
연구자를 위한 마크다운 템플릿을 보관하는 저장소
디렉터리 구조 참고 사항:
generate-directories.py 스크립트는 GitHub에서 VRT 구조의 현재 최신 버전을 가져와 누락된 디렉터리를 생성합니다. VRT에서 제거된 항목을 기준으로 디렉터리를 삭제하거나 이름을 바꾸지는 않습니다.
스크립트는 표준 항목 이름을 따르며 VRT id 필드가 제공하는 밑줄과 대소문자를 유지합니다.
이 저장소에는 'Protected Master'가 활성화되어 있습니다. 즉, 프로젝트 관리자만 Pull Request를 통해 master 브랜치에 커밋할 수 있습니다. 모든 업데이트는 무결성을 보장하기 위해 pull request를 통해서만 이루어져야 합니다.
다음 내용은 SSH 접속이 올바르게 구성되어 있다고 가정합니다.
먼저 master 브랜치를 체크아웃하세요:
git clone [email protected]:bugcrowd/templates.git ## n.b. using SSH aliases can make this much simpler
master 브랜치를 시스템에 받은 후에는 수행할 작업을 위한 브랜치를 생성해야 합니다:
git checkout -b <branch-name>
브랜치 이름 예시로는 XXE-templates, XSS-templates처럼 해당 작업 내용을 나타내는 이름이 좋습니다. 브랜치는 작게 유지해야 하며, 가급적 템플릿 묶음 정도를 넘지 않아야 합니다. 자주 커밋하고 푸시하세요!
git commit -am "Comments about what you changed go here" 명령은 변경 사항을 로컬 git 저장소에 저장합니다. 항상 설명이 포함된 커밋 메시지를 남기세요.
템플릿 작성이 끝나면 저장소에 푸시할 수 있습니다. 이때도 별도의 브랜치 상태이지만, 푸시하면 linter가 실행되어 일련의 규칙에 따라 마크다운을 검증합니다. 예시 템플릿을 따르고 크게 벗어나지 않았다면 템플릿은 통과할 것입니다.
git push --set-upstream origin <branch-name> 명령은 origin 서버(github)에 브랜치를 생성하고 변경 사항을 푸시합니다. 이 작업은 브랜치당 한 번만 수행하면 되며, 이후 브랜치 푸시는 git push로 수행할 수 있습니다.
linter가 성공적으로 실행되면 Pull Request(PR)를 생성할 수 있습니다.
GitHub 인터페이스에서 브랜치를 선택하세요. 코드 위에 'Pull request' 버튼이 표시될 것입니다.
해당 버튼을 선택한 다음, 프로젝트 관리자가 검토할 수 있도록 변경된 내용에 대한 세부 정보를 작성하고 'Create pull request'를 클릭하세요.
이제 완료입니다! 관리자가 PR을 검토하고 적절하다고 판단되면 병합하거나 거부합니다.
PR이 승인되면 브랜치를 삭제해도 됩니다.
git branch -d <branch-name>
아래는 예시 템플릿입니다. 모든 섹션은 올바른 정보를 포함하도록 업데이트해야 합니다.
## Overview of the Vulnerability
Provide a 1-2 sentence description of the vulnerability.
This format is a good guide:
[VULNTYPE] in [COMPONENT] in [APPLICATION] allows [ATTACKER] to [IMPACT] via [VECTOR]
## Business Impact
Provide an example of the impact to the business. This could be reputational damage, financial loss, a loss in customer trust, etc.
## Steps to Reproduce
Provide a step-by-step walkthrough on how to access the vulnerable injection point, and how to exploit the vulnerability.
Example:
1. Login to in-scope asset at <www.bugcrowd.com/login>
1. Browse to account page
1. Modify ID token to add single quote
1. View error which states 'SQL Syntax Error'
1. Replace ID value with `1' waitfor delay '00:00:10'; `
## Proof of Concept (PoC)
Your submission must include evidence of the vulnerability and not be theoretical in nature.
You may present your evidence as output from a tool, such as SQLMap, unless the program forbids the use of these tools. Evidence may also be in the format of terminal output, screenshots, or video.
