본문 바로가기
WIKI 기술 지식 베이스

요청 경로

원문 보기 위키 갱신

요청 경로 (Request Path)

출처: Request Path

본문

Request Path

정제와 필터링을 통한 경로 기반 공격 방어

Traefik은 들어오는 요청 경로를 처리할 때 여러 보안 계층을 구현해요. 여기에는 위험한 시퀀스를 정규화하는 경로 정제(path sanitization)와 URL 인코딩을 사용하는 공격 벡터를 방지하는 인코딩 문자 필터링이 포함돼요. Traefik이 요청 경로를 어떻게 처리하는지 이해하는 것은 안전한 라우팅 인프라를 유지하는 데 중요해요.

Traefik이 요청 경로를 처리하는 방법

Traefik이 HTTP 요청을 받으면 여러 보안 중심 단계를 거쳐 요청 경로를 처리해요:

1. 인코딩 문자 필터링

Traefik은 경로에서 잠재적으로 위험한 인코딩 문자를 검사하고, 명시적으로 허용하지 않는 한 그런 문자를 포함한 요청을 거부해요.

기본적으로 허용되는 인코딩 문자 목록은 다음과 같아요:

| Encoded Character | Character | | %2f or %2F | / (slash) | | %5c or %5C | \ (backslash) | | %00 | NULL (null character) | | %3b or %3B | ; (semicolon) | | %25 | % (percent) | | %3f or %3F | ? (question mark) | | %23 | # (hash) |

2. 경로 정규화

Traefik은 예약되지 않은(unreserved) 퍼센트 인코딩 문자를 디코딩해서 요청 경로를 정규화해요. 이 문자들은 인코딩되지 않은 형태와 동등하기 때문이고(rfc3986#section-2.3 참고), 퍼센트 인코딩 문자를 대문자화하기 때문이에요(rfc3986#section-6.2.2.1 참고).

3. 경로 정제

Traefik은 URL에서 .., ., 그리고 중복 슬래시 세그먼트를 제거해 일반적인 공격 벡터를 방지하도록 요청 경로를 정제해요(rfc3986#section-6.2.2.3 참고).

경로 보안 구성

Traefik은 함께 작동해 애플리케이션을 보호하는 두 가지 주요 경로 보안 메커니즘을 제공해요.

경로 정제

경로 정제는 기본적으로 활성화되어 있고 요청 경로를 정규화해 디렉터리 탐색 공격을 방지하는 데 도움을 줘요. EntryPoints HTTP 섹션에서 구성하세요:

File (YAML)

entryPoints:
  websecure:
    address: ":443"
    http:
      sanitizePath: true  # Default: true (recommended)

File (TOML)

[entryPoints.websecure]
  address = ":443"

  [entryPoints.websecure.http]
    sanitizePath = true

CLI

--entryPoints.websecure.address=:443
--entryPoints.websecure.http.sanitizePath=true

정제 동작:

  • ./foo/bar → /foo/bar (상대 현재 디렉터리 제거)

  • /foo/../bar → /bar (부모 디렉터리 탐색 해석)

  • /foo/bar// → /foo/bar/ (중복 슬래시 제거)

  • /./foo/../bar// → /bar/ (모든 정규화 결합)

인코딩 문자 필터링

인코딩 문자 필터링은 잠재적으로 위험한 URL 인코딩 문자를 거부해 추가적인 보안 계층을 제공해요. EntryPoints HTTP 섹션에서 구성하세요.

이 필터링은 경로 정제 전에 수행되고, 인코딩을 사용해 다른 보안 통제를 우회하려는 공격 시도를 잡아내요.

모든 인코딩 문자 필터링은 기본적으로 비활성화되어 있어요 (true는 인코딩 문자가 허용된다는 뜻이에요).

보안 고려 사항

백엔드가 RFC 3986을 완전히 준수하지 않고 특히 요청 경로의 인코딩된 예약 문자를 디코딩한다면, split-view 상황을 피하고 경로 탐색 공격이나 보안 통제를 우회하려는 다른 악의적 시도를 막기 위해 이 옵션들을 false로 설정하는 게 권장돼요.

File (YAML)

entryPoints:
  websecure:
    address: ":443"
    http:
      encodedCharacters:
        allowEncodedSlash: false          # %2F - Default: true
        allowEncodedBackSlash: false      # %5C - Default: true
        allowEncodedNullCharacter: false  # %00 - Default: true
        allowEncodedSemicolon: false      # %3B - Default: true
        allowEncodedPercent: false        # %25 - Default: true
        allowEncodedQuestionMark: false   # %3F - Default: true
        allowEncodedHash: false           # %23 - Default: true

File (TOML)

[entryPoints.websecure]
  address = ":443"

  [entryPoints.websecure.http.encodedCharacters]
    allowEncodedSlash = false
    allowEncodedBackSlash = false
    allowEncodedNullCharacter = false
    allowEncodedSemicolon = false
    allowEncodedPercent = false
    allowEncodedQuestionMark = false
    allowEncodedHash = false

CLI

--entryPoints.websecure.address=:443
--entryPoints.websecure.http.encodedCharacters.allowEncodedSlash=false
--entryPoints.websecure.http.encodedCharacters.allowEncodedBackSlash=false
--entryPoints.websecure.http.encodedCharacters.allowEncodedNullCharacter=false
--entryPoints.websecure.http.encodedCharacters.allowEncodedSemicolon=false
--entryPoints.websecure.http.encodedCharacters.allowEncodedPercent=false
--entryPoints.websecure.http.encodedCharacters.allowEncodedQuestionMark=false
--entryPoints.websecure.http.encodedCharacters.allowEncodedHash=false

라우트별 인코딩 문자 필터링

인코딩 문자 필터링을 라우트별로 구성해야 한다면 EncodedCharacters 미들웨어를 사용할 수 있어요. 자세한 구현 지침과 구성 옵션은 EncodedCharacter 미들웨어 문서를 참고하세요.

더 알아보기