# 설정 및 설치된 플러그인이 로그인 페이지에 노출됨

**URL:** https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541
**Category:** Support
**Created:** [11월 27, 2019, 1:25오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541 "2019-11-27T13:25:15Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![ahunter](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@ahunter](https://meta.discourse.org/u/ahunter)
#### Post date: [11월 27, 2019, 1:25오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/1 "2019-11-27T13:25:15Z")

</div>

안녕하세요,

저희 discourse 서버의 로그인 페이지에서 문제를 해결하려고 합니다. 현재 로그인 페이지에서 서버 설정 및 설치된 플러그인 정보가 노출되고 있습니다. 페이지 소스를 확인하거나 로그인 페이지를 검사하면 이 정보가 보입니다. 이 정보를 페이지에서 제거하거나 숨기는 방법은 무엇인가요?

노출된 플러그인 코드 예시:

```plaintext
<link href="[/stylesheets/poll_desktop_2_aaf730f938a1162e369c60cef250ac2b3bf97c05.css?__ws=discourse.bob.host](https://discourse.bob.host/stylesheets/poll_desktop_2_aaf730f938a1162e369c60cef250ac2b3bf97c05.css?__ws=discourse.bob.host)" media="all" rel="stylesheet" data-target="poll_desktop" data-theme-id="3"/>

```

노출된 설정 예시:

```plaintext
<div class="hidden" id="data-preloaded" data-preloaded="{&quot;site&quot;:&quot;{\&quot;periods\&quot;:[\&quot;all\&quot;,\&quot;yearly\&quot;,\&quot;quarterly\&quot;,\&quot;monthly\&quot;,\&quot;weekly\&quot;,\&quot;daily\&quot;],\&quot;filters\&quot;:[\&quot;latest\&quot;,\&quot;unread\&quot;,\&quot;new\&quot;,\&quot;read\&quot;,\&quot;posted\&quot;,\&quot;bookmarks\&quot;],\&quot;user_fields\&quot;:[],\&quot;auth_providers\&quot;:[]}&quot;,&quot;siteSettings&quot;:&quot;{\&quot;default_locale\&quot;:\&quot;en\&quot;,\&quot;title\&quot;:\&quot;bobDiscourse\&quot;,\&quot;short_site_description\&quot;:\&quot;bob Integration Discourse\&quot;,\&quot;contact_email\&quot;:\&quot;infrastructure@bob.com\&quot;,\&quot;contact_url\&quot;:\&quot;https://bob.com\&quot;,\&quot;logo\&quot;:\&quot;/uploads/default/original/1X/96eba37e4fb0f19f8f04e09ad31d1bf14111e122.png\&quot;,\&quot;logo_small\&quot;:\&quot;/uploads/default/original/1X/96eba37e4fb0f19f8f04e09ad31d1bf14111e122.png\&quot;,\&quot;digest_logo\&quot;:\&quot;\&quot;,\&quot;mobile_logo\&quot;:\&quot;\&quot;,\&quot;large_icon\&quot;:\&quot;/uploads/default/original/1X/96eba37e4fb0f19f8f04e09ad31d1bf14111e122.png\&quot;,\&quot;favicon\&quot;:\&quot;/uploads/default/original/1X/96eba37e4fb0f19f8f04e09ad31d1bf14111e122.png\&quot;,\&quot;apple_touch_icon\&quot;:\&quot;\&quot;,\&quot;allow_user_locale\&quot;:false,\&quot;support_mixed_text_direction\&quot;:false,\&quot;suggested_topics\&quot;:5,\&quot;ga_universal_tracking_code\&quot;:\&quot;\&quot;,\&quot;ga_universal_domain_name\&quot;:\&quot;auto\&quot;,\&quot;gtm_container_id\&quot;:\&quot;\&quot;,\&quot;top_menu\&quot;:\&quot;categories|latest|new|unread|top\&quot;,\&quot;post_menu\&quot;:\&quot;read|like|share|flag|edit|bookmark|delete|admin|reply\&quot;,\&quot;post_menu_hidden_items\&quot;:\&quot;flag|bookmark|edit|delete|admin\&quot;,\&quot;share_links\&quot;:\&quot;twitter|facebook|email\&quot;,\&quot;desktop_category_page_style\&quot;:\&quot;categories_with_featured_topics\&quot;,\&quot;category_colors\&quot;:\&quot;BF1E2E|F1592A|F7941D|9EB83B|3AB54A|12A89D|25AAE2|0E76BD|652D90|92278F|ED207B|8C6238|231F20|808281|B3B5B4|E45735\&quot;,\&quot;category_style\&quot;:\&quot;bullet\&quot;,\&quot;enable_mobile_theme\&quot;:true,\&quot;relative_date_duration\&quot;:30,\&quot;fixed_category_positions\&quot;:false,\&quot;fixed_category_positions_on_create\&quot;:false,\&quot;enable_badges\&quot;:true,\&quot;enable_badge_sql\&quot;:false,\&quot;enable_whispers\&quot;:false,\&quot;push_notifications_prompt\&quot;:true,\&quot;vapid_public_key_bytes\&quot;:\&quot;4|170|50|111|127|76|83|223|177|204|254|218|146|40|188|175|8|235|76|71|207|133|49|159|219|30|44|72|138|250|138|188|150|192|11|194|246|81|233|148|144|142|143|243|38|251|133|5|10|219|95|160|9|246|246|186|2|162|200|182|219|187|92|28|26\&quot;,\&quot;invite_only\&quot;:true,\&quot;login_required\&quot;:true,\&quot;must_approve_users\&quot;:false,\&quot;enable_local_logins\&quot;:true,\&quot;enable_local_logins_via_email\&quot;:true,\&quot;allow_new_registrations\&quot;:true,\&quot;enable_signup_cta\&quot;:true,\&quot;enable_sso\&quot;:false,\&quot;sso_overrides_email\&quot;:false,\&quot;sso_overrides_avatar\&quot;:false,\&quot;min_username_length\&quot;:3,\&quot;max_username_length\&quot;:20,\&quot;unicode_usernames\&quot;:false,\&quot;min_password_length\&quot;:10,