Use this section to demonstrate clearly the effect of the vulnerability. However, do not access Personally Identifiable Information (PII).
이것은 예시 템플릿입니다:
# Reflected Cross-Site Scripting (Non-self)
## Overview of the Vulnerability
Reflected Cross-Site Scripting (XSS) is a type of injection attack where malicious JavaScript code is injected into a website. When a user visits the affected web page, the JavaScript code executes and its input is reflected in the user’s browser. Reflected XSS can be found on this domain which allows an attacker to create a crafted URL. When opened by a user, this URL will execute arbitrary Javascript within that user’s browser in the context of this domain.
When an attacker can control code that is executed within a user’s browser, they are able to carry out any actions that the user is able to perform, including accessing any of the user's data and modifying information within the user’s permissions. This can result in modification, deletion, or theft of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session.
## Business Impact
Reflected XSS could lead to data theft through the attacker’s ability to manipulate data through their access to the application, and their ability to interact with other users, including performing other malicious attacks, which would appear to originate from a legitimate user. These malicious actions could also result in reputational damage for the business through the impact to customers’ trust.
## Steps to Reproduce
1. Enable a HTTP interception proxy, such as Burp Suite or OWASP ZAP
1. Use a browser to navigate to: {{URL}}
1. Forward the following request to the endpoint:
```HTTP Request
{{request}}
```
1. Observe the JavaScript payload being executed
## Proof of Concept (PoC)
Below is a screenshot demonstrating the injected JavaScript executing at the vulnerable endpoint:
{{screenshot}}
가능하면 수동태를 사용하세요. 예를 들어:
올바른 예:
웹 애플리케이션에서 SQL 인젝션 취약점이 발견되었습니다.
잘못된 예:
저는 웹 애플리케이션에서 SQL 인젝션 취약점을 발견했습니다.
잘못된 예:
Bugcrowd는 웹 애플리케이션에서 SQL 인젝션 취약점을 발견했습니다.
잘못된 예:
우리는 웹 애플리케이션에서 SQL 인젝션을 발견했습니다.
잘못된 예:
전체 엔지니어링 과정 동안 백엔드 데이터베이스에서 개인 식별 정보를 탈취하는 데 공격자가 사용할 수 있는 심각도 높은 SQL 인젝션이 웹 애플리케이션(<www.example.com>)에서 발견되었습니다.
올바른 예:
개인 식별 정보를 탈취할 수 있는 악의적인 공격자를 허용하는 SQL 인젝션이 <www.example.com>에서 발견되었습니다.
잘못된 예:
개인 식별 정보(이메일 주소 포함)를 탈취할 수 있는 악의적인 공격자를 허용하는 SQL 인젝션이 <www.example.com>에서 발견되었으며, 이는 GDPR 위반으로 간주되고 상당한 비즈니스 위험을 초래합니다.
올바른 예:
개인 식별 정보를 탈취할 수 있는 악의적인 공격자를 허용하는 SQL 인젝션이 <www.example.com>에서 발견되었습니다. 검색 가능한 데이터에는 비밀번호, 이메일 주소, 성명이 포함됩니다. 이는 GDPR 위반 및 상당한 비즈니스 위험을 초래합니다.
약어를 사용할 때는 항상 먼저 전체 이름을 쓰고 괄호 안에 약어를 넣으세요. 전체 이름을 한 번 표기한 후에는 이후부터 약어만 사용할 수 있습니다.
예를 들어:
XSS(교차 사이트 스크립팅, Cross-Site Scripting)는 악의적인 공격자가 사용자의 브라우저에서 JavaScript를 실행할 수 있게 하는 클라이언트 측 공격입니다. XSS는 사용자 입력이 인코딩되지 않은 채 브라우저로 다시 반영될 때 발생합니다.
CSRF(교차 사이트 요청 위조, Cross-Site Request Forgery)가 example.com에서 발견되었습니다. 이 CSRF를 통해 피해 사용자가 알지 못하는 사이에 주소를 업데이트할 수 있습니다.
올바른 예: Bugcrowd 잘못된 예: BugCrowd, bugcrowd, Bug Crowd, Bug crowd, bug crowd.
