๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Dreamhack

[Dreamhack] Command Injection - 1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2022. 10. 3.

4 - 0 - 1. Command Injection - 1 ํŒจํ‚ท ์ „์†ก ์‹ค์Šต

 

 

 

# Command Injection - 1 ํŒจํ‚ท ์ „์†ก ์‹ค์Šต

1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

 

 

 

2. ๋‹ค์šด๋ฐ›์€ ํŒŒ์ผ์„ ์—ด์–ด ์ฝ”๋“œ ๋ถ„์„ 

+ << Line 18 >>

: ping ๋ฒ„ํŠผ ํด๋ฆญ ์‹œ ํ•˜๋‹จ์˜ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•จ์„ ์•Œ๋ฆฌ๋Š” ์ฝ”๋“œ

 

+ << Line 19 >>

: ์‚ฌ์šฉ์ž๊ฐ€ ๋นˆ์นธ์— ๊ฐ’ ์ž…๋ ฅ ์‹œ  -->  ์‚ฌ์šฉ์ž ์ž…๋ ฅ๊ฐ’์ด ๋ณ€์ˆ˜ host์— ์ €์žฅ

 

+ << Line 20 >>

: ์œ„์˜ ๊ณผ์ • ์ง„ํ–‰์ด ๋๋‚˜๋ฉด cmd ๋ช…๋ น์–ด ์‹คํ–‰

: cmd = ๋ช…๋ น ํ”„๋กฌํฌํŠธ

 

+ << Line 22 >>

: ์‰˜๊ณผ bin์„ ํ†ตํ•ด ๋ฆฌ๋ˆ…์Šค์™€ ๊ด€๋ จ๋œ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•จ์„ ๊ณต์ง€ํ•˜๋Š” ์ฝ”๋“œ

 

 

++ ํŒŒ์•… ๊ฐ€๋Šฅํ•œ ์ •๋ณด

A) flag๋Š” flag.py ํŒŒ์ผ์— ์œ„์น˜

B) ํŒŒ์ผ ํ˜ธ์ถœ ๋ฆฌ๋ˆ…์Šค ๋ช…๋ น์–ด์ธ cat ์„ ์‚ฌ์šฉํ•˜์—ฌ flag.py ํŒŒ์ผ์„ ํ˜ธ์ถœํ•ด์•ผ ํ•จ

C) multi command ์„ธ๋ฏธ์ฝœ๋ก (;) ์‚ฌ์šฉํ•˜์—ฌ ๋ช…๋ น์–ด๋ฅผ ์ƒ์„ฑํ•ด์•ผ ํ•จ

 

 

 

3. ์•ˆ๋‚ด๋œ ์ ‘์† ์ •๋ณด ๋งํฌ์— ์ ‘์† ํ›„ ping ํŽ˜์ด์ง€๋กœ ์ด๋™

 

 

 

4. ping ํŽ˜์ด์ง€ ์ด๋™ ํ›„ ์ž…๋ ฅ๋ž€์— 8.8.8.8 ์ž…๋ ฅ

 

+ ํŒจํ‚ท์˜ ์ „์†ก ๋ฐ ์ˆ˜์‹  ์ƒํƒœ๋ฅผ ์ถœ๋ ฅํ•จ

 

 

 

5. F12 ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์‹คํ–‰  -->  Elements ํƒญ์˜ pattern ์ฝ”๋“œ ์‚ญ์ œ

 

 

 

6. ๋‹ค์‹œ ping ํŽ˜์ด์ง€๋กœ ๋Œ์•„์™€์„œ ์ž…๋ ฅ์นธ์— "8.8.8.8; cat flag.py" ์ž…๋ ฅ  -->  Flag๊ฐ€ ์ •์ƒ์ ์œผ๋กœ ์ถœ๋ ฅ๋˜๋Š” ๊ฒƒ์„ ํ™•์ธ

 

FLAG ๋Š” 'DH{pingpingppppppppping!!}'