```

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [11월 27, 2019, 1:32오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/2 "2019-11-27T13:32:27Z")

</div>

이 모든 설정은 클라이언트에서 필요하며, 어쨌든 유추할 수 있으므로 사실상 비밀이 아닙니다.

이 부분에 대해 정확히 어떤 문제가 있으신가요?

---

<div class="post-metadata">

### Author: ![ahunter](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@ahunter](https://meta.discourse.org/u/ahunter)
#### Post date: [11월 27, 2019, 2:36오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/3 "2019-11-27T14:36:44Z")

</div>

Richard님, 감사합니다.

귀하의 답변을 판단컨대, 이는 표준 설정이며 위험성이 고려되어 문제가 되지 않는다고 판단된 것 같습니다.

저는 이것이 문제라고 생각한 이유는 다음과 같습니다.

적대자가 웹사이트와 그 잠재적 악용 방법에 대한 취약점을 탐색할 때, 가능한 한 많은 정보를 수집하는 것에서 시작합니다. 웹사이트 코드에 포함된 정보는 적대자가 거의 노력하지 않고도 무지한 상태에서 더 많은 정보를 얻을 수 있게 해줍니다.

예를 들어, 설정값은 보안 모델이 어떻게 구성되어 있는지에 대해 공격자에게 매우 명확한 지침을 제공하여 공격을 표적으로 삼을 수 있게 합니다. 최소 사용자 이름 길이, 최대 사용자 이름 길이, 최소 비밀번호 길이는 모두 공격 경로를 좁히는 데 유용합니다. SSO가 활성화되어 있습니까? 2FA가 활성화되어 있지 않습니까?

