๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Dreamhack

[Dreamhack] funjs ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2022. 11. 15.

7 - 0 - 2. funjs ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

 

 

# funjs ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

 

 

 

 

2. index.html ํŽ˜์ด์ง€๋กœ ์ ‘์† ํ›„ ์ž…๋ ฅ๋ž€์— hello ์ž…๋ ฅ

+ ์œ„ ํ˜•์‹์ด ๋นˆ ํŽ˜์ด์ง€ ๋‚ด์—์„œ ์œ„์น˜๋ฅผ ๋ฐ”๊ฟ”๊ฐ€๋ฉฐ ์ถœ๋ ฅ๋จ์„ ํ™•์ธ

 

+ ์ž˜๋ชป๋œ ๊ฐ’์„ ์ž…๋ ฅํ•˜๋ฉด 'NOP!'์ด ์ถœ๋ ฅ๋จ

 

 

 

 

3. F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ํ†ตํ•ด ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ 

+ << Line 63 ~ 65 >>

: _0x374fd6(0x17c) (=length)์˜ ๊ฐ’์ด 0x24( = 10์ง„์ˆ˜ ํ‘œ๊ธฐ๋กœ๋Š” 36 )์ด ์•„๋‹ ๊ฒฝ์šฐ  -->  ํ•จ์ˆ˜ ๋ฆฌํ„ด

 

+ << Line 67 >>  

: ์ž‘์„ฑ๋œ for๋ฌธ์€ 0 ~ Flag์˜ ์ „์ฒด ๊ธธ์ด -1 ๊นŒ์ง€ ๋ฐ˜๋ณต

 

+ << Line 68 ~ 69 >>

: 'input ๋ฌธ์ž์—ด์˜ index๊ฐ’ = operator ๊ฐ’'์ธ ๊ฒฝ์šฐ์— 'NOP!'(=_0x374fd6(0x185)) ์ถœ๋ ฅ

 

 

 

 

4. main ํ•จ์ˆ˜ ์ฝ”๋“œ๋ฅผ Console ํƒญ์— ๋กœ๋”ฉํ•œ ํ›„ ์‹คํ–‰

 

 

 

 

5. for๋ฌธ์„ ํฌํ•จํ•œ ์ฝ”๋“œ๋ฅผ ์•„๋ž˜์™€ ๊ฐ™์ด ์ž‘์„ฑํ•œ ํ›„ Console ํƒญ์—์„œ ์‹คํ–‰

var flagcode=""
for (var i=0;i<36;i++)
    {
        flagcode+=String.fromCharCode(operator[i % operator[_0x374fd6(0x17c)]](_0x4949[i],_0x42931[i]))
    }

+ ์œ„ ์ฝ”๋“œ์˜ for๋ฌธ์€ input, operator์˜ ๊ฐ’์„ ๋™์ผํ•˜๊ฒŒ ๋งŒ๋“œ๋Š” ์—ญํ•  ์ˆ˜ํ–‰

 

Flag๊ฐ€ ์„ฑ๊ณต์ ์œผ๋กœ ์ถœ๋ ฅ๋จ์„ ํ™•์ธ

 

 

 

 

+ ๋ฌธ์ œ ํ’€์ด ์ฐธ๊ณ 

https://mokpo.tistory.com/153

https://not4dog.tistory.com/32