๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Web Hacking/Dreamhack41

[Dreamhack] Web - SSRF ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 5 - 1 - 1. Web - SSRF ์ทจ์•ฝ์  ์‹ค์Šต # Web - SSRF 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ ์† app.py ํŒŒ์ผ์˜ ์ฝ”๋“œ ๋ถ„์„ + > : /img_viewer.html ์€ GET, POST ๋‘ ๊ฐ€์ง€์˜ ์š”์ฒญ์„ ์ฒ˜๋ฆฌ + > : GET ์˜ ๊ฒฝ์šฐ --> img_viewer.html ์„ ๋ Œ๋”๋ง : POST ์˜ ๊ฒฝ์šฐ --> ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ URL์— HTTP ์š”์ฒญ ์ „์†ก ํ›„ ๊ทธ์— ๋Œ€ํ•œ ์‘๋‹ต์„ img_viewer.html ์˜ ์ธ์ž๋กœ ํ•˜์—ฌ ๋ Œ๋”๋ง + > : ์„œ๋ฒ„ ์ฃผ์†Œ์— "127.0.0.1" ์ด๋‚˜ "localhost" ๊ฐ€ ํฌํ•จ๋œ URL๋กœ์˜ ์ ‘๊ทผ ์ œํ•œ --> ์‚ฌ์šฉ์ž์— ์˜ํ•ด ์ž…๋ ฅ๋œ ๋ฌธ์ž์—ด ์•ˆ์— ์œ„ ๋‘ ์š”์†Œ๊ฐ€ ์žˆ๋‹ค๋ฉด error.png ๋ฐ˜ํ™˜ + > : http (=ํŒŒ์ด์ฌ ๊ธฐ๋ณธ ๋ชจ๋“ˆ) ๋ฅผ ์ด์šฉํ•˜์—ฌ ์ž„.. 2022. 11. 3.
[Dreamhack] File Download - 1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 5 - 0 - 2. File Download - 1 ์›น & ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์  ์‹ค์Šต # File Download - 1 ์›น & ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์  ์‹ค์Šต 1. ๋ฌธ์ œ ํ™•์ธ ๋ฐ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ์˜ app.py ํŒŒ์ผ ๋ถ„์„ + > : ๋””๋ ‰ํ„ฐ๋ฆฌ ์ด๋™์„ ์ œํ•œํ•˜๋Š” ์ฝ”๋“œ ex) ์‹ค์ œ๋กœ ํŒŒ์ผ๋ช…์„ ../flag.py , Content์˜ ๋‚ด์šฉ์„ Content๋กœ ์ž‘์„ฑํ•  ๊ฒฝ์šฐ "bad characters,," ๋ฉ”์„ธ์ง€๊ฐ€ ์ถœ๋ ฅ --> ํŒŒ์ผ ์—…๋กœ๋”ฉ์„ ํ†ตํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์ด๋™์ด ์•„๋‹Œ, URL์„ ์ด์šฉํ•˜๋Š” ๋ฐฉ์‹์„ ํ†ตํ•ด Flag ์ถœ๋ ฅํ•ด์•ผ ํ•จ 2. ์ ‘์† ์ •๋ณด ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† 3. ํ™ˆํŽ˜์ด์ง€์—์„œ Upload My Memo๋ฅผ ํด๋ฆญํ•˜์—ฌ ์—…๋กœ๋”ฉ ํŽ˜์ด์ง€๋กœ ์ด๋™ 4. ์—…๋กœ๋”ฉ ํŽ˜์ด์ง€์—์„œ ํŒŒ์ผ๋ช… ์นธ์— 'filename'์„, Conten.. 2022. 11. 1.
