๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Webhacking.kr

[Webhacking.kr] old-17 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2023. 8. 23.

๐Ÿ… old-17 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

1.  ๋ฌธ์ œ ํ™”๋ฉด์˜ ์ž…๋ ฅ๋ž€์— hello! ์ž…๋ ฅ ํ›„ check ํด๋ฆญ  -->  Wrong ์ด๋ผ๋Š” ๊ฒฝ๊ณ ์ฐฝ ์ถœ๋ ฅ

2.  F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ๋ˆŒ๋Ÿฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ

3.  Elements ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ ์ฝ”๋“œ ์—ด๋žŒ

<!DOCTYPE html>
<html>
<head>
<title>Challenge 17</title>
</head>
<body bgcolor="black">
<font color="red" size="10"></font>
<p> </p>
<form name="login"> <!-- ๋กœ๊ทธ์ธ ํผ ์‹œ์ž‘ -->
<input type="passwd" name="pw"> <!-- ํŒจ์Šค์›Œ๋“œ ์ž…๋ ฅ ํ•„๋“œ -->
<input type="button" onclick="sub()" value="check"> <!-- 'check' ๋ฒ„ํŠผ, ํด๋ฆญํ•˜๋ฉด sub() ํ•จ์ˆ˜ ํ˜ธ์ถœ -->
</form> <!-- ๋กœ๊ทธ์ธ ํผ ์ข…๋ฃŒ -->

<script> <!-- ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ ์ฝ”๋“œ ์‹œ์ž‘ -->
unlock = 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 1 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 + 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 - 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 + 9999999;
function sub() {
    if (login.pw.value == unlock) { // ์ž…๋ ฅํ•œ ํŒจ์Šค์›Œ๋“œ๊ฐ€ unlock ๊ฐ’๊ณผ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธ
        location.href = "?" + unlock / 10; // ์ผ์น˜ํ•  ๊ฒฝ์šฐ ํŽ˜์ด์ง€ ์ด๋™ (query string์— unlock ๊ฐ’์˜ 10๋ถ„์˜ 1 ์ถ”๊ฐ€)
    } else {
        alert("Wrong"); // ํŒจ์Šค์›Œ๋“œ๊ฐ€ ์ผ์น˜ํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ ๊ฒฝ๊ณ ์ฐฝ ํ‘œ์‹œ
    }
}
</script> <!-- ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ ์ฝ”๋“œ ์ข…๋ฃŒ -->

<whale-quicksearch translate="no"> <!-- ํ€ต์„œ์น˜ ์š”์†Œ -->
#shadow-root (closed) <!-- ์›๋ž˜์˜ DOM ํŠธ๋ฆฌ ๋‚ด๋ถ€์— ์ ‘๊ทผํ•˜๋Š” shadow DOM ํ‘œ์‹œ -->
<style></style>
<div class="quicksearch"></div>
</whale-quicksearch> <!-- ํ€ต์„œ์น˜ ์š”์†Œ ์ข…๋ฃŒ -->
</body>
</html>

 

 

++  unlock ๋ณ€์ˆ˜์— ๋“ค์–ด๊ฐ„ ๊ฐ’์„ ์ž…๋ ฅ๋ž€์— ๋„ฃ์œผ๋ฉด ๋˜๋Š” ๋“ฏ ํ•˜๋‹ค.

4.  Console ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ unlock ๋ณ€์ˆ˜๊ฐ’์„ ํ™•์ธ

console.log(unlock);

 

5.  Console ์—์„œ ์–ป์€ ๊ฐ’์„ ์ž…๋ ฅ ํ›„ check ๋ฒ„ํŠผ ํด๋ฆญ  -->  ๋ฌธ์ œ ํ•ด๊ฒฐ ์„ฑ๊ณต