09 POSTS

Security 1

  • #nodejs#security#javascript

    Node.js vm ๋ชจ๋“ˆ์˜ ํ•จ์ •: ์ƒŒ๋“œ๋ฐ•์Šค๊ฐ€ ์•„๋‹Œ ์ด์œ 

    ์ง‘ํ•„ ์ค‘์ธ Node.js Deep Dive์˜ 5.2์žฅ(vm ๋ชจ๋“ˆ์˜ ํ•จ์ •) ์ผ๋ถ€๋ฅผ ๋ฏธ๋ฆฌ ๊ณต๊ฐœํ•ฉ๋‹ˆ๋‹ค.

    25๋ถ„
  • #security#nextjs#react

    React ์ทจ์•ฝ์ ์ธ๋ฐ ์™œ Next.js๋ฅผ ์—…๊ทธ๋ ˆ์ด๋“œํ•ด์•ผ ํ•˜์ง€?

    CVE-2025-55182, CVE-2025-55184, CVE-2025-55183 ๊ทธ๋ฆฌ๊ณ  Next.js์˜ ์ˆจ๊ฒจ์ง„ React

    30๋ถ„
  • #nodejs#security

    colors.js์™€ faker.js ์‚ฌํƒœ๊ฐ€ ์ค€ ๊ตํ›ˆ

    ๋‹ค์ด๋‚˜๋ฏนํ•˜๊ฒŒ ์‹œ์ž‘ํ•˜๋Š” 2022๋…„

    10๋ถ„
  • #javascript#security

    ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ์—์„œ ์•ˆ์ „ํ•˜๊ฒŒ ๋‚œ์ˆ˜ ์ƒ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•

    Math.random()๋„ ์ž˜๋ชป ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋”๋Ÿฌ ์žˆ์Œ

    7๋ถ„
  • #security#authentication

    JWT์˜ ๋‹จ์ ๊ณผ ์ฃผ์˜์‚ฌํ•ญ

    ๊ณต๋ถ€ํ• ๊ฒŒ ์ •๋ง ๋งŽ์Šต๋‹ˆ๋‹น 222

    10๋ถ„
  • #web-performance#browser#security

    ํŒŒํ‹ฐ์…”๋‹ ์บ์‹œ (partitioning cache)

    Google Font ๋ฅผ ์จ๋„ ์ด์ œ ์บ์‹œ ํšจ๊ณผ๋Š” ๋ชป๋ฐ›๊ฒ ๋„ค์š”

    8๋ถ„
  • #security#web-performance

    Referer์™€ Referer-Policy๋ฅผ ์œ„ํ•œ ๊ฐ€์ด๋“œ

    ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ request๋ฅผ ๋ฐ›๊ธฐ ์œ„ํ•œ ์ตœ์ ์˜ Referer์™€ Referrer ์ •์ฑ…

    14๋ถ„
  • #nodejs#security

    Nodejs์—์„œ์˜ ์•”/๋ณตํ˜ธํ™”

    ### Nodejs์—์„œ์˜ ์•”ํ˜ธํ™”์™€ ๋ณตํ˜ธํ™” ๋งŒ์•ฝ ๊ฐ™์€ ํ…์ŠคํŠธ๋กœ ์•”ํ˜ธํ™”๋ฅผ ๋™์ผํ•˜๊ฒŒ ์‹œ๋„ํ–ˆ์„ ๋•Œ, ์•”ํ˜ธํ™”๋œ ๊ฒฐ๊ณผ๊ฐ€ ๋™์ผํ•˜๊ฒŒ ๋‚˜์˜จ๋‹ค๋ฉด ์ด ์•”ํ˜ธํ™”๋Š” ๊ต‰์žฅํžˆ ์•ฝํ•œ ์•”ํ˜ธํ™”๋ผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ๊ฐ•๋ ฅํ•œ ์•”ํ˜ธํ™”๋Š” ๋งค๋ฒˆ ์•”ํ˜ธํ™”๋ฅผ ์‹œ๋„ํ•  ๋•Œ๋งˆ๋‹ค (์„ค๋ น ๊ฐ™์€ ํ…์ŠคํŠธ๋ผ ํ• ์ง€๋ผ๋„) ๋‹ค๋ฅธ ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์™€์•ผ ํ•œ๋‹ค. ๋ฌผ๋ก , ์–ด์จŒ๋“  ์•”ํ˜ธํ™” ๋˜์–ด ์žˆ๋‹ค๋Š” ์‚ฌ์‹ค ๋งŒ์œผ๋กœ๋„ ๋งŒ์กฑํ•  ์ˆ˜๋„ ์žˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ...

    3๋ถ„
  • #security#browser#backend

    Chrome Samesite ์ฟ ํ‚ค ์ •์ฑ…

    # ๋ฌธ์ œ์˜ ์‹œ์ž‘ ์ง€๋‚œ ์ฃผ๋ง, ์—„์ฒญ๋‚˜๊ฒŒ ๊ธ‰ํ•˜๊ฒŒ ๋น ๋ฅธ ์†๋„๋กœ ํ”„๋กœ์ ํŠธ๋ฅผ heroku์— ์˜ฌ๋ฆด ์ผ์ด ์žˆ์—ˆ๋‹ค. DB๋„ ์ƒˆ๋กœ๋งŒ๋“ค์–ด์•ผํ•˜๊ณ , ๋กœ๊ทธ์ธ๋„ ํ•„์š”ํ•œ ์‚ฌ์ดํŠธ๋ผ DB๋Š” Heroku์˜ Clean DB๋ฅผ, ๋กœ๊ทธ์ธ์€ [google sign-in for websites](https://developers.google.com/identity/sign-in/web)์„ ์‚ฌ์šฉํ•˜...

    9๋ถ„