[Dreamhack] Image - Storage ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 5 - 0 - 1. Image - Storage ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์  ์‹ค์Šต # Image - Storage ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์  ์‹ค์Šต 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. index.php , list.php, upload.php ๋ฌธ์ œ ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ๊ฐ๊ฐ ๋ถ„์„ - index.php ํŒŒ์ผ + > : ์ธ๋ฑ์Šค ํŽ˜์ด์ง€์—์„œ list.php ๋กœ ์ด๋™ํ•˜๋Š” ๋ฉ”๋‰ด ์ถœ๋ ฅ + > : ์ธ๋ฑ์Šค ํŽ˜์ด์ง€์—์„œ upload.php ๋กœ ์ด๋™ํ•˜๋Š” ๋ฉ”๋‰ด ์ถœ๋ ฅ - list.php ํŒŒ์ผ + > : $directory ์˜ ํŒŒ์ผ๋“ค ์ค‘์—์„œ ํŠน์ • ์š”์†Œ๋ฅผ ํ•„ํ„ฐ๋งํ•˜์—ฌ ์ œ์™ธํ•œ ์ƒํƒœ๋กœ ๋‚˜์—ด ๋‚˜์—ด ์‹œ ์ œ์™ธ ์š”์†Œ . .. index.html - upload.php ํŒŒ์ผ + ์ด์šฉ์ž๊ฐ€ ์—…๋กœ๋“œํ•œ ํŒŒ์ผ์„ ๊ฒ€์‚ฌ ๊ณผ์ • ์—†์ด uploads ํด๋”์— ๋ณต์‚ฌ --> ๋ณ„๋„์˜ ๊ฒ€.. 2022. 11. 1.
[Dreamhack] Crave Party ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 4 - 0 - 3. Crave Party ์ฝ”๋“œ ์กฐ์ž‘ ์‹ค์Šต # Crave Party ์ฝ”๋“œ ์กฐ์ž‘ ์‹ค์Šต 1. ๋ฌธ์ œ ๋‚ด์šฉ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ ํŒŒ์ผ ์† jack-o-lantern.html ํŽ˜์ด์ง€ ์ ‘์† 3. ํ˜ธ๋ฐ•์„ 2ํšŒ ํด๋ฆญ --> ๋งจ ์•„๋ž˜์˜ ์ˆซ์ž๊ฐ€ 2๋งŒํผ ์ค„์–ด๋“  ๊ฒƒ์„ ํ™•์ธ ๊ฐ€๋Šฅ 4. F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ --> Element ํƒญ์œผ๋กœ ์ด๋™ ํ›„ ํ•จ์ˆ˜ ์ฝ”๋“œ ์กฐ์ž‘ 5. Console ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ for ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ฝ”๋“œ ์ƒ์„ฑ + ๋ณ€์ˆ˜ i๋ฅผ ์„ค์ •ํ•˜์—ฌ ์•„๋ž˜์˜ ์ฝ”๋“œ๊ฐ€ 10000๋ฒˆ ๋ฐ˜๋ณต๋˜๋„๋ก ์„ค์ • + ๋ณ€์ˆ˜ i์˜ ํฌ๊ธฐ๋Š” ํ•œ ๋ฒˆ์˜ ์‹คํ–‰์ด ์™„๋ฃŒ๋  ๋•Œ๋งˆ๋‹ค 1์”ฉ ์ฆ๊ฐ€ + ์ฝ”๋“œ 1๋ฒˆ ์‹คํ–‰ = ํ˜ธ๋ฐ•์„ 1๋ฒˆ ํด๋ฆญํ•˜๋Š” ํ–‰์œ„ 6. ์ฝ”๋“œ ์ž‘์„ฑ ํ›„ ์—”ํ„ฐ ํด๋ฆญ --> ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋˜๋ฉฐ Flag๊ฐ€ ์ถœ๋ ฅ๋˜๋Š”.. 2022. 10. 6.
