๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Web Hacking52

[Webhacking.kr] old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ›ผ old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ view-source ++ Line 15์˜ ์ •๊ทœํ‘œํ˜„์‹ ์ •์˜์— ์ฃผ๋ชฉ $pat="/[1-3][a-f]{5}_.*$_SERVER[REMOTE_ADDR].*\tp\ta\ts\ts/"; ์ฝ”๋“œ ์˜๋ฏธ [1-3] 1๋ถ€ํ„ฐ 3 ์‚ฌ์ด์˜ ์ˆซ์ž๋กœ ์‹œ์ž‘ [a-f]{5} ์•ŒํŒŒ๋ฒณ a๋ถ€ํ„ฐ f๊นŒ์ง€์˜ ๋ฌธ์ž ์ค‘ ๋™์ผํ•œ 5๊ฐœ๊ฐ€ ์—ฐ์†์œผ๋กœ ์œ„์น˜ .*$_SERVER[REMOTE_ADDR].* ์‚ฌ์šฉ์ž์˜ IP ์ฃผ์†Œ ํฌํ•จ \tp\ta\ts\ts ํƒญ ๋ฌธ์ž๋กœ ๊ตฌ๋ถ„๋˜๋Š” "ptass" ๋ฌธ์ž์—ด ํฌํ•จ --> ์œ„ 4๊ฐœ์˜ ์กฐ๊ฑด์„ ๋งŒ์กฑํ•œ ๋ฌธ์ž์—ด์„ $_GET['val'] ์— ์ „๋‹ฌํ•ด์•ผ ํ•จ 3. ์œ„์˜ ์กฐ๊ฑด์— ์œ ์˜ํ•˜๋ฉฐ ๋ฌธ์ž์—ด ์ž‘์„ฑ val = 2.. 2023. 8. 26.
[Webhacking.kr] old-23 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿฆ‹ old-23 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์˜ ์ž…๋ ฅ๋ž€์— FLAG ๋ฅผ ์ž‘์„ฑํ•œ ํ›„, ์ œ์ถœ ๋ฒ„ํŠผ ํด๋ฆญ --> "no hack" ์ด๋ผ๋Š” ๋ฌธ๊ตฌ ์ถœ๋ ฅ 2. ์ƒ๋‹จ URL๋ž€์— ์•„๋ž˜์™€ ๊ฐ™์ด ์ž…๋ ฅ ํ›„ Enter ํด๋ฆญ --> F, L, A, G ๊ฐ€ ๋ถ™์€ ์ƒํƒœ๋กœ ์ถœ๋ ฅ F%00L%00A%00G ++ %00 ์€ ๋ฌด์Šจ ํ‘œํ˜„์ผ๊นŒ? "%00"์€ NULL ๋ฌธ์ž์˜ URL ์ธ์ฝ”๋”ฉ๋œ ํ‘œํ˜„์ด์œผ๋กœ, ๋งŽ์€ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด์™€ ์‹œ์Šคํ…œ์—์„œ ๋ฌธ์ž์—ด ์ฒ˜๋ฆฌ์— ์‚ฌ์šฉ๋œ๋‹ค. NULL ์€ ๋ฌธ์ž์—ด์˜ ๋์„ ๋‚˜ํƒ€๋‚ด๋Š” ํŠน๋ณ„ํ•œ ๋ฌธ์ž์ธ๋ฐ, ์ด๋ฒˆ ๋ฌธ์ œ ํ’€์ด์—์„œ๋„ 2๋ฌธ์ž ์ด์ƒ ๋™์‹œ์— ์ž…๋ ฅ ์‹œ ๊ทธ ๊ฐ’์ด ํ•„ํ„ฐ๋ง๋˜๋Š” ๊ฒƒ์„ ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋œ๋‹ค. 3. ๊ธฐ์กด ๋ฏธ์…˜์ด์˜€๋˜ "alert(1);" ์ฃผ์ž…์„ ์œ„ํ•ด, ์•„๋ž˜ ์ฟผ๋ฆฌ๋ฌธ ์ž…๋ ฅ ํ›„ Enter ํด๋ฆญ a%00l%00e%00r%00t(1);.. 2023. 8. 25.
[Webhacking.kr] old-20 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐ŸŽข old-20 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์˜ ์ž…๋ ฅ๋ž€์„ ๋ชจ๋‘ ์ž‘์„ฑํ•œ ํ›„ Submit ํด๋ฆญ --> Too Slow ๋ผ๋Š” ํŽ˜์ด์ง€๋กœ ์ด๋™ 2. F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ๋ˆŒ๋Ÿฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ 3. Elements ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ ์ฝ”๋“œ ์—ด๋žŒ ++ ๋‹จ์ˆœํžˆ ์œ„ ์ž…๋ ฅ๋ž€์˜ ๋นˆ์นธ์„ 2์ดˆ ์•ˆ์— ์ฑ„์šฐ๋ฉด ๋˜๋Š” ๋“ฏ ํ•จ 4. Console ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ ์•„๋ž˜์™€ ๊ฐ™์ด ์ž‘์„ฑ lv5frm.id.value=2023; lv5frm.cmt.value=2023; lv5frm.captcha.value=lv5frm.captcha_.value; lv5frm.submit(); ์ฝ”๋“œ ์„ค๋ช… lv5frm.id.value=2023; id ์ž…๋ ฅ ํ•„๋“œ์— "2023" ๋Œ€์ž… lv5frm.cmt.value=2023; cmt ์ž…๋ ฅ ํ•„๋“œ์— "2023" ๋Œ€์ž… lv5frm.. 2023. 8. 24.
