๊ธ€ ์ž‘์„ฑ์ž: heogi

1. Web Server ?

Web Server๋Š” ๋‹จ์ˆœํžˆ ์ •์ ์ธ ํŽ˜์ด์ง€๋ฅผ ์„œ๋น„์Šคํ•˜๊ธฐ ์œ„ํ•œ ์„œ๋ฒ„์ด๋‹ค.

์ด๋ฏธ์ง€ ํŒŒ์ผ, ๋‹จ์ˆœ HTML ํŒŒ์ผ ๊ฐ™์€ ์ •์ ์ธ ํŒŒ์ผ๋“ค์€ Web Server๋ฅผ ํ†ตํ•ด์„œ ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•œ๋‹ค.

์˜ˆ) Apache Server, Nginx, IIS ๋“ฑ

 

2. WAS(Web Application Server)?

๋™์ ์ธ ํŽ˜์ด์ง€๋ฅผ ์ œ๊ณตํ•˜๊ธฐ ์œ„ํ•ด DB ์กฐํšŒ๋‚˜ ์„œ๋น„์Šค๋ฅผ ์œ„ํ•œ ๋กœ์ง์„ ์ˆ˜ํ–‰ํ•˜๋Š” ์„œ๋ฒ„์ด๋‹ค. ์ƒ๋Œ€์ ์œผ๋กœ ๋ถ€ํ•˜๊ฐ€ ๋งŽ์€ ์ž‘์—…๋“ค์ด ์ง„ํ–‰๋œ๋‹ค.

์˜ˆ) Tomcat, JBoss, Jeus ๋“ฑ

 

3. Web Server์™€ WAS๋ฅผ ๋”ฐ๋กœ ์“ฐ๋Š” ์ด์œ 

  1. ์„œ๋ฒ„ ๋ถ€ํ•˜ ๋ฐฉ์ง€ ์ •์ ์ธ ํŽ˜์ด์ง€์˜ ์š”์ฒญ์€ Web Server์—์„œ ์ฒ˜๋ฆฌํ•˜๋„๋ก ํ•˜์—ฌ WAS์˜ ๋ถ€ํ•˜๋ฅผ ๋ฐฉ์ง€ํ•œ๋‹ค.
  2. ๋ฌผ๋ฆฌ์ ์œผ๋กœ ๋ถ„๋ฆฌํ•˜์—ฌ ๋ณด์•ˆ ๊ฐ•ํ™” SSL์— ๋Œ€ํ•œ ์•”๋ณตํ˜ธํ™” ์ฒ˜๋ฆฌ์— Web Server๋ฅผ ์‚ฌ์šฉ WAS์˜ ์™ธ๋ถ€๋กœ์˜ ์ง์ ‘์ ์ธ ์š”์ฒญ์€ ์ฐจ๋‹จํ•จ์œผ๋กœ์จ ๋ณด์•ˆ ๊ฐ•ํ™”
  3. Scaling, Avalibility ๋ฌด์ค‘๋‹จ์œผ๋กœ Scale-In, Out ๋“ฑ์— ์œ ๋ฆฌํ•˜๋ฉฐ, ์—ฌ๋Ÿฌ๋Œ€์˜ WAS์ค‘ ํ•˜๋‚˜๊ฐ€ ์„œ๋น„์Šค๊ฐ€ ์ค‘๋‹จ๋˜๋”๋ผ๋„ Web Server์—์„œ ์ค‘๋‹จ๋œ WAS๋กœ์˜ ์ „๋‹ฌ์„ ๋ชป ํ•˜๋„๋ก ์„ค์ •ํ•˜์—ฌ ์žฅ์•  ์ฒ˜๋ฆฌ์— ์œ ๋ฆฌํ•˜๋‹ค.(์œ„ ๊ทธ๋ฆผ ์ฒ˜๋Ÿผ ๋กœ๋“œ๋ฐธ๋Ÿฐ์„œ๊ฐ€ ์žˆ์œผ๋ฉด ์˜๋ฏธ๊ฐ€ ์—†์ง€๋งŒ…)

'๐ŸŒWeb' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

Broken API Authorization  (0) 2023.08.13
AeroCTF - Localization is hard  (0) 2023.08.13
RCE via Server-Side Template Injection  (0) 2023.08.13
[KVE-2020-1616] ๊ทธ๋ˆ„๋ณด๋“œ ๋ฉ”์ธํ™”๋ฉด XSS ์ทจ์•ฝ์   (0) 2023.08.13
SSTI(Server Side Template Injection)  (0) 2022.01.29