올바른 예: pentest (문법상 필요하면 Pentest) 잘못된 예: pen test, PenTest, Pen Test
"An"은 다음 단어가 자음 소리로 시작할 때 사용해야 합니다. 그 외에는 "A"를 사용해야 합니다.
올바른 예:
잘못된 예:
사용되는 언어는 항상 감정적이지 않고 공정해야 합니다.
예시:
{{target}}: 프로그램 페이지에 나열된 범위 내 대상의 이름 (예: *.bugcrowd.com){{application}}: 대상 내 특정 애플리케이션 (예: Acme Inc. Employee Portal){{type}}: 프로그램 페이지의 대상 옆에 나열된 수행 테스트 유형 (예: 웹사이트 테스트, API 테스트, 모바일 애플리케이션 테스트, 하드웨어 테스트 등){{url}}: URL용 자리 표시자 (예: https://bugcrowd.com/vulnerability-rating-taxonomy){{version}}: 테스트한 소프트웨어의 특정 버전 번호 (예: 13.3.7){{program}}: 프로그램 이름 (예: Bugcrowd){{screenshot}}: 개념 증명이 실행된 모습을 보여주는 사진 또는 동영상 증거.{{action}}: 공격자가 이를 악용할 경우 수행할 수 있는 행동 (예: 세션 토큰 탈취, 관리자 계정 완전 제어, PII 덤프 등){{parameter}}: 클라이언트에서 서버로 데이터를 전송하는 변수로, 내부에 다양한 유형의 데이터를 저장할 수 있습니다. 처리 방식은 서버 측 코드에 의해 결정됩니다. (예: id=1337){{hardware}}: IoT 또는 자동차 자산을 공격하는 데 사용되는 특정 하드웨어{{software}}: 자산을 공격하는 데 사용되는 특정 소프트웨어 (예: burp, nessus, nikto 등){{payload}}: 자산에서 실행되는 명령 또는 페이로드{{value}}: 특정 측정값 (초, 밀리초, 주파수 등)이 저장소에는 bugcrowd_templates 젬이 포함되어 있습니다. 이 젬은 VRT 선택에 따라 제출 설명 및 방법론 노트용 templates를 가져오는 데 사용됩니다. Bugcrowd Engineering에서 사용 및 유지 관리합니다.
Gemfile에 다음 줄을 추가하세요:
gem 'bugcrowd_templates'
개발 편의를 위해 젬을 사용해 볼 수 있는 플레이그라운드를 시작하는 유틸리티를 제공합니다. 다음 명령으로 호출할 수 있습니다:
bin/console
아래는 제출 설명 및 방법론 노트 필드에서 templates를 가져오기 위해 BugcrowdTemplates를 호출하는 예시입니다.
BugcrowdTemplates.get(
type: 'any_value', # type can be submissions or methodologies
field: 'any_value', # field name of the type
category: 'any_value', # any category name from VRT option
subcategory: 'any_value', # any subcategory name from VRT option
item: 'any_value', # any item name from VRT option
file_name: 'any_value' # file_name can be 'template' or 'guidance'
)
아래는 제출 설명 필드에서 template을 가져오기 위해 BugcrowdTemplates를 호출하는 예시입니다.
BugcrowdTemplates.get(
type: 'submissions',
field: 'description', # field name of the submissions
category: 'server_security_misconfiguration', # category name from VRT option
subcategory: 'clickjacking', # subcategory name from VRT option
item: 'non_sensitive_action', # item name from VRT option
file_name: 'template' # template
)
=> '# Clickjacking on a non-sensitive action\n\n## Overview\n\n' # template fetched from templates path
guidance 템플릿을 가져오는 예시:
BugcrowdTemplates.get(
type: 'submissions',
field: 'description',
category: 'using_components_with_known_vulnerabilities',
subcategory: 'outdated_software_version',
file_name: 'guidance'
)
아래는 방법론 노트 필드에서 templates를 가져오기 위해 BugcrowdTemplates를 호출하는 예시입니다.
BugcrowdTemplates.get(
type: 'methodology',
field: 'notes', # field name of the methodologies
category: 'website_testing',
file_name: 'information'
)
=> '# Information gathering and Reconnaisance\n\n##' # template fetched from templates path