๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Webhacking.kr

[Webhacking.kr] old-26 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2023. 8. 21.

โ˜„๏ธ old-26 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

1.  ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ„ ํ›„ view-source ์„ ํƒํ•˜์—ฌ ์ฝ”๋“œ ์—ด๋žŒ

 

<?php
  include "../../config.php";
  if($_GET['view_source']) view_source();
?><html>
<head>
<title>Challenge 26</title>
<style type="text/css">
body { background:black; color:white; font-size:10pt; }    
a { color:lightgreen; }
</style>
</head>
<body>
<?php
  if(preg_match("/admin/",$_GET['id'])) { echo"no!"; exit(); }
  $_GET['id'] = urldecode($_GET['id']);
  if($_GET['id'] == "admin"){
    solve(26);
  }
?>
<br><br>
<a href=?view_source=1>view-source</a>
</body>
</html>

 

++  GET ๋ฐฉ์‹์œผ๋กœ ์ž…๋ ฅ๋ฐ›์€ id๊ฐ’์ด admin ์ด๋ผ๋ฉด, ๋ฌธ์ œ ํ•ด๊ฒฐ

2.  preg_match() ํ•จ์ˆ˜ ์šฐํšŒ๋ฅผ ์œ„ํ•ด, URL ์ธ์ฝ”๋”ฉ ํ‘œ์ค€์— ๋”ฐ๋ผ ์•„๋ž˜ ์ž‘์—… ์ˆ˜ํ–‰

Not - Encoded Encoded - Once Encoded - Twice
admin %61%64%6D%69%6E %2561%2564%256D%2569%256E

 

++  ์‚ฌ์šฉํ•œ URL ์ธ์ฝ”๋” & ๋””์ฝ”๋”

-->  https://heavenly-appear.tistory.com/176

 

[URL ์ธ์ฝ”๋”, ๋””์ฝ”๋”] url์ธ์ฝ”๋”ฉ, url๋””์ฝ”๋”ฉ - ๋ฐ”๋กœ ๋ณ€ํ™˜ํ•ด๋“œ๋ ค์š”!

Encoding Decoding ๋ณต์‚ฌ๋ฒ„ํŠผ์€ ํ˜„์žฌ ํฌ๋กฌ์—์„œ๋งŒ ์ง€์›๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์•ˆ๋…•ํ•˜์„ธ์š”. ๊ฐœ์ธ์ ์œผ๋กœ url์ธ์ฝ”๋”ฉ ๋ฐ url๋””์ฝ”๋”ฉ์„ ์ž์ฃผ ๋ณ€ํ™˜ํ•ด์„œ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ๋กœ ๊ธฐ๋ฐ˜์œผ๋กœ URL์ธ์ฝ”๋” ๋ฐ URL๋””์ฝ”๋”๋ฅผ ๋งŒ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. (

heavenly-appear.tistory.com

 

++  Encoding ์„ 1๋ฒˆ์ด ์•„๋‹Œ 2๋ฒˆ ํ•˜๋Š” ์ด์œ 

Encoding์„ 1๋ฒˆ ํ•œ ๊ฒฝ์šฐ Encoding์„ 2๋ฒˆ ํ•œ ๊ฒฝ์šฐ
๋ธŒ๋ผ์šฐ์ €๊ฐ€ %61%64%6D%69%6E ์œผ๋กœ ์ธ์ฝ”๋”ฉ
-->  PHP๊ฐ€ ๋‹ค์‹œ ๋””์ฝ”๋”ฉํ•˜์—ฌ admin์ด ๋จ
(ํ•จ์ˆ˜์— ์˜ํ•œ ํ•„ํ„ฐ๋ง O)
๋ธŒ๋ผ์šฐ์ €๊ฐ€ %2561%2564%256D%2569%256E ์œผ๋กœ ์ธ์ฝ”๋”ฉ
-->  PHP๊ฐ€ ๋””์ฝ”๋”ฉํ•ด๋„ %61%64%6D%69%6E
(ํ•จ์ˆ˜์— ์˜ํ•œ ํ•„ํ„ฐ๋ง X)

3.  ๋ฌธ์ œ ํ™”๋ฉด์˜ URL๋ž€์„ ์•„๋ž˜์™€ ๊ฐ™์ด ์ž…๋ ฅ ํ›„ Enter ํด๋ฆญ  -->  ๋ฌธ์ œ ํ•ด๊ฒฐ ์„ฑ๊ณต