๋ ‰ํ† ๋ฆฌ ๋ชฉ๋ก์„ Set์— ์ถ”๊ฐ€ํ•˜๊ธฐ ์œ„ํ•ด ํ•„ํ„ฐ๋ง๋งŒ ํ•  ๋•Œ๋Š” ์ •๋ ฌ์ด ๋ถˆํ•„์š”ํ•˜๋ฏ€๋กœ .sorted()๋ฅผ ์ œ๊ฑฐํ•˜์—ฌ O(N log N) ์˜ค๋ฒ„ํ—ค๋“œ๋ฅผ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.
val list = dirFilesNames ?: curr_dir.list()
list?.forEach {
val current = it
try {
val pathCurrent = java.nio.file.Paths.get(current)
for (matcher in ignored_matchers) {
if (matcher.matches(pathCurrent)) {
files_to_exclude.add(current)
break
}
}
} catch (e: Exception) {
// ๋ณด์•ˆ ํ–ฅ์ƒ: ๊ฐœ๋ณ„ ํŒŒ์ผ๋ช…(์˜ˆ: ๋„ ๋ฐ”์ดํŠธ ํฌํ•จ)์œผ๋กœ ์ธํ•œ ์˜ˆ์™ธ ๋ฐœ์ƒ ์‹œ ํ•ด๋‹น ํŒŒ์ผ ๊ฒ€์‚ฌ๋งŒ ๊ฑด๋„ˆ๋›ฐ๊ณ  ๋‚˜๋จธ์ง€ ํŒŒ์ผ ๊ฒ€์‚ฌ๋Š” ๊ณ„์† ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค. (Fail Closed ๋ฐฉ์ง€)
}
}
}
}
} catch (e: Exception) {
// ๋ณด์•ˆ ํ–ฅ์ƒ: IO ์˜ˆ์™ธ๊ฐ€ ๋ฐœ์ƒํ•˜๋”๋ผ๋„ ์•ˆ์ „ํ•˜๊ฒŒ ๋ฌด์‹œํ•˜๊ณ  ๋‹ค์Œ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค (Fail Securely)
}

if ("index.html" !in files_to_exclude)
Expand Down
59 changes: 59 additions & 0 deletions src/test/kotlin/html4tree/UseLinesExceptionTest.kt
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
package html4tree

import org.junit.Test
import java.io.File
import kotlin.test.assertTrue
import kotlin.test.assertFalse
import java.nio.file.Files

class UseLinesExceptionTest {

@Test
fun testProcessIgnoreFileThrowsException() {
val tempDir = Files.createTempDirectory("ignore_test").toFile()
try {
val ignoreFile = File(tempDir, ".html4ignore")
ignoreFile.writeText("pattern1")

// badNames์— ์ •์ƒ์ ์ธ ์ด๋ฆ„๊ณผ ๋„ ๋ฐ”์ดํŠธ๊ฐ€ ํฌํ•จ๋œ ์ž˜๋ชป๋œ ์ด๋ฆ„์„ ๊ฐ™์ด ๋„ฃ์Šต๋‹ˆ๋‹ค.
val badNames = arrayOf("valid.txt", "bad\u0000name.txt")

val excluded = process_ignore_file(tempDir, badNames)
assertTrue(excluded.contains("index.html"))
assertTrue(excluded.contains(".git"))

} finally {
tempDir.deleteRecursively()
}
}

@Test
fun testProcessIgnoreFileOuterException() {
val tempDir = Files.createTempDirectory("ignore_test2").toFile()
try {
val ignoreFile = File(tempDir, ".html4ignore")
ignoreFile.writeText("pattern1")

var listCallCount = 0
val badDir = object : File(tempDir.absolutePath) {
override fun list(): Array<String>? {
listCallCount++
if (listCallCount == 1) {
// ์ฒซ ๋ฒˆ์งธ ํ˜ธ์ถœ(204์ค„, try ๋‚ด๋ถ€)์—์„œ ์˜ˆ์™ธ ๋ฐœ์ƒ
throw RuntimeException("Forced exception for outer try-catch coverage")
} else {
// ๋‘ ๋ฒˆ์งธ ํ˜ธ์ถœ(232์ค„, try ์™ธ๋ถ€)์—์„œ๋Š” ์ •์ƒ ๋ฐ˜ํ™˜
return arrayOf("somefile.txt")
}
}
}

val excluded = process_ignore_file(badDir, null)
assertTrue(excluded.contains("index.html"))
assertTrue(excluded.contains(".git"))

} finally {
tempDir.deleteRecursively()
}
}
}
Loading