Tomcat 9 ์„ค์น˜

[ํ™˜๊ฒฝ] Windows 10 JDK 1.8.0 Tomcat 9 ๋ฒ„์ „์„ ์„ค์น˜ํ•˜๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค. - ๋‹ค์šด๋กœ๋“œ ๋งํฌ ์ ‘์† (tomcat.apache.org/) - ๋ฒ„์ „ ์„ ํƒ Download -> Tomcat 9 -> Core ํ•ญ๋ชฉ์—์„œ 32bit/64bit ๋ฅผ ์„ ํƒํ•˜์—ฌ ๋‹ค์šด๋กœ๋“œ ํ•ฉ๋‹ˆ๋‹ค. - ์„ค์น˜ ์ง„ํ–‰ shutdown port์™€ connector port๋Š” ๋‹ค๋ฅธ ํฌํŠธ์™€ ์ค‘๋ณต๋˜์ง€ ์•Š๊ฒŒ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ํ†ฐ์บฃ ๊ด€๋ฆฌ์ž ๊ณ„์ •์€ ๊ด€๋ฆฌํ•˜๊ณ ์ž ํ•˜๋Š” ๊ณ„์ • ์ •๋ณด๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. JRE๊ฐ€ ์„ค์น˜๋œ ํด๋”๋กœ ์ž๋™ ์ž…๋ ฅ๋ผ ์žˆ์œผ๋‚˜, java ์„ค์น˜๊ฐ€ ๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๋นˆ ๊ณต๋ž€์œผ๋กœ ๋‚˜์˜ฌ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์‚ฌ์ „์— ์„ค์น˜ํ•˜์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค. ํ†ฐ์บฃ์ด ์„ค์น˜๋  ๊ฒฝ๋กœ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. 'Run Apache Tomcat' ์ฒดํฌ ํ›„ Finish ํด๋ฆญ ์‹œ ์ž๋™์œผ๋กœ ํ†ฐ์บฃ ์„œ๋น„์Šค๊ฐ€ ์‹คํ–‰๋ฉ..

[ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…] ORA-00942: table or view does not exist

[ํ˜„์ƒ] Caused by: java.sql.SQLException: ORA-00942: table or view does not exist [์›์ธ] ์‚ฌ์šฉ์ž๊ฐ€ 'USER' ํ…Œ์ด๋ธ”์— ์žˆ๋Š” ๋‚ด์šฉ์„ ์›น์„œ๋ฒ„์— ์กฐํšŒ ์š”์ฒญ์„ ํ–ˆ๋Š”๋ฐ, 'USER' ํ…Œ์ด๋ธ”์ด ์กด์žฌํ•˜์ง€ ์•Š์•„ Exception ๋ฐœ์ƒ. ํ•ด๋‹น ํ…Œ์ด๋ธ”๋ช…์€ ์˜ˆ์‹œ๋กœ 'USER'๋กœ ๋ช…ํ•จ. ์›น์„œ๋ฒ„ ๋กœ๊ทธ๋ฅผ ํ™•์ธํ•˜์—ฌ ์–ด๋Š ํด๋ž˜์Šค์—์„œ ์–ด๋Š DB๋ฅผ ์กฐํšŒํ•˜๋‹ค ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ–ˆ๋Š”์ง€๋Š” ๋””๋ฒ„๊น…์„ ํƒœ์šฐ๋ฉฐ ํ™•์ธ ํ•„์š”. ๋˜๋Š” ์›น์„œ๋ฒ„ ๋กœ๊ทธ์— StackTrace ๋ชฉ๋ก์„ ํ™•์ธํ•ด๋ณด๋ฉด ๊ฐ€์žฅ ์ตœ์‹  ํด๋ž˜์Šค์—์„œ ์–ด๋Š ๋ผ์ธ์—์„œ Exception ๋ฐœ์ƒํ–ˆ๋Š”์ง€ ํ™•์ธ ๊ฐ€๋Šฅ. [์กฐ์น˜] 'USER' ํ…Œ์ด๋ธ” ์ƒ์„ฑ์œผ๋กœ ์กฐ์น˜. create table USER( USERID varchar(255) NOT NULL, USER..

[ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…] No suitable driver

[ํ˜„์ƒ] ์‚ฌ๋‚ด SVN์—์„œ ์›น ํ”„๋กœ์ ํŠธ๋ฅผ ์ฒดํฌ์•„์›ƒ ํ•œ ๋’ค ํ†ฐ์บฃ์„ ์ด์šฉํ•ด ๊ธฐ๋™์„ ํ•˜์ž ์•„๋ž˜์™€ ๊ฐ™์€ ์—๋Ÿฌ ๋ฐœ์ƒ. Caused by: java.sql.SQLException: No suitable driver [์กฐ์น˜] Exception ๋ฐœ์ƒํ•˜๋Š” ํ˜„์ƒ์€ ์—ฌ๋Ÿฌ ์ƒํ™ฉ์ด ์žˆ์–ด์„œ ์•„๋ž˜ ํ•ด๊ฒฐ๋ฐฉ๋ฒ•์œผ๋กœ ๋˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ์„ ์ˆ˜ ์žˆ์Œ. ํ™˜๊ฒฝ์„ค์ • ํŒŒ์ผ์— jdbc ์ •๋ณด ์ค‘ log4jdbc ๋ฌธ์ž์—ด ์‚ญ์ œ. (๋‹น์žฅ ์“ธ๋ชจ์—†์–ด์„œ log4jdbc๋Š” ์‚ญ์ œ) ๋ณ€๊ฒฝ ์ „ jdbc:log4jdbc:oracle:thin:@127.0.0.1:1521:orcl ๋ณ€๊ฒฝ ํ›„ jdbc:oracle:thin:@127.0.0.1:1521:orcl

[ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…] ORA-00923: FROM keyword not found where expected

[ํ˜„์ƒ] ์•„๋ž˜ ์—๋Ÿฌ๋‚ด์šฉ๊ณผ ๊ฐ™์ด FROM ํ‚ค์›Œ๋“œ๋ฅผ ์ฐพ์„ ์ˆ˜ ์—†๋‹ค๊ณ  ํ•œ๋‹ค. Caused by: java.sql.SQLException: ORA-00923: FROM keyword not found where expected [ํ˜„์ƒ ๋ฐœ์ƒ ์ด์œ ] ์›นํ”„๋กœ์ ํŠธ๋ฅผ ๊ธฐ๋™ ์‹œ JDBC ์ •๋ณด๋ฅผ ๋ณด๊ณ  validation ์ฒดํฌ๋ฅผ ํ•˜๊ฒŒ๋˜๋Š”๋ฐ ์˜คํƒ€ ๋˜๋Š” ๊ฐ DB์— ๋งž์ง€์•Š๋Š” ์ฟผ๋ฆฌ ํ˜•์‹์ด ์ž…๋ ฅ๋œ ๊ฒฝ์šฐ ๋ฐœ์ƒํ•จ. [์กฐ์น˜] Mysql์˜ ๊ฒฝ์šฐ SELECT 1 .... Oracle์˜ ๊ฒฝ์šฐ SELECT 1 FROM DUAL .... Oracle์€ Validation ์ฟผ๋ฆฌ ์ˆ˜ํ–‰ ์‹œ ํ…Œ์ด๋ธ”์„ ์ด์šฉํ•ด ์ฒดํฌ๋ฅผ ํ•˜๊ฒŒ๋œ๋‹ค. ๋‹น์—ฐํžˆ ํ…Œ์ด๋ธ” ๋ช…์„ ์ ์–ด์ค˜์•ผ ํ•˜๋Š”๋ฐ Oracle์—์„œ๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ์ œ๊ณตํ•˜๋Š” ํ…Œ์ด๋ธ”์ด ์กด์žฌํ•ด DUAL์ด๋ผ๋Š” ํ…Œ์ด๋ธ”์„ ์‚ฌ์šฉํ•œ๋‹ค. DUAL..

