๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Web Hacking/Webhacking.kr10

[Webhacking.kr] old-53 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ”ญ old-53 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ 2023. 8. 31.
[Webhacking.kr] old-39 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿท old-39 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ 2023. 8. 30.
[Webhacking.kr] old-01 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ‘  old-01 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ --------------------- 2023. 8. 28.
[Webhacking.kr] old-06 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿš‚ old-06 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ ++ ID์™€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๊ธฐ์กด ์ฝ”๋“œ์™€ ๋ฐ˜๋Œ€๋กœ Encode & Decode ํ•˜์—ฌ ์›๋ž˜์˜ ๊ฐ’์„ ๊ตฌํ•ด์•ผ ํ•จ 3. ๋ฌธ์ œ ํ•ด๊ฒฐ์„ ์œ„ํ•œ Python ์Šคํฌ๋ฆฝํŠธ ์ž‘์„ฑ import base64 # ๋ฌธ์ž ์น˜ํ™˜์„ ์—ญ์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๋Š” ํ•จ์ˆ˜ ์ •์˜ def reverse_replace(s): s = s.replace("1", "!") s = s.replace("2", "@") s = s.replace("3", "$") s = s.replace("4", "^") s = s.replace("5", "&") s = s.replace("6", "*") s = s.replace("7", "(") s = s.repl.. 2023. 8. 27.
[Webhacking.kr] old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ›ผ old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ view-source ++ Line 15์˜ ์ •๊ทœํ‘œํ˜„์‹ ์ •์˜์— ์ฃผ๋ชฉ $pat="/[1-3][a-f]{5}_.*$_SERVER[REMOTE_ADDR].*\tp\ta\ts\ts/"; ์ฝ”๋“œ ์˜๋ฏธ [1-3] 1๋ถ€ํ„ฐ 3 ์‚ฌ์ด์˜ ์ˆซ์ž๋กœ ์‹œ์ž‘ [a-f]{5} ์•ŒํŒŒ๋ฒณ a๋ถ€ํ„ฐ f๊นŒ์ง€์˜ ๋ฌธ์ž ์ค‘ ๋™์ผํ•œ 5๊ฐœ๊ฐ€ ์—ฐ์†์œผ๋กœ ์œ„์น˜ .*$_SERVER[REMOTE_ADDR].* ์‚ฌ์šฉ์ž์˜ IP ์ฃผ์†Œ ํฌํ•จ \tp\ta\ts\ts ํƒญ ๋ฌธ์ž๋กœ ๊ตฌ๋ถ„๋˜๋Š” "ptass" ๋ฌธ์ž์—ด ํฌํ•จ --> ์œ„ 4๊ฐœ์˜ ์กฐ๊ฑด์„ ๋งŒ์กฑํ•œ ๋ฌธ์ž์—ด์„ $_GET['val'] ์— ์ „๋‹ฌํ•ด์•ผ ํ•จ 3. ์œ„์˜ ์กฐ๊ฑด์— ์œ ์˜ํ•˜๋ฉฐ ๋ฌธ์ž์—ด ์ž‘์„ฑ val = 2.. 2023. 8. 26.
[Webhacking.kr] old-23 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿฆ‹ old-23 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์˜ ์ž…๋ ฅ๋ž€์— FLAG ๋ฅผ ์ž‘์„ฑํ•œ ํ›„, ์ œ์ถœ ๋ฒ„ํŠผ ํด๋ฆญ --> "no hack" ์ด๋ผ๋Š” ๋ฌธ๊ตฌ ์ถœ๋ ฅ 2. ์ƒ๋‹จ URL๋ž€์— ์•„๋ž˜์™€ ๊ฐ™์ด ์ž…๋ ฅ ํ›„ Enter ํด๋ฆญ --> F, L, A, G ๊ฐ€ ๋ถ™์€ ์ƒํƒœ๋กœ ์ถœ๋ ฅ F%00L%00A%00G ++ %00 ์€ ๋ฌด์Šจ ํ‘œํ˜„์ผ๊นŒ? "%00"์€ NULL ๋ฌธ์ž์˜ URL ์ธ์ฝ”๋”ฉ๋œ ํ‘œํ˜„์ด์œผ๋กœ, ๋งŽ์€ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด์™€ ์‹œ์Šคํ…œ์—์„œ ๋ฌธ์ž์—ด ์ฒ˜๋ฆฌ์— ์‚ฌ์šฉ๋œ๋‹ค. NULL ์€ ๋ฌธ์ž์—ด์˜ ๋์„ ๋‚˜ํƒ€๋‚ด๋Š” ํŠน๋ณ„ํ•œ ๋ฌธ์ž์ธ๋ฐ, ์ด๋ฒˆ ๋ฌธ์ œ ํ’€์ด์—์„œ๋„ 2๋ฌธ์ž ์ด์ƒ ๋™์‹œ์— ์ž…๋ ฅ ์‹œ ๊ทธ ๊ฐ’์ด ํ•„ํ„ฐ๋ง๋˜๋Š” ๊ฒƒ์„ ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋œ๋‹ค. 3. ๊ธฐ์กด ๋ฏธ์…˜์ด์˜€๋˜ "alert(1);" ์ฃผ์ž…์„ ์œ„ํ•ด, ์•„๋ž˜ ์ฟผ๋ฆฌ๋ฌธ ์ž…๋ ฅ ํ›„ Enter ํด๋ฆญ a%00l%00e%00r%00t(1);.. 2023. 8. 25.