App Service FTP 전송 보호 점검

파일 전송에는 FTPS를 사용하고 필요 없는 FTP 접근은 끄세요.

설명

site_config.ftps_state = "AllAllowed"는 암호화되지 않은 FTP도 허용합니다. 실제로 평문 FTP를 사용하면 자격 증명과 파일 내용이 전송 중 노출될 수 있습니다. 파일 전송이 필요하면 FTPS로 제한하고, 사용하지 않는다면 FTP 기능을 끄는 것이 좋습니다.

잠재적 영향

평문 전송을 관찰하거나 변조할 수 있는 공격자가 게시 자격 증명과 배포 파일을 노릴 수 있습니다.

해결 방법

site_config.ftps_state를 FtpsOnly로 설정하거나 FTP가 필요 없으면 Disabled로 설정하세요. 클라이언트가 TLS와 서버 인증서를 검증하는지 확인하고, 게시 자격 증명을 제한·관리하세요. 다른 배포 경로를 사용한다면 그 경로의 인증과 전송 보호도 확인하세요.

예시

AzureRM 3.x의 기존 azurerm_app_service 예시입니다. 현재 Linux·Windows Web App에서도 해당 FTP 상태를 설정할 수 있습니다.

변경 전

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    ftps_state               = "AllAllowed"
  }
}

변경 후

hcl
resource "azurerm_app_service" "example" {
  name                = "example-app-service"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  app_service_plan_id = azurerm_app_service_plan.example.id

  site_config {
    dotnet_framework_version = "v4.0"
    scm_type                 = "LocalGit"
    ftps_state               = "FtpsOnly"
  }
}

변경 후에는 FTPS만 허용합니다. 이는 파일 전송 채널 설정이며 웹앱의 HTTPS 전용 설정이나 사용자 인증을 대신하지 않습니다.

참조