๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Web Hacking/Dreamhack41

[Dreamhack] Login-1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 7 - 0 - 1. Login-1 ์Šคํฌ๋ฆฝํŠธ ๊ณต๊ฒฉ ์‹ค์Šต # Login-1 ์Šคํฌ๋ฆฝํŠธ ๊ณต๊ฒฉ ์‹ค์Šต 1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. app.py ํŒŒ์ผ์„ ์—ด๊ณ  ์ฝ”๋“œ ๋ถ„์„ + > : admin ๊ณ„์ •์˜ ๊ถŒํ•œ์€ 1, guest ๊ณ„์ •์˜ ๊ถŒํ•œ์ด 0์œผ๋กœ ์„ค์ •๋˜๋ฉฐ, 5ํšŒ ์ด์ƒ ๋น„๋ฐ€๋ฒˆํ˜ธ์— ์ž˜๋ชป๋œ ๊ฐ’์„ ์ž…๋ ฅํ•œ๋‹ค๋ฉด ๋” ์ด์ƒ ์‹œ๋„ํ•  ์ˆ˜ ์—†์Œ + > : ์‚ฌ์šฉ์ž๊ฐ€ ์ƒˆ๋กœ์šด ๊ณ„์ •์„ ์ƒ์„ฑํ•  ๋•Œ ๊ฐ ๊ณ„์ •๋งˆ๋‹ค ๋ถ€์—ฌ๋˜๋Š” BackupCode๋Š” 1๊ณผ 100 ์‚ฌ์ด์˜ ์ •์ˆ˜์ž„ + > : ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ userid, password, name์„ ์ž…๋ ฅ๋ฐ›์•„ ์ƒˆ๋กœ์šด ๊ณ„์ •์„ ์ƒ์„ฑ + > : ๋งŒ์ผ ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ userid๊ฐ€ ๊ธฐ์กด์— ์กด์žฌํ•˜๋˜ id์™€ ๋™์ผํ•˜๋‹ค๋ฉด 'Already Exists userid.' ๊ฒฝ๊ณ ๋ฌธ์„ ์ถœ๋ ฅ + > : ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ id, ๋ณ€.. 2022. 11. 14.
[Dreamhack] Session ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 6 - 1 - 2. Session ์ธ์ฆ ์ƒํƒœ ์กฐ์ž‘ ์‹ค์Šต # Session ์ธ์ฆ ์ƒํƒœ ์กฐ์ž‘ ์‹ค์Šต 1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ + > : ๋ฌธ์ œ ์ƒ ์กด์žฌํ•˜๋Š” ํŽ˜์ด์ง€์— ์ด 3๊ฐœ์˜ ๊ณ„์ •(admin, guest, user1234) ์กด์žฌ + > : ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€์˜ ๊ฒฝ์šฐ ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ username, password ๊ฐ’์„ POST ๋ฐฉ์‹์œผ๋กœ ์ž…๋ ฅ๋ฐ›๊ณ , ์ด๋ฅผ ๋ณ€์ˆ˜ pw์— ์ €์žฅ + > : 4๋ฐ”์ดํŠธ์˜ ๊ฐ’์„ os.urandom().hex() ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜์—ฌ hex๋กœ ํ˜•๋ณ€ํ™˜ --> ๋ณ€ํ™˜ํ•œ ๊ฐ’์„ session_id ๋ณ€์ˆ˜์— ์ €์žฅ + > : os.urandom().hex() ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜์—ฌ 16์ง„์ˆ˜๋กœ ๊ตฌ์„ฑ๋œ 2๊ฐœ์˜ ๋‚œ์ˆ˜๊ฐ’์„ session_storage ์— ์ €์žฅํ•จ์œผ๋กœ์จ admin ๊ณ„์ •.. 2022. 11. 10.
[Dreamhack] Simple-SSTI ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 6 - 1 - 1. Simple - SSTI ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด # Simple - SSTI ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ - SSTI(Server Side Template Injection) ์ทจ์•ฝ์ ์ด๋ž€? : ๊ณต๊ฒฉ์ž์— ์˜ํ•ด ์‚ฝ์ž…๋œ ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๊ฐ€ ์„œ๋ฒ„ ์ธก์—์„œ ์‹คํ–‰๋˜๋ฉฐ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์  + ์•…์„ฑ ํŽ˜์ด๋กœ๋“œ๋ฅผ ์‚ฝ์ž…ํ•˜๋Š” ๊ณผ์ •์—์„œ ์„œ๋ฒ„์˜ ๊ธฐ์กด ๊ธฐ๋ณธ ํ…œํ”Œ๋ฆฟ ๊ตฌ๋ฌธ์ด ์ด์šฉ๋  ์ˆ˜ ์žˆ์Œ - ํ…œํ”Œ๋ฆฟ ๋ฐ ํ…œํ”Œ๋ฆฟ ์–ธ์–ด๋ž€? : ํŠน์ • ์–ธ์–ด์˜ ๋ณ€์ˆ˜, ๋ฌธ๋ฒ•์„ html ์•ˆ์—์„œ๋„ ์‚ฌ์šฉ์ด ๊ฐ€๋Šฅํ•˜๋„๋ก ๋•๋Š” ์–ธ์–ด ex) flask์˜ jinja2, django์˜ python๊ณผ html 2. ์ ‘์† ์ •๋ณด ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† 3. 404Error, robots.txt ํŽ˜์ด์ง€๋กœ ๊ฐ๊ฐ ์ ‘์† 4. ์ƒ๋‹จ url์˜ ๊ฒฝ๋กœ์—.. 2022. 11. 10.