[Webhacking.kr] old-17 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ… old-17 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์˜ ์ž…๋ ฅ๋ž€์— hello! ์ž…๋ ฅ ํ›„ check ํด๋ฆญ --> Wrong ์ด๋ผ๋Š” ๊ฒฝ๊ณ ์ฐฝ ์ถœ๋ ฅ 2. F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ๋ˆŒ๋Ÿฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ 3. Elements ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ ์ฝ”๋“œ ์—ด๋žŒ #shadow-root (closed) ++ unlock ๋ณ€์ˆ˜์— ๋“ค์–ด๊ฐ„ ๊ฐ’์„ ์ž…๋ ฅ๋ž€์— ๋„ฃ์œผ๋ฉด ๋˜๋Š” ๋“ฏ ํ•˜๋‹ค. 4. Console ํƒญ์œผ๋กœ ์ด๋™ํ•˜์—ฌ unlock ๋ณ€์ˆ˜๊ฐ’์„ ํ™•์ธ console.log(unlock); 5. Console ์—์„œ ์–ป์€ ๊ฐ’์„ ์ž…๋ ฅ ํ›„ check ๋ฒ„ํŠผ ํด๋ฆญ --> ๋ฌธ์ œ ํ•ด๊ฒฐ ์„ฑ๊ณต 2023. 8. 23.
[Webhacking.kr] old-16 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ– old-16 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ„ ํ›„ ๋‹จ์ถ•ํ‚ค F12๋ฅผ ํ†ตํ•ด ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์˜คํ”ˆ 2. Sources ํƒญ์˜ Index ํŽ˜์ด์ง€๋กœ ๋“ค์–ด๊ฐ€ ์ฝ”๋“œ ์—ด๋žŒ Challenge 16 * ++ ์ž…๋ ฅ ์ด๋ฒคํŠธ์— ๋”ฐ๋ผ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜๋Š” mv() ํ•จ์ˆ˜์— ์ฃผ๋ชฉ ++ Do it! ์ด๋ผ๋Š” ์ฃผ์„์ด ๋‹ฌ๋ฆฐ Line 15์— ์ฃผ๋ชฉ 3. ์•„๋ž˜ ์‚ฌ์ดํŠธ๋ฅผ ์ด์šฉํ•˜์—ฌ ASCII Code ์™€ ๋งค์นญ๋˜๋Š” ํ‚ค๋ณด๋“œ ๋ฌธ์ž ํƒ์ƒ‰ cd ๊ฐ’ (ASKII Code) ๋งค์นญ๋˜๋Š” ๋ฌธ์ž ์ˆ˜ํ–‰ ์ž‘์—… 100 d ๋ณ„์˜ x ์ขŒํ‘œ๋ฅผ ์˜ค๋ฅธ์ชฝ์œผ๋กœ 50px๋งŒํผ ์ด๋™ 97 a ๋ณ„์˜ x ์ขŒํ‘œ๋ฅผ ์™ผ์ชฝ์œผ๋กœ 50px๋งŒํผ ์ด๋™ 119 w ๋ณ„์˜ y ์ขŒํ‘œ๋ฅผ ์œ„์ชฝ์œผ๋กœ 50px๋งŒํผ ์ด๋™ 115 s ๋ณ„์˜ y ์ขŒํ‘œ๋ฅผ ์•„๋ž˜์ชฝ์œผ๋กœ 50px๋งŒํผ ์ด๋™ 124 | ๋ธŒ๋ผ์šฐ์ €๋ฅผ ๋‹ค๋ฅธ ํŽ˜์ด์ง€๋กœ ์ด๋™ ++.. 2023. 8. 22.
[Webhacking.kr] old-26 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด โ˜„๏ธ old-26 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ„ ํ›„ view-source ์„ ํƒํ•˜์—ฌ ์ฝ”๋“œ ์—ด๋žŒ view-source ++ GET ๋ฐฉ์‹์œผ๋กœ ์ž…๋ ฅ๋ฐ›์€ id๊ฐ’์ด admin ์ด๋ผ๋ฉด, ๋ฌธ์ œ ํ•ด๊ฒฐ 2. preg_match() ํ•จ์ˆ˜ ์šฐํšŒ๋ฅผ ์œ„ํ•ด, URL ์ธ์ฝ”๋”ฉ ํ‘œ์ค€์— ๋”ฐ๋ผ ์•„๋ž˜ ์ž‘์—… ์ˆ˜ํ–‰ Not - Encoded Encoded - Once Encoded - Twice admin %61%64%6D%69%6E %2561%2564%256D%2569%256E ++ ์‚ฌ์šฉํ•œ URL ์ธ์ฝ”๋” & ๋””์ฝ”๋” --> https://heavenly-appear.tistory.com/176 [URL ์ธ์ฝ”๋”, ๋””์ฝ”๋”] url์ธ์ฝ”๋”ฉ, url๋””์ฝ”๋”ฉ - ๋ฐ”๋กœ ๋ณ€ํ™˜ํ•ด๋“œ๋ ค์š”! Encoding Decoding ๋ณต์‚ฌ๋ฒ„ํŠผ์€ ํ˜„์žฌ ํฌ๋กฌ์—์„œ๋งŒ ์ง€์›.. 2023. 8. 21.