๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Web Hacking/Dreamhack41

[Dreamhack] XSS-1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 2 - 0 - 2. XSS - 1 ์ทจ์•ฝ์  ๋ถ„์„ ์‹ค์Šต # XSS - 1 ์ทจ์•ฝ์  ๋ถ„์„ ์‹ค์Šต 1. ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ๋ฐ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ์ ‘์† ์ •๋ณด ๋ณด๊ธฐ์—์„œ ์•ˆ๋‚ด๋œ http://host3.dreamhack.games:22929/ ๋งํฌ๋กœ ์ด๋™ 3. ๋ฌธ์ œ ํŒŒ์ผ ์† ์ฝ”๋“œ ๋ถ„์„ + > : read_url ํ•จ์ˆ˜ ์‹คํ–‰ --> driver.get('http://127.0.0.1:8000/') ์ฝ”๋“œ๋ฅผ ํ†ตํ•ด ๋กœ์ปฌํ˜ธ์ŠคํŠธ ํ™˜๊ฒฝ์—์„œ ์›นํŽ˜์ด์ง€์— ์ ‘์† --> driver.add_cookie(cookie) ์ฝ”๋“œ๋ฅผ ํ†ตํ•ด ์ ‘์†ํ•œ ์›น ํŽ˜์ด์ง€์— ๋งค๊ฐœ๋ณ€์ˆ˜๋กœ ๋ฐ›์•„์˜จ cookie ์ถ”๊ฐ€ --> driver.get(url) ์ฝ”๋“œ๋ฅผ ํ†ตํ•ด ๋งค๊ฐœ๋ณ€์ˆ˜๋กœ ๋ฐ›์•„์˜จ xss ๊ฐ’์„ ์ด์šฉํ•˜์—ฌ xss ํŽ˜์ด์ง€ ์ ‘์† + > : POSTํ•˜๋Š” ๊ณผ์ •์—์„œ check_xss ํ•จ.. 2022. 9. 21.
[Dreamhack] ClientSide : Cross Site Scripting (XSS) + Stored XSS + Reflected XSS 2 - 0 - 1. ClientSide : Cross Site Scripting (XSS) + Stored XSS + Reflected XSS # Cross Site Scripting (XSS) ( = ํด๋ผ์ด์–ธํŠธ ์‚ฌ์ด๋“œ ์ทจ์•ฝ์  ) : ๊ณต๊ฒฉ์ž๊ฐ€ ์›น ๋ฆฌ์†Œ์Šค์— ์•…์„ฑ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฝ์ž…ํ•˜์—ฌ ํด๋ผ์ด์–ธํŠธ์˜ ์›น ๋ธŒ๋ผ์šฐ์ €์—์„œ ํ•ด๋‹น ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ทจ์•ฝ์ ์„ ๋งํ•˜๋ฉฐ, ์ด์šฉ์ž๊ฐ€ ์‚ฝ์ž…ํ•œ ๋‚ด์šฉ์„ ์ถœ๋ ฅํ•˜๋Š” ๊ธฐ๋Šฅ์—์„œ ๋ฐœ์ƒํ•จ + Cross Site Scripting ์˜ ๊ฒฝ์šฐ CSS (์Šคํƒ€์ผ์‹œํŠธ)์™€์˜ ํ˜ผ๋™ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์–ด CSS๊ฐ€ ์•„๋‹Œ XSS๋กœ ๋ช…๋ช…ํ•จ - XSS ์˜ ์ข…๋ฅ˜ Stored XSS Reflected XSS DOM-based XSS Universal XSS ์‚ฌ์šฉ๋˜๋Š” ์•…์„ฑ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์„œ๋ฒ„์— ์ €์žฅ๋˜๊ณ , ์„œ๋ฒ„์˜ ์‘๋‹ต์— ๋‹ด๊ฒจ์˜ค๋Š” XSS.. 2022. 9. 21.
