๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Dreamhack

[Dreamhack] sql injection bypass WAF ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2022. 11. 24.

# sql injection bypass WAF ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

 

1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

 

 

 

 

2. ๋ฌธ์ œ ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ํ™•์ธ

app.py

+ << Line 31 ~ 32 >>

: uid ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์ด์šฉํ•ด ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ ๊ฐ’์„ ์ž…๋ ฅ๋ฐ›์Œ 

 

+ << Line 34 ~ 45 >>

: ์‚ฌ์šฉ์ž ์ž…๋ ฅ๊ฐ’์„ check_WAF ํ•จ์ˆ˜์˜ ์ธ์ž๋กœ ์ „๋‹ฌํ•œ ํ›„ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์ด ํŠน์ • ํ‚ค์›Œ๋“œ๋ฅผ ํฌํ•จํ•˜๋Š”์ง€ ์—ฌ๋ถ€ ์กฐ์‚ฌ 

: ํ‚ค์›Œ๋“œ ๊ฒ€์‚ฌ ํ›„ ์ฟผ๋ฆฌ์— ์ž…๋ ฅ๊ฐ’ ์‚ฝ์ž…  -->  SQL Injection ์ทจ์•ฝ์  ๋ฐœ์ƒ

 

 

 

init.sql

+ << Line 4 ~ 9 >>

: user ํ…Œ์ด๋ธ”์ด users ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์กด์žฌ  -->  ํ…Œ์ด๋ธ” ๋‚ด๋ถ€์— idx, upw, uid ์นผ๋Ÿผ์ด ์กด์žฌํ•จ

 

+ << Line 11 ~ 16 >>

: admin, guest, test, dream ๋“ฑ์˜ ๊ณ„์ •์ด ์กด์žฌํ•จ

 

 

 

 

3. ์ ‘์† ๋งํฌ ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์†

 

 

 

 

 

4. ์‚ฌ์šฉ์ž ์ž…๋ ฅ๋ž€์— hello ์ž…๋ ฅ ํ›„ submit ๋ฒ„ํŠผ ํด๋ฆญ

 

+ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์ด ๊ทธ๋Œ€๋กœ WHERE๋ฌธ์— ๋“ค์–ด๊ฐ์„ ํ™•์ธ

 

 

 

 

5. ์‚ฌ์šฉ์ž ์ž…๋ ฅ๋ž€์— admin 1' ์ž…๋ ฅ ํ›„ submit ๋ฒ„ํŠผ ํด๋ฆญ

 

+ ์š”์ฒญ์ด WAF( = ์›น ๋ฐฉํ™”๋ฒฝ)์— ์˜ํ•ด ๋ง‰ํž˜

 

++ WAF(Web Application Firewall = ์›น ๋ฐฉํ™”๋ฒฝ)์ด๋ž€?

: ์›น์„ ํ†ตํ•ด ์ด๋ค„์ง€๋Š” ์™ธ๋ถ€ ๊ณต๊ฒฉ์ด๋‚˜ ์นจ์ž…(XSS, SQL injection ๋“ฑ)์„ ํƒ์ง€ํ•˜๊ณ , ๊ทธ์— ๋Œ€์‘ํ•˜๋Š” ์—ญํ• ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ์— ํŠนํ™”๋œ ์†”๋ฃจ์…˜

 

 

 

 

6. admin ๊ณ„์ •์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ž๋ฆฌ์ˆ˜๋ฅผ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•œ ์ฟผ๋ฆฌ๋ฌธ ์ž‘์„ฑ

+ '||(length(upw))like(5)#' ๋ฅผ ์‚ฌ์šฉ์ž ์ž…๋ ฅ๋ž€์— ์ž…๋ ฅํ•˜๋ฉด ๋น„๋ฐ€๋ฒˆํ˜ธ์˜ ์ž๋ฆฌ์ˆ˜๊ฐ€ 5์ธ ๊ณ„์ •๋ช…์ด ์ถœ๋ ฅ๋œ๋‹ค.

 

 

 

+ '||(length(upw))like(44)#' ์„ ์ž…๋ ฅํ–ˆ์„ ๋•Œ admin์ด ์ถœ๋ ฅ๋œ ๊ฒƒ์„ ๋ณด์•„ admin์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ž๋ฆฌ์ˆ˜๋Š” 44์ž„์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

 

 

 

 

7. ์•Œ์•„๋‚ธ ์ •๋ณด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ WAF์™€ ํ‚ค์›Œ๋“œ ๊ฒ€์‚ฌ๋ฅผ ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•œ ์ฟผ๋ฆฌ๋ฌธ์„ ์ž‘์„ฑ ํ›„ ์‹คํ–‰

 

+ Flag๊ฐ€ ์„ฑ๊ณต์ ์œผ๋กœ ์ถœ๋ ฅ๋จ์„ ํ™•์ธ