βœ’οΈ Web Hacking/Webhacking.kr

[Webhacking.kr] old-17 μ›Œκ²Œμž„ 문제 풀이

A Lim Han 2023. 8. 23. 10:08

πŸ… old-17 μ›Œκ²Œμž„ 문제 풀이

1.  λ¬Έμ œ ν™”λ©΄μ˜ μž…λ ₯λž€μ— hello! μž…λ ₯ ν›„ check 클릭  -->  Wrong μ΄λΌλŠ” κ²½κ³ μ°½ 좜λ ₯

2.  F12 단좕킀λ₯Ό 눌러 개발자 도ꡬ μ˜€ν”ˆ

3.  Elements νƒ­μœΌλ‘œ μ΄λ™ν•˜μ—¬ μ½”λ“œ μ—΄λžŒ

<!DOCTYPE html>
<html>
<head>
<title>Challenge 17</title>
</head>
<body bgcolor="black">
<font color="red" size="10"></font>
<p> </p>
<form name="login"> <!-- 둜그인 폼 μ‹œμž‘ -->
<input type="passwd" name="pw"> <!-- νŒ¨μŠ€μ›Œλ“œ μž…λ ₯ ν•„λ“œ -->
<input type="button" onclick="sub()" value="check"> <!-- 'check' λ²„νŠΌ, ν΄λ¦­ν•˜λ©΄ sub() ν•¨μˆ˜ 호좜 -->
</form> <!-- 둜그인 폼 μ’…λ£Œ -->

<script> <!-- μžλ°”μŠ€ν¬λ¦½νŠΈ μ½”λ“œ μ‹œμž‘ -->
unlock = 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 1 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 + 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 - 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 / 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 * 100 * 10 * 10 + 100 / 10 - 10 + 10 + 50 - 9 * 8 + 7 - 6 + 5 - 4 * 3 - 2 * 1 * 10 + 9999999;
function sub() {
    if (login.pw.value == unlock) { // μž…λ ₯ν•œ νŒ¨μŠ€μ›Œλ“œκ°€ unlock κ°’κ³Ό μΌμΉ˜ν•˜λŠ”μ§€ 확인
        location.href = "?" + unlock / 10; // μΌμΉ˜ν•  경우 νŽ˜μ΄μ§€ 이동 (query string에 unlock κ°’μ˜ 10λΆ„μ˜ 1 μΆ”κ°€)
    } else {
        alert("Wrong"); // νŒ¨μŠ€μ›Œλ“œκ°€ μΌμΉ˜ν•˜μ§€ μ•Šμ„ 경우 κ²½κ³ μ°½ ν‘œμ‹œ
    }
}
</script> <!-- μžλ°”μŠ€ν¬λ¦½νŠΈ μ½”λ“œ μ’…λ£Œ -->

<whale-quicksearch translate="no"> <!-- ν€΅μ„œμΉ˜ μš”μ†Œ -->
#shadow-root (closed) <!-- μ›λž˜μ˜ DOM 트리 내뢀에 μ ‘κ·Όν•˜λŠ” shadow DOM ν‘œμ‹œ -->
<style></style>
<div class="quicksearch"></div>
</whale-quicksearch> <!-- ν€΅μ„œμΉ˜ μš”μ†Œ μ’…λ£Œ -->
</body>
</html>

 

 

++  unlock λ³€μˆ˜μ— λ“€μ–΄κ°„ 값을 μž…λ ₯λž€μ— λ„£μœΌλ©΄ λ˜