[Dreamhack] Mitigation : Same Origin Policy ( SOP ) + Cross Origin Resource Sharing ( CORS ) + JSON with Padding ( JSONP ) 1 - 0 - 9. Mitigation : Same Origin Policy ( SOP ) + Cross Origin Resource Sharing ( CORS ) + JSON with Padding ( JSONP ) # ๋™์ผ ์ถœ์ฒ˜ ์ •์ฑ… ( = Same Origin Policy ( SOP ) ) : ํ˜„ ํŽ˜์ด์ง€๊ฐ€ ์•„๋‹Œ ํƒ€ ์ถœ์ฒ˜์—์„œ ์˜จ ๋ฐ์ดํ„ฐ๋ฅผ ์ฝ์–ด๋“ค์ด์ง€ ๋ชปํ•˜๊ฒŒ ํ•˜๋Š” ๋ธŒ๋ผ์šฐ์ €์˜ ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜ + mitigation์ด๋ž€? : '์™„ํ™”, ๊ฒฝ๊ฐ' ์ด๋ผ๋Š” ์˜๋ฏธ๋ฅผ ์ง€๋‹˜ - ๋™์ผ ์ถœ์ฒ˜ ์ •์ฑ…์˜ ์˜ค๋ฆฌ์ง„(origin) ๊ตฌ๋ถ„๋ฒ• origin์˜ ๊ตฌ์„ฑ ์š”์†Œ ํ”„๋กœํ† ์ฝœ(protocol, scheme) ํ˜ธ์ŠคํŠธ(host) ํฌํŠธ(port) + ์œ„ ๊ตฌ์„ฑ ์š”์†Œ๊ฐ€ ๋ชจ๋‘ ์ผ์น˜ํ•˜๋Š” ๊ฒฝ์šฐ์—๋งŒ ๋™์ผํ•œ ์˜ค๋ฆฌ์ง„์ด๋ผ๊ณ  ์นญํ•œ๋‹ค. ex 1) https://sam.. 2022. 9. 18.
[Dreamhack] Web - Misconf - 1 ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1 - 0 - 8. Web - Misconf - 1 FLAG ํƒ์ƒ‰ ์‹ค์Šต # Web - Misconf - 1 FLAG ํƒ์ƒ‰ ์‹ค์Šต 1. ๋“œ๋ฆผํ•ต ์‚ฌ์ดํŠธ์—์„œ ๋ฌธ์ œ ํ™•์ธ ๋ฐ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ์ ‘์† ์ •๋ณด ํ™•์ธ ํ›„ ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† 3. ์ ‘์† ํ›„ ์•„์ด๋””๋ž€๊ณผ password ๋ž€์— ๊ฐ๊ฐ admin์„ ์ž…๋ ฅํ•˜์—ฌ ๋กœ๊ทธ์ธ 4. ๋กœ๊ทธ์ธ ํ›„ ์ขŒ์ธก ๋ฉ”๋‰ด๋ฐ”๋ฅผ ํ†ตํ•ด Server Admin ํƒญ์œผ๋กœ ์ด๋™ 5. ์ƒ๋‹จ์˜ Users, Orgs, Upgrade, Stats, Settings ํƒญ์œผ๋กœ ๊ฐ๊ฐ ์ด๋™ํ•˜์—ฌ FLAG๊ฐ€ ์žˆ๋Š”์ง€ ๊ฒ€์‚ฌ + ์ด๋ฒˆ ๋ฌธ์ œ์˜ FLAG๋Š” DH{default_account_is very dangerous} 2022. 9. 18.