이 정보는 또한 잠재적으로 잘못 구성된 Discourse 서버를 온라인에서 찾는 데에도 유용합니다. Google Dork를 사용하여 잠재적으로 안전하지 않거나 쉽게 해킹될 수 있는 Discourse 서버를 찾을 수 있습니다.

---

<div class="post-metadata">

### Author: ![RGJ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/rgj/32/523185_2.png) [@RGJ](https://meta.discourse.org/u/RGJ)
#### Post date: [11월 27, 2019, 2:49오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/4 "2019-11-27T14:49:57Z")

</div>

> [@ahunter](#):
>
> 웹사이트 코드에 포함된 정보는 공격자가 거의 노력하지 않고도 무지 상태에서 더 많은 정보를 얻을 수 있게 합니다.

이 정보가 소스 코드에서 JSON 형식으로 제공되지 않았다면, 결국 이 정보를 추출하는 스크립트를 작성하는 데 약 1시간 정도가 걸렸을 것입니다. 결국 가입을 시도하면 폼 검증기를 통해 사용자 이름과 비밀번호의 길이와 같은 정보도 얻을 수 있기 때문입니다.

이러한 정보 중 어느 것도 잘못된 구성이나 비보안 설정에 대한 정보를 드러내지 않는다고 생각합니다.

---

<div class="post-metadata">

### Author: ![Remah](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/remah/32/70590_2.png) [@Remah](https://meta.discourse.org/u/Remah)
#### Post date: [11월 27, 2019, 4:04오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/5 "2019-11-27T16:04:50Z")

</div>

> [@ahunter](#):
>
> 설정 값들은 공격자가 보안 모델이 어떻게 설정되어 있는지에 대해 매우 명확한 정보를 제공합니다.

Discourse는 오픈 소스이며, 기본 설정은 이미 공개적으로 문서화되어 있습니다.

분명히 [해커 보상을 받을 만큼](https://hackerone.com/discourse)의 이점이 되지 않습니다.

---

<div class="post-metadata">

### Author: ![ahunter](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@ahunter](https://meta.discourse.org/u/ahunter)
#### Post date: [11월 27, 2019, 4:13오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/6 "2019-11-27T16:13:08Z")

</div>

원래 질문에서는 토론 사이트 로그인 페이지에 표시되는 정보의 양을 줄이고 싶었는데, 어떻게 해커 보너스 프로그램 이야기로 흘러간 건지 모르겠습니다. 제가 묻고 있는 것은 코드에 있는 취약점이 아닙니다. 단순히 로그인 페이지에 표시되는 정보가 내 기준으로는 너무 많다고 느껴져서, 이를 제거하는 방법을 찾고 싶었던 것입니다.

제발 주제에 맞춰 주세요.

---

<div class="post-metadata">

### Author: ![ahunter](https://avatars.discourse-cdn.com/v4/letter/a/7cd45c/32.png) [@ahunter](https://meta.discourse.org/u/ahunter)
#### Post date: [11월 27, 2019, 4:21오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/7 "2019-11-27T16:21:26Z")

</div>

Richard님,

이 문제에 대해 제 견해가 당신과 다릅니다. 하지만 그것은 제 의견이며, 다른 사람들이 다른 관점을 가질 수 있다는 점을 이해합니다. 잠재적인 위협, 즉 리스크가 될 수도 있고 아닐 수도 있는 사항들에 대해 논의하면서, 원래의 요청에서 다소 벗어난 것 같습니다.

이 정보의 가시성을 줄이는 방법이 있는지, 아니면 그것이 불가능한지 궁금합니다. 불가능하다면, 이 지원 요청을 종료하겠습니다.

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [11월 27, 2019, 8:00오후 UTC](https://meta.discourse.org/t/settings-and-plugins-installed-exposed-on-login-page/134541/8 "2019-11-27T20:00:45Z")

</div>


