๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Web Hacking52

[Dreamhack] ex-reg-ex ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿคธ‍โ™€๏ธ ex-reg-ex ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ์„ค๋ช… ํ™•์ธ ํ›„ ์„œ๋ฒ„ ์ƒ์„ฑ 2. ์ƒ์„ฑํ•œ ์„œ๋ฒ„๋กœ ์ ‘์†ํ•œ ๋’ค ์ž„์˜์˜ ๊ฐ’ ์ž…๋ ฅ --> Input ๊ฐ’์ด ๊ทธ๋Œ€๋กœ ์ถœ๋ ฅ๋จ์„ ํ™•์ธ 3. ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ํ›„ app.py ์˜คํ”ˆ #!/usr/bin/python3 from flask import Flask, request, render_template import re app = Flask(__name__) try: ใ…คใ…คFLAG = open("./flag.txt", "r").read() # flag is here! except: ใ…คใ…คFLAG = "[**FLAG**]" @app.route("/", methods = ["GET", "POST"]) def index(): ใ…คใ…คinput_val = "" ใ…คใ…คif re.. 2023. 11. 24.
[Webhacking.kr] old-53 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ”ญ old-53 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ 2023. 8. 31.
[Webhacking.kr] old-39 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿท old-39 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ 2023. 8. 30.
[The Python Challenge] Warming Up ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿช€ Warming Up ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ Hint ํƒ์ƒ‰ ++ URL ์ฃผ์†Œ ๋ณ€๊ฒฝ์„ ์‹œ๋„ํ•˜๋ผ๋Š” Hint ๊ฐ€ ๋ˆˆ์— ๋ˆ๋‹ค. 2. URL ์ˆ˜์ •์„ ์œ„ํ•ด, ํ˜„์žฌ URL ํ™•์ธ # ํ˜„์žฌ URL http://www.pythonchallenge.com/pc/def/0.html 3. ์ด๋ฏธ์ง€ ์† TV์— ์“ฐ์—ฌ์ง„ ์ˆซ์ž์— ์ฃผ๋ชฉํ•˜์—ฌ ์ •๋ฆฌํ•œ URL ์— ๊ฐ๊ฐ ์ ‘์†ํ•ด๋ณด๊ธฐ ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ์˜ ์ˆ˜ ๋ฐ˜์˜ URL 238 http://www.pythonchallenge.com/pc/def/238.html 2 ^ 28 http://www.pythonchallenge.com/pc/def/274877906944.html 2 x 38 http://www.pythonchallenge.com/pc/def/76.html 2 + 38 htt.. 2023. 8. 29.
[Webhacking.kr] old-01 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ‘  old-01 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ --------------------- 2023. 8. 28.
[Webhacking.kr] old-06 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿš‚ old-06 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ ++ ID์™€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๊ธฐ์กด ์ฝ”๋“œ์™€ ๋ฐ˜๋Œ€๋กœ Encode & Decode ํ•˜์—ฌ ์›๋ž˜์˜ ๊ฐ’์„ ๊ตฌํ•ด์•ผ ํ•จ 3. ๋ฌธ์ œ ํ•ด๊ฒฐ์„ ์œ„ํ•œ Python ์Šคํฌ๋ฆฝํŠธ ์ž‘์„ฑ import base64 # ๋ฌธ์ž ์น˜ํ™˜์„ ์—ญ์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๋Š” ํ•จ์ˆ˜ ์ •์˜ def reverse_replace(s): s = s.replace("1", "!") s = s.replace("2", "@") s = s.replace("3", "$") s = s.replace("4", "^") s = s.replace("5", "&") s = s.replace("6", "*") s = s.replace("7", "(") s = s.repl.. 2023. 8. 27.