[Dreamhack] Cookie ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1 - 0 - 7. Cookie ์ทจ์•ฝ์  ํƒ์ƒ‰ ์‹ค์Šต # Cookie ์ทจ์•ฝ์  ํƒ์ƒ‰ ์‹ค์Šต 1. ๋“œ๋ฆผํ•ต ์‚ฌ์ดํŠธ์—์„œ ๋ฌธ์ œ ์ •๋ณด ํ™•์ธ ๋ฐ ๋ฌธ์ œ ์ž๋ฃŒ ๋‹ค์šด๋ฐ›๊ธฐ 2. VScode ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ด์ฌ ํŒŒ์ผ ์—ด๊ธฐ 3. ํŒŒ์ด์ฌ ํŒŒ์ผ์˜ ์ฝ”๋“œ ๋ถ„์„ + > : flag.txt ํŒŒ์ผ์—์„œ FLAG ๋ฐ์ดํ„ฐ ํ˜ธ์ถœํ•˜๋Š” ์ฝ”๋“œ + > : ํ˜„์žฌ admin, guest 2๊ฐœ์˜ ๊ณ„์ •์ด ์กด์žฌํ•˜๋ฉฐ admin ์˜ password๋Š” FLAG์˜ ๋ฐ์ดํ„ฐ๋กœ ์„ ์–ธํ–ˆ์Œ์„ ํ™•์ธ ๊ฐ€๋Šฅ + > : route ์ฝ”๋“œ๋Š” ํŽ˜์ด์ง€ ๋ผ์šฐํŒ…์„ ์œ„ํ•ด ์ด์šฉ + > : ์ด์šฉ์ž๊ฐ€ ์ „์†กํ•œ ์ฟ ํ‚ค์˜ username ์ž…๋ ฅ๊ฐ’์„ ๋ถˆ๋Ÿฌ์˜ค๋Š” ์ฝ”๋“œ + > : username ์ž…๋ ฅ๊ฐ’์ด ์กด์žฌํ•˜๋Š” ๊ฒฝ์šฐ ํ˜„ ์‚ฌ์šฉ์ž๊ฐ€ admin์ด๋ผ๋ฉด FLAG๋ฅผ, admin์ด ์•„๋‹ˆ๋ผ๋ฉด "you are not admin"์„ ์ถœ๋ ฅํ•œ.. 2022. 9. 17.
[Dreamhack] Session - Basic ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1 - 0 - 6. Session - Basic ์ทจ์•ฝ์  ํƒ์ƒ‰ ์‹ค์Šต # Session - Basic 1. ๋ฌธ์ œ ์„ค๋ช…์„ ํ™•์ธํ•œ ํ›„ ๋“œ๋ฆผํ•ต ์‚ฌ์ดํŠธ์—์„œ ๋ฌธ์ œ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ 2. VScode์—์„œ python ํŒŒ์ผ์„ ์‹คํ–‰ 3. ๋ฌธ์ œ ํŒŒ์ผ์˜ ์ฝ”๋“œ ๋ถ„์„ + > : flag.txt ํŒŒ์ผ์—์„œ FLAG ๋ฐ์ดํ„ฐ๋ฅผ ํ˜ธ์ถœํ•˜๋Š” ์ฝ”๋“œ + > : ํ˜„์žฌ guest, user, admin 3๊ฐœ์˜ ๊ณ„์ •์ด ์กด์žฌํ•œ๋‹ค๋Š” ๊ฒƒ์„ ํ™•์ธ : guest์˜ pw๋Š” guest, user์˜ pw๋Š” user1234, admin ์˜ pw๋Š” FLAG์ž„์„ ํ™•์ธ + > : route๋Š” URL์— ์š”์ฒญ์ด ๋“ค์–ด์™”์„ ๊ฒฝ์šฐ ํ˜ธ์ถœํ•  ํ•จ์ˆ˜๋ฅผ ๊ฒฐ์ • + > : ๋งŒ์ผ ๋กœ๊ทธ์ธํ•œ ์•„์ด๋””๊ฐ€ admin์ด ์•„๋‹ˆ๋ผ๋ฉด 'you are not admin'์„, ๋งž๋‹ค๋ฉด FLAG๋ฅผ ์ถœ๋ ฅ + > : ํด๋ผ.. 2022. 9. 17.