[webhacking.kr] 5๋ฒˆ ๋ฌธ์ œ

(ํ•™์Šต ๋ชฉ์ ์œผ๋กœ ์ž‘์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ž˜๋ชป๋œ ๋ถ€๋ถ„์ด ์žˆ๋‹ค๋ฉด ์ง€์ ํ•ด์ฃผ์„ธ์š”.) 5๋ฒˆ ๋ฌธ์ œ๋กœ ๋“ค์–ด๊ฐ€ ๋ณด์ž. ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ™”๋ฉด์ด ๋ณด์ธ๋‹ค. ๋กœ๊ทธ์ธ ๋ถ€๋ถ„๊ณผ ํšŒ์›๊ฐ€์ž… ๋ถ€๋ถ„์œผ๋กœ ๋ถ„๋ฅ˜๋˜์–ด์žˆ๋‹ค. ๋จผ์ € ๋กœ๊ทธ์ธ์„ ํด๋ฆญํ•˜์—ฌ ๋“ค์–ด๊ฐ€๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. id๋ถ€๋ถ„๊ณผ pw๋ถ€๋ถ„์— admin/admin์œผ๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„๋ฅผ ํ•ด ๋ณด์•˜๋‹ค. ํŒจ์Šค์›Œ๋“œ๊ฐ€ ๋งž์ง€ ์•Š๋‹ค๋Š” ์ถœ๋ ฅ๊ฒฐ๊ณผ๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. id๋Š” ๋งž์œผ๋‚˜, ํŒจ์Šค์›Œ๋“œ๊ฐ€ ํ‹€๋ฆฐ ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. id๊ฐ€ ์‹ค์ œ๋กœ admin์ธ์ง€ ํ…Œ์ŠคํŠธํ•˜๊ธฐ ์œ„ํ•ด admin2/admin์œผ๋กœ ์ ‘์† ์‹œ๋„ํ•ด ๋ณด์•˜๋‹ค. id๊ฐ€ ํ‹€๋ ธ๋‹ค๋Š” ๋ฌธ๊ตฌ๊ฐ€ ์ถœ๋ ฅ๋จ์œผ๋กœ์จ id๋Š” admin์ด๋‹ค. ํŒจ์Šค์›Œ๋“œ๋Š” ํ˜„์žฌ ๋ชจ๋ฅด๋Š” ์ƒํ™ฉ์ด๋‹ˆ, ํšŒ์›๊ฐ€์ž…์„ ํŽ˜์ด์ง€์— ์ ‘์†ํ•ด๋ณด์ž. join ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ๋ณด์ž. ์ ‘๊ทผ์ด ํ—ˆ๊ฐ€๋˜์ง€ ์•Š์•˜๋‹ค๊ณ  ํ•œ๋‹ค. ์†Œ์Šค๋ณด๊ธฐ๋ฅผ ํ†ตํ•ด ํ™•์ธํ•ด๋ณธ ๊ฒฐ..

[webhacking.kr] 4๋ฒˆ ๋ฌธ์ œ

(ํ•™์Šต ๋ชฉ์ ์œผ๋กœ ์ž‘์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ž˜๋ชป๋œ ๋ถ€๋ถ„์ด ์žˆ๋‹ค๋ฉด ์ง€์ ํ•ด์ฃผ์„ธ์š”.) 4๋ฒˆ ๋ฌธ์ œ๋กœ ๋“ค์–ด๊ฐ€ ๋ณด์ž. ์‹ฌํ”Œํ•œ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์ดˆ๋ก์ƒ‰์˜ ๋ฌธ์ž์—ด์€ ๋”ฑ ๋ด๋„ base64๋กœ ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž์—ด์ฒ˜๋Ÿผ ๋ณด์ธ๋‹ค. ๋ฌธ์ž์—ด์„ base64๋กœ ๋Œ๋ ค๋ณด๊ธฐ ์ „์— ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋จผ์ € ํ™•์ธํ•ด ๋ณด์ž. ๋”ฑํžˆ ๋ณผ ๊ฒƒ๋„ ์—†๊ณ  ํžŒํŠธ๊ฐ€ ๋  ๋งŒํ•œ๊ฒƒ๋„ ์—†๋‹ค. ๋ฉ”์ธ ํ™”๋ฉด์œผ๋กœ ๊ฐ€์„œ ํŒจ์Šค์›Œ๋“œ์— guest๋‚˜ admin์„ ์ž…๋ ฅํ•ด๋ณด์ž. ์•„๋ฌด๋Ÿฐ ๋ฐ˜์‘๋„ ์—†๋‹ค. Sql Injection ๊ณต๊ฒฉ๋„ ์‹œ๋„ํ•ด๋ดค๋Š”๋ฐ ๋˜‘๊ฐ™์ด ์•„๋ฌด ๋ฐ˜์‘์ด ์—†๋‹ค. ๊ทธ๋Ÿผ ์ด์ œ base64๋กœ ์ธ์ฝ”๋”ฉ๊ฒƒ ๊ฐ™์€ ๋ฌธ์ž์—ด์„ ๋””์ฝ”๋”ฉ ํ•ด๋ณด์ž. ( http://ostermiller.org/calc/encode.html ) ๋””์ฝ”๋”ฉ ๊ฒฐ๊ณผ ์ด๋ ‡๊ฒŒ ์ˆœ์กฐ๋กญ๊ฒŒ ๋ณ€๊ฒฝ๋˜์—ˆ๋‹ค. ํ•˜์ง€๋งŒ ์•„์ง ์‚ฌ๋žŒ์ด ์•Œ์•„๋ณผ ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ž์—ด๋„ ์•„๋‹ˆ๊ณ , ๋‹ต ๊ฐ™์ง€๋„..