[Dreamhack] Pathtraversal ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 4 - 0 - 2. Pathtraversal ์ทจ์•ฝ์  ๊ณต๋žต ์‹ค์Šต # Pathtraversal ์ทจ์•ฝ์  ๊ณต๋žต ์‹ค์Šต 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ + > : Flag์˜ ์œ„์น˜๋ฅผ ์•Œ๋ ค์ฃผ๋Š” ์ฝ”๋“œ + > : Userid์˜ ๊ฐ’์„ ์™ธ๋ถ€๋กœ๋ถ€ํ„ฐ ๋ถˆ๋Ÿฌ์˜ค๋Š” ์ฝ”๋“œ + > : Flag๋ฅผ ๋ช…์‹œ๋œ ํ•ด๋‹น ํŽ˜์ด์ง€๋กœ ๋ฆฌํ„ดํ•˜๋Š” ์ฝ”๋“œ + > : ../๋ฅผ ์‚ฌ์šฉํ•ด์„œ ๊ฒฝ๋กœ ์ทจ์•ฝ์  ๊ณต๊ฒฉ์ด ๊ฐ€๋Šฅํ•จ์„ ์‹œ์‚ฌํ•˜๋Š” ์ฝ”๋“œ : ../flag --> ์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ, flag ํŽ˜์ด์ง€๋กœ ์ฐจ๋ก€๋กœ ์ด๋™ํ•˜๊ฒŒ๋” ํ•˜๋Š” ๊ฒฝ๋กœ ์กฐ์ž‘ ์ฝ”๋“œ (ํ˜„์žฌ ์‚ฌ์šฉ์ž๊ฐ€ ์œ„์น˜ํ•œ ๋””๋ ‰ํ† ๋ฆฌ์˜ ์ •ํ™•ํ•œ ์œ„์น˜๋ฅผ ์•Œ ์ˆ˜ ์—†์–ด ์ผ๋‹จ ์ƒ์œ„์˜ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ๋น ์ ธ๋‚˜๊ฐ„ ๋‹ค์Œ flag ํŽ˜์ด์ง€๋กœ ์ ‘๊ทผํ•ด์•ผ ํ•œ๋‹ค.) 3. ์ ‘์† ์ •๋ณด ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† --> Get user .. 2022. 10. 6.
[Dreamhack] Command Injection - 1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 4 - 0 - 1. Command Injection - 1 ํŒจํ‚ท ์ „์†ก ์‹ค์Šต # Command Injection - 1 ํŒจํ‚ท ์ „์†ก ์‹ค์Šต 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ ํŒŒ์ผ์„ ์—ด์–ด ์ฝ”๋“œ ๋ถ„์„ + > : ping ๋ฒ„ํŠผ ํด๋ฆญ ์‹œ ํ•˜๋‹จ์˜ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•จ์„ ์•Œ๋ฆฌ๋Š” ์ฝ”๋“œ + > : ์‚ฌ์šฉ์ž๊ฐ€ ๋นˆ์นธ์— ๊ฐ’ ์ž…๋ ฅ ์‹œ --> ์‚ฌ์šฉ์ž ์ž…๋ ฅ๊ฐ’์ด ๋ณ€์ˆ˜ host์— ์ €์žฅ + > : ์œ„์˜ ๊ณผ์ • ์ง„ํ–‰์ด ๋๋‚˜๋ฉด cmd ๋ช…๋ น์–ด ์‹คํ–‰ : cmd = ๋ช…๋ น ํ”„๋กฌํฌํŠธ + > : ์‰˜๊ณผ bin์„ ํ†ตํ•ด ๋ฆฌ๋ˆ…์Šค์™€ ๊ด€๋ จ๋œ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•จ์„ ๊ณต์ง€ํ•˜๋Š” ์ฝ”๋“œ ++ ํŒŒ์•… ๊ฐ€๋Šฅํ•œ ์ •๋ณด A) flag๋Š” flag.py ํŒŒ์ผ์— ์œ„์น˜ B) ํŒŒ์ผ ํ˜ธ์ถœ ๋ฆฌ๋ˆ…์Šค ๋ช…๋ น์–ด์ธ cat ์„ ์‚ฌ์šฉํ•˜์—ฌ flag.py ํŒŒ์ผ์„ ํ˜ธ์ถœํ•ด์•ผ ํ•จ C) multi command ์„ธ.. 2022. 10. 3.