[Dreamhack] php-1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 6 - 0 - 2. php - 1 ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด # php - 1 ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ + LFI(=Local File Inclusion) ์ทจ์•ฝ์ ์ด๋ž€? : ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ ์ž…๋ ฅ๋ฐ›์€ ๊ฐ’์ด๋‚˜ ์š”์†Œ๋ฅผ '๊ฒฝ๋กœ'์— ์ถ”๊ฐ€ํ•˜๋Š” ๊ณผ์ •์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์œผ๋กœ, ์ฃผ๋กœ php๋กœ ๋งŒ๋“ค์–ด์ง„ ์›น์‚ฌ์ดํŠธ๊ฐ€ ํŠน์ • ํ•จ์ˆ˜(include,require,fopen)๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ ๋ฐœ์ƒํ•œ๋‹ค. --> ์„œ๋ฒ„ ์•ˆ์— ์กด์žฌํ•˜๋Š” ํŒŒ์ผ์— ์ ‘๊ทผํ•˜๋Š” ๋ฐฉ์‹์„ ํ†ตํ•ด ๊ณต๊ฒฉ ๊ฐ€๋Šฅ 2. ๋ฌธ์ œ ํŒŒ์ผ(index.php, list.php, main.php, view.php) ๋ถ„์„ + > : include ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜์—ฌ GET ๋ฐฉ์‹์œผ๋กœ ๋ณ€์ˆ˜ page์— php๋ช…์„ ์ž…๋ ฅ๋ฐ›๊ณ , ์ด์— ๋Œ€ํ•œ main.php๋ฅผ ํ˜ธ์ถœ + > : ๋ณ€์ˆ˜ file์— ๊ฒฝ๋กœ๋ฅผ.. 2022. 11. 8.
[Dreamhack] Proxy-1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 6 - 0 - 1. Proxy-1 ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด # Proxy-1 ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ + Raw Socket์ด๋ž€? : ๋ณดํ†ต์˜ ์ธํ„ฐ๋„ท ํ†ต์‹ ์€ TCP/IP์˜ 4๊ณ„์ธต์— ๋”ฐ๋ฅธ ๋‹จ๊ณ„๋ณ„๋กœ ํฌ๋งทํŒ… ๋ฐ ์ „์†ก๋˜๋Š” ๊ณผ์ •์„ ๊ฑฐ์น˜๋Š”๋ฐ, ํ”„๋กœํ† ์ฝœ์šฉ ์ „์†ก ๊ณ„์ธต ํฌ๋งทํŒ… ๊ณผ์ • ์—†์ด ์ธํ„ฐ๋„ท์˜ ํ”„๋กœํ† ์ฝœ ํŒจํ‚ท์„ ์ง์ ‘ ์ฃผ๊ณ  ๋ฐ›๋Š” ๊ฒƒ์„ ๋•๋Š” ์†Œ์ผ“. --> ์œ„ ์†Œ์ผ“์„ ํ†ตํ•ด ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜(= Application) ๋‹จ๊ณ„์—์„œ ํ†ต์‹  ๋ฐ์ดํ„ฐ๋ฅผ ์กฐ์ž‘ํ•  ์ˆ˜ ์žˆ๋‹ค. 2. ์ ‘์† ๋งํฌ ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† 3. Raw Socket Sender (Done)์„ ํด๋ฆญ ํ›„ host, port, Data ์— ๊ฐ๊ฐ 8000.0.0.1, 80, flags ์ž…๋ ฅ + ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•จ์„ ํ™•์ธ ๊ฐ€๋Šฅ 4. ๋‹ค์šด๋ฐ›์€ ๋ฌธ์ œ ํŒŒ์ผ ap.. 2022. 11. 7.
[Dreamhack] Blind - Command ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 5 - 1 - 2. Blind - Command ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด # Blind - Command ๋“œ๋ฆผํ•ต ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ์˜ app.py ํŒŒ์ผ ์ฝ”๋“œ ๋ถ„์„ + > : ์‚ฌ์šฉํ•œ ๋ฉ”์†Œ๋“œ๊ฐ€ GET ๋ฉ”์†Œ๋“œ๊ฐ€ ์•„๋‹ ๊ฒฝ์šฐ cmd ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ์ „๋‹ฌ๋œ ๊ฐ’์„ ์‹œ์Šคํ…œ ๋ช…๋ น์–ด๋กœ ์‹คํ–‰ --> HEAD๋‚˜ OPTIONS ๋ฉ”์†Œ๋“œ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•ด์•ผ ํ•จ 3. ์ ‘์† ๋งํฌ ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ URL๋กœ ์ ‘์† 4. ์ƒ๋‹จ์˜ url์„ ?cmd=[cmd] ํ˜•์‹์— ๋งž์ถ”์–ด ์กฐ์ž‘ ์‹œ๋„ + ์ž…๋ ฅํ•œ ๊ฐ’(=wow)์„ ๊ทธ๋Œ€๋กœ ์ถœ๋ ฅํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธ 5. ๋“œ๋ฆผํ•ต ํˆด ์‚ฌ์ดํŠธ(https://tools.dreamhack.games/requestbin/vmgkpnu) ์— ์ ‘์†ํ•˜์—ฌ Request Bin ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•˜์—ฌ fla.. 2022. 11. 3.