๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ439

[Dreamhack] Flying Chars ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿฆ‹ Flying Chars ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฌธ์ œ ํ™”๋ฉด์—์„œ ์„œ๋ฒ„๋ฅผ ์ƒ์„ฑํ•˜๊ณ , ์•ˆ๋‚ด๋œ ๋งํฌ๋กœ ์ ‘์† ๊ธ€์ž๋“ค์ด ์•„์ฃผ ํ™œ๊ธฐ์ฐจ๊ฒŒ ์›€์ง์ด๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค...^^ 3. F12 ๋‹จ์ถ•ํ‚ค๋ฅผ ํด๋ฆญํ•˜์—ฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ ์—ด๊ธฐ 4. ๊ธ€์ž๋“ค์˜ ์›€์ง์ด๋Š” ์†๋„์™€ ๊ด€๋ จ๋œ ์ฝ”๋“œ๋ฅผ ๋ฐœ๊ฒฌ for(var i=0; i 2023. 8. 13.
[Dreamhack] Session ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐ŸŽž๏ธ Session ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ app.py ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for app = Flask(__name__) try: FLAG = open('./flag.txt', 'r').read() except: FLAG = '[**FLAG**]' ์ฝ”๋“œ ์„ค๋ช… from flask import Flask, request, render_template, make_response, redirect, url_for ์›น ์„œ๋ฒ„ ์ƒ์„ฑ, ์š”์ฒญ ์ฒ˜๋ฆฌ, ํ…œํ”Œ๋ฆฟ ๋ Œ๋”๋ง ๋“ฑ์— ํ•„.. 2023. 8. 12.
[Dreamhack] Simple SQLI ChatGPT ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿˆ‍โฌ› Simple SQLI ChatGPT ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ app.py ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ #!/usr/bin/python3 from flask import Flask, request, render_template, g import sqlite3 import os import binascii app = Flask(__name__) app.secret_key = os.urandom(32) try: FLAG = open('./flag.txt', 'r').read() except: FLAG = '[**FLAG**]' DATABASE = "database.db" if os.path.exists(DATABASE) == False: .. 2023. 8. 11.
[Dreamhack] XSS Filtering Bypass ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด โš”๏ธ XSS Filtering Bypass ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ app.py ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ #!/usr/bin/python3 from flask import Flask, request, render_template from selenium import webdriver import urllib import os A) ํ•„์š”ํ•œ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ imoport ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์„ค๋ช… Flask ์›น ํ”„๋ ˆ์ž„์›Œํฌ Request HTTP ์š”์ฒญ ์ฒ˜๋ฆฌ ๊ด€๋ จ ๊ธฐ๋Šฅ Render_template HTML ํ…œํ”Œ๋ฆฟ ๋ Œ๋”๋ง Selenium ์›น ๋ธŒ๋ผ์šฐ์ € ์ž๋™ํ™” ๋„๊ตฌ Urllib URL ์ธ์ฝ”๋”ฉ ๊ธฐ๋Šฅ OS ์šด์˜์ฒด์ œ์™€์˜ ์ƒํ˜ธ์ž‘์šฉ ๊ธฐ๋Šฅ app = Flask(__name__.. 2023. 8. 10.
[GitHub & Git] GitHub(๊นƒํ—ˆ๋ธŒ) Personal Access Token ์ƒ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ• ๐Ÿ ํผ์Šค๋„ ์—‘์„ธ์Šค ํ† ํฐ(Personal Access Token) ์ด๋ž€? ๊นƒํ—ˆ๋ธŒ์˜ ํผ์Šค๋„ ์—‘์„ธ์Šค ํ† ํฐ(Personal Access Token)์€ ๊นƒํ—ˆ๋ธŒ(GitHub)์—์„œ ์ œ๊ณตํ•˜๋Š” ์ธ์ฆ ๋ฐฉ์‹ ์ค‘ ํ•˜๋‚˜๋กœ, ์‚ฌ์šฉ์ž๊ฐ€ ์ž์‹ ์˜ ๊ณ„์ •์„ ์ธ์ฆํ•˜๊ณ  API ์š”์ฒญ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ฃผ๋Š” ๋ณด์•ˆ ์ธ์ฆ ํ‚ค์ด๋‹ค. ํผ์Šค๋„ ์—‘์„ธ์Šค ํ† ํฐ์€ ์‚ฌ์šฉ์ž๊ฐ€ ์ž์‹ ์˜ ๊นƒํ—ˆ๋ธŒ ๊ณ„์ •๊ณผ ์—ฐ๊ฒฐ๋œ ๊ถŒํ•œ๊ณผ ๋ฒ”์œ„๋ฅผ ์ •์˜ํ•˜์—ฌ ์ƒ์„ฑ๋˜๋ฉฐ, ์‚ฌ์šฉ์ž๋Š” ํ† ํฐ์˜ ๋ฒ”์œ„์— ๋”ฐ๋ผ ํŠน์ • ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— ๋Œ€ํ•œ ์ฝ๊ธฐ๋‚˜ ์“ฐ๊ธฐ, ๊ด€๋ฆฌ ๋“ฑ์˜ ๊ถŒํ•œ์„ ํ—ˆ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. ๐Ÿ Personal Access Token ์ƒ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ• 1. ๋ณธ์ธ์˜ GitHub ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ ํ›„ ์šฐ์ธก ์ƒ๋‹จ์˜ ๋กœ๊ณ  ํด๋ฆญ 2. "Settings" ์„ ํƒ ํ›„ "Developer settings" ํด๋ฆญ 3. "Perso.. 2023. 8. 6.
