๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Web Hacking/Webhacking.kr

[Webhacking.kr] old-01 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

by A Lim Han 2023. 8. 28.

๐Ÿ‘  old-01 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด

1.  ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ

2.  ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰

<?php
  // "../../config.php" ํŒŒ์ผ์„ ํฌํ•จํ•˜์—ฌ ํ•ด๋‹น ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ํ˜„์žฌ ํŒŒ์ผ๋กœ ๊ฐ€์ ธ์˜ด
  include "../../config.php";

  // URL ๋งค๊ฐœ๋ณ€์ˆ˜ 'view-source'๊ฐ€ 1๋กœ ์„ค์ •๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ, view_source() ํ•จ์ˆ˜ ํ˜ธ์ถœ
  if($_GET['view-source'] == 1){ view_source(); }

  // 'user_lv' ์ฟ ํ‚ค๊ฐ€ ์„ค์ •๋˜์–ด ์žˆ์ง€ ์•Š์€ ๊ฒฝ์šฐ
  if(!$_COOKIE['user_lv']){
    // "user_lv"๋ผ๋Š” ์ด๋ฆ„์˜ ์ฟ ํ‚ค๋ฅผ ์ƒ์„ฑํ•˜๊ณ , ๊ฐ’์€ "1"๋กœ ์„ค์ •. ์œ ํšจ๊ธฐ๊ฐ„์€ ํ˜„์žฌ ์‹œ๊ฐ„์—์„œ 30์ผ ํ›„๋กœ ์„ค์ •.
    SetCookie("user_lv","1",time()+86400*30,"/challenge/web-01/");
    
    // ํŽ˜์ด์ง€๋ฅผ ์ƒˆ๋กœ ๊ณ ์นจํ•˜์—ฌ ์ฟ ํ‚ค๊ฐ€ ์ ์šฉ๋˜๋„๋ก ํ•จ
    echo("<meta http-equiv=refresh content=0>");
  }
?>
<html>
<head>
<title>Challenge 1</title>
</head>
<body bgcolor=black>
<center>
<br><br><br><br><br>
<font color=white>
---------------------<br>

<?php
  // 'user_lv' ์ฟ ํ‚ค๊ฐ€ ์ˆซ์ž๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ, ๊ฐ’์„ 1๋กœ ์„ค์ •
  if(!is_numeric($_COOKIE['user_lv'])) $_COOKIE['user_lv']=1;

  // 'user_lv' ์ฟ ํ‚ค๊ฐ€ 4 ์ด์ƒ์ธ ๊ฒฝ์šฐ, ๊ฐ’์„ 1๋กœ ์„ค์ • (์ˆœํ™˜๋˜๋„๋ก ํ•จ)
  if($_COOKIE['user_lv']>=4) $_COOKIE['user_lv']=1;

  // 'user_lv' ์ฟ ํ‚ค๊ฐ€ 3๋ณด๋‹ค ํฐ ๊ฒฝ์šฐ, solve(1) ํ•จ์ˆ˜ ํ˜ธ์ถœ
  if($_COOKIE['user_lv']>3) solve(1);

  // 'user_lv' ์ฟ ํ‚ค์˜ ๊ฐ’์„ ์ถœ๋ ฅ
  echo "<br>level : {$_COOKIE['user_lv']}";
?>

<br>
<!-- 'view-source' ๋งค๊ฐœ๋ณ€์ˆ˜๊ฐ€ 1๋กœ ์„ค์ •๋˜์–ด ์žˆ๋Š” ๋งํฌ ์ œ๊ณต -->
<a href=./?view-source=1>view-source</a>
</body>
</html>

 

++  Cookie ๊ฐ’์ด ๋ฌด์กฐ๊ฑด 1๋กœ ๊ณ ์ •๋˜๋Š” ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•ด์•ผ ํ•จ

3.  ๋ฌธ์ œ ํ•ด๊ฒฐ์„ ์œ„ํ•ด F12๋ฅผ ๋ˆŒ๋Ÿฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ

4.  Application ํƒญ์˜ Cookies ๋กœ ์ด๋™  -->   https://webhacking.kr ํด๋ฆญ

5.  1๋กœ ์„ค์ •๋˜์–ด์žˆ๋Š” user_lv ๋ฅผ ์ง€์šฐ๊ณ , ์•„๋ž˜์™€ ๊ฐ™์€ ํ˜•ํƒœ์˜ ์‹ค์ˆ˜ ์ž…๋ ฅ

 

 

++  ์ˆ˜ ์ž…๋ ฅ ์‹œ ์ค€์ˆ˜ ์‚ฌํ•ญ

โ“ ์ •์ˆ˜๊ฐ€ ์•„๋‹Œ ์‹ค์ˆ˜ ํ˜•ํƒœ๋กœ ์ž…๋ ฅ
โ“‘  3๋ณด๋‹ค ํฐ ์‹ค์ˆ˜์—ฌ์•ผ ํ•จ
โ“’ 4๋ณด๋‹ค๋Š” ์ž‘์€ ์‹ค์ˆ˜์—ฌ์•ผ ํ•จ

6.  ๊ฐ’ ๋ณ€๊ฒฝ ํ›„ ํŽ˜์ด์ง€ ์ƒˆ๋กœ๊ณ ์นจ  -->  ๋ฌธ์ œ ํ•ด๊ฒฐ ์„ฑ๊ณต