βοΈ Web Hacking/Webhacking.kr
[Webhacking.kr] old-17 μκ²μ λ¬Έμ νμ΄
A Lim Han
2023. 8. 23. 10:08
π old-17 μκ²μ λ¬Έμ νμ΄
1. λ¬Έμ νλ©΄μ μ λ ₯λμ hello! μ λ ₯ ν check ν΄λ¦ --> Wrong μ΄λΌλ κ²½κ³ μ°½ μΆλ ₯
2. F12 λ¨μΆν€λ₯Ό λλ¬ κ°λ°μ λꡬ μ€ν
3. Elements νμΌλ‘ μ΄λνμ¬ μ½λ μ΄λ
<!DOCTYPE html>
<html>
<head>
<title>Challenge 17</title>
</head>
<body bgcolor="black">
<font color="red" size="10"></font>
<p> </p>
<form name="login"> <!-- λ‘κ·ΈμΈ νΌ μμ -->
<input type="passwd" name="pw"> <!-- ν¨μ€μλ μ
λ ₯ νλ -->
<input type="button" onclick="sub()" value="check"> <!-- 'check' λ²νΌ, ν΄λ¦νλ©΄ sub() ν¨μ νΈμΆ -->
</form> <!-- λ‘κ·ΈμΈ νΌ μ’
λ£ -->
<script> <!-- μλ°μ€ν¬λ¦½νΈ μ½λ μμ -->
unlock = 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 1 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 + 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 - 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 + 9999999;
function sub() {
if (login.pw.value == unlock) { // μ
λ ₯ν ν¨μ€μλκ° unlock κ°κ³Ό μΌμΉνλμ§ νμΈ
location.href = "?" + unlock / 10; // μΌμΉν κ²½μ° νμ΄μ§ μ΄λ (query stringμ unlock κ°μ 10λΆμ 1 μΆκ°)
} else {
alert("Wrong"); // ν¨μ€μλκ° μΌμΉνμ§ μμ κ²½μ° κ²½κ³ μ°½ νμ
}
}
</script> <!-- μλ°μ€ν¬λ¦½νΈ μ½λ μ’
λ£ -->
<whale-quicksearch translate="no"> <!-- ν΅μμΉ μμ -->
#shadow-root (closed) <!-- μλμ DOM νΈλ¦¬ λ΄λΆμ μ κ·Όνλ shadow DOM νμ -->
<style></style>
<div class="quicksearch"></div>
</whale-quicksearch> <!-- ν΅μμΉ μμ μ’
λ£ -->
</body>
</html>
++ unlock λ³μμ λ€μ΄κ° κ°μ μ λ ₯λμ λ£μΌλ©΄ λλ λ― νλ€.
4. Console νμΌλ‘ μ΄λνμ¬ unlock λ³μκ°μ νμΈ
console.log(unlock);
5. Console μμ μ»μ κ°μ μ λ ₯ ν check λ²νΌ ν΄λ¦ --> λ¬Έμ ν΄κ²° μ±κ³΅