๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Webhacking.kr

[Webhacking.kr] old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2023. 8. 26.

๐Ÿ›ผ old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

1.  ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ

2.  ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰

<?php
  include "../../config.php";
  if($_GET['view_source']) view_source();
?><html>
<head>
<title>Challenge 11</title>
<style type="text/css">
body { background:black; color:white; font-size:10pt; }
</style>
</head>
<body>
<center>
<br><br>
<?php
  $pat="/[1-3][a-f]{5}_.*$_SERVER[REMOTE_ADDR].*\tp\ta\ts\ts/";
  if(preg_match($pat,$_GET['val'])){
    solve(11);
  }
  else echo("<h2>Wrong</h2>");
  echo("<br><br>");
?>
<a href=./?view_source=1>view-source</a>
</center>
</body>
</html>

 

++  Line 15์˜ ์ •๊ทœํ‘œํ˜„์‹ ์ •์˜์— ์ฃผ๋ชฉ

$pat="/[1-3][a-f]{5}_.*$_SERVER[REMOTE_ADDR].*\tp\ta\ts\ts/";

 

์ฝ”๋“œ ์˜๋ฏธ
[1-3] 1๋ถ€ํ„ฐ 3 ์‚ฌ์ด์˜ ์ˆซ์ž๋กœ ์‹œ์ž‘
[a-f]{5} ์•ŒํŒŒ๋ฒณ a๋ถ€ํ„ฐ f๊นŒ์ง€์˜ ๋ฌธ์ž ์ค‘
๋™์ผํ•œ 5๊ฐœ๊ฐ€ ์—ฐ์†์œผ๋กœ ์œ„์น˜
.*$_SERVER[REMOTE_ADDR].* ์‚ฌ์šฉ์ž์˜ IP ์ฃผ์†Œ ํฌํ•จ
\tp\ta\ts\ts ํƒญ ๋ฌธ์ž๋กœ ๊ตฌ๋ถ„๋˜๋Š” "ptass" ๋ฌธ์ž์—ด ํฌํ•จ

 

-->  ์œ„ 4๊ฐœ์˜ ์กฐ๊ฑด์„ ๋งŒ์กฑํ•œ ๋ฌธ์ž์—ด์„ $_GET['val'] ์— ์ „๋‹ฌํ•ด์•ผ ํ•จ

3.  ์œ„์˜ ์กฐ๊ฑด์— ์œ ์˜ํ•˜๋ฉฐ ๋ฌธ์ž์—ด ์ž‘์„ฑ

val = 2bbbbb_{๋ณธ์ธ์˜ IP ์ฃผ์†Œ}*%09p%09a%09s%09s

++  IP ์ฃผ์†Œ ํ™•์ธ์€ ์–ด๋–ป๊ฒŒ ํ•˜์ง€?

-->  https://ip.pe.kr/

 

๋‚ด ์•„์ดํ”ผ ํ™•์ธ (My ip address) - ip.pe.kr

211.231.103.94 ๋‹น์‹ ์˜ ๊ณต์ธ ์•„์ดํ”ผ ์ฃผ์†Œ๋Š” ์œ„์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์ ‘์†ํ•˜์‹  ๊ตญ๊ฐ€๋Š” ๋Œ€ํ•œ๋ฏผ๊ตญ (KR) ์ž…๋‹ˆ๋‹ค. ์ž์„ธํžˆ ์•Œ์•„๋ณด๊ธฐ ์„œ๋ฒ„๋ฅผ ์ด์ „ ํ–ˆ์Šต๋‹ˆ๋‹ค! NEW -->

ip.pe.kr


++  URL ํ‘œ์ค€์œผ๋กœ Encode & Decode

-->  http://www.hipenpal.com/tool/url_encode_and_decode_in_korean.php

 

URL ์ธ์ฝ”๋”/๋””์ฝ”๋” - Hi!Penpal!

๋ฌธ์ž์—ด์„ Base64 ๋ฐฉ์‹์œผ๋กœ ์ธ์ฝ”๋”ฉ ๋˜๋Š” ๋””์ฝ”๋”ฉํ•ด์ค๋‹ˆ๋‹ค.

www.hipenpal.com

4.  ์ž‘์„ฑํ•œ ๋ฌธ์ž์—ด ๋งํฌ๋กœ ๋‹ค์‹œ ์ ‘์†  -->  ๋ฌธ์ œ ํ•ด๊ฒฐ ์„ฑ๊ณต

https://webhacking.kr/challenge/code-2/?val=2bbbbb_{์ ‘์†ํ•œ IP}*%09p%09a%09s%09s