servlet-context.xml ์—๋Ÿฌ

servlet-context.xml์— ์—๋Ÿฌ๊ฐ€ ๋–ด์„ ๋•Œ, ์—๋Ÿฌ ๋‚ด์šฉ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. ์—๋Ÿฌ ๋‚ด์šฉ Attribute : class The fully qualified name of the bean's class, except if it serves only as a parent definition for child bean definitions. Data Type : string ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• 1. Build Path์—์„œ ojdbc6.jar / ojdbc14.jar๋ฅผ import ํ•ด์ค€๋‹ค. 2. Project - Clean pom.xml์˜ oracle์€ com.oracle ojdbc6 11.2.0.3 compile ojdbc6์ด๋ฏ€๋กœ ojdbc6.jar๋ฅผ import ํ•ด์คฌ๋‹ค.

[webhacking.kr] 3๋ฒˆ ๋ฌธ์ œ

(ํ•™์Šต ๋ชฉ์ ์œผ๋กœ ์ž‘์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ž˜๋ชป๋œ ๋ถ€๋ถ„์ด ์žˆ๋‹ค๋ฉด ์ง€์ ํ•ด์ฃผ์„ธ์š”.) 2๋ฒˆ ๋ฌธ์ œ๋ฅผ ๋“ค์–ด๊ฐ€ ๋ณด์ž. ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋„ค๋ชจ๋„ค๋ชจ ๋กœ์ง์ด ๋‚˜์˜จ๋‹ค. ๋„ค๋ชจ๋„ค๋ชจ ๋กœ์ง์€ ์‰ฝ๊ธฐ ๋•Œ๋ฌธ์— ๊ธˆ๋ฐฉ ํ’€์—ˆ๋‹ค. ๋กœ์ง์„ ํ’€๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋œ๋‹ค. 'gogo'๋ฅผ ํด๋ฆญํ•ด๋ณด๋‹ˆ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ํ™”๋ฉด์ด ์ถœ๋ ฅ๋œ๋‹ค. ๋จผ์ € ์†Œ์Šค๋ฅผ ํ™•์ธํ•ด ๋ณด์•˜๋‹ค. ํผ ์•ˆ์— input์˜ ํƒ€์ž…์€ ํžˆ๋“ ์œผ๋กœ ๋˜์–ด์žˆ๊ณ  value๊ฐ€ 2์ง„์ˆ˜ ํ˜•ํƒœ๋กœ ์ •ํ•ด์ ธ์žˆ๋‹ค. ์ฒ˜์Œ์— ์ € 2์ง„์ˆ˜๊ฐ€ ํ”Œ๋ž˜๊ทธ์ธ์ค„ ์•Œ๊ณ  ์ œ์ถœํ•ด๋ดค๋”๋‹ˆ ์‹คํŒจํ–ˆ๋‹ค. ๋‹ค์‹œ ๋’ค๋กœ๊ฐ€์„œ, input ํ…์ŠคํŠธ์ฐฝ์— ์›ํ•˜๋Š” ๋ฌธ์ž์—ด์„ ์ž…๋ ฅํ•˜๊ณ  write ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ๋ณด์•˜๋‹ค. ํ•„์ž๋Š” ์ž์‹ ์˜ ID๋ฅผ ๋„ฃ์–ด๋ณด์•˜๊ณ , admin๋„ ๋„ฃ์–ด๋ณด์•˜๋‹ค. answer ๊ฐ’์€ ๋™์ผํ•˜๊ฒŒ ์ถœ๋ ฅ๋˜์—ˆ๋‹ค. ์ข€์ „์— ์†Œ์Šค๋ณด๊ธฐ๋ฅผ ํ†ตํ•ด ๋ณด์•˜๋˜ hidden ๊ฐ’์˜ value ๊ฐ’์ด ์ •ํ•ด์ ธ์žˆ์—ˆ๊ธฐ ๋•Œ๋ฌธ์—..