[AWS] AWS Secret Key ์œ ์ถœ ์‹œ ๋Œ€์ฒ˜ ๋ฐฉ๋ฒ• ๐Ÿฅฃ AWS Secret Key ์œ ์ถœ ์‹œ ๋Œ€์ฒ˜ ๋ฐฉ๋ฒ• ์ •๋ฆฌ 1. AWS์˜ ์‹œํฌ๋ฆฟ ํ‚ค๊ฐ€ ์œ ์ถœ๋œ ๊ฒฝ์šฐ, ์•„๋ž˜์™€ ๊ฐ™์€ ๋ฉ”์ผ์ด ์ „์†ก๋œ๋‹ค. 2. ์ด๋•Œ ๋ฉ”์ผ์˜ ๋ณธ๋ฌธ์„ ๋ณด๋ฉด ํ‚ค์˜ ์œ ์ถœ ๊ฒฝ๋กœ๊ฐ€ ์žˆ๋Š”๋ฐ, ์ด ๊ฒฝ๋กœ๋ฅผ ํƒ€๊ณ  ๋“ค์–ด๊ฐ€ ํ•ด๋‹น ํŒŒ์ผ ๋ฐ ํด๋”๋ฅผ ์‚ญ์ œํ•œ๋‹ค. ++ ํŒŒ์ผ & ํด๋” ์‚ญ์ œ ํ›„์—๋Š” ๊ผญ ๋‹ค์‹œ ์œ„ URL ๋กœ ๋“ค์–ด๊ฐ€ ์—‘์„ธ์Šค ํ‚ค๊ฐ€ ํฌํ•จ๋œ ๋‚ด์šฉ์ด ๋œจ๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ์žฌ์ฐจ ํ™•์ธํ•ด์•ผ ํ•จ 3. ์œ ์ถœ์˜ ์›์ธ์„ ์‚ญ์ œํ•˜์˜€๋‹ค๋ฉด, ๊ทธ ํ›„์—๋Š” ๋ฉ”์ผ ๋ณธ๋ฌธ์˜ ์•ˆ๋‚ด์— ๋”ฐ๋ผ ์•„๋ž˜ ์‚ฌํ•ญ์„ ์ˆœ์„œ๋Œ€๋กœ ์ˆ˜ํ–‰ํ•œ๋‹ค. โ“ ์ฒ˜์Œ ์ „์†ก๋˜์—ˆ๋˜ ๋ฉ”์ผ์— ์ž‘์„ฑ๋œ ์—ฐ๋ฝ์ฒ˜๋กœ ๊ถŒํ•œ ์ˆ˜์ • ์š”์ฒญ ๋ฉ”์ผ ์ž‘์„ฑ --> ์œ ์ถœ๋œ Secret Access ํ‚ค๋ฅผ ๋น„ํ™œ์„ฑํ™” ๋ฐ ์‚ญ์ œํ•˜๊ธฐ ์œ„ํ•ด ๊ถŒํ•œ ํ•„์š” โ“‘ ์œ ์ถœ๋œ ํ‚ค๋ฅผ ๋ณด์œ ํ•œ ์‚ฌ์šฉ์ž ๊ณ„์ •์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณ€๊ฒฝ + AWS ํ‚ค๋ฅผ ๋น„ํ™œ์„ฑํ™” & ์‚ญ์ œํ•  ๋•Œ ํ‚ค์˜ .. 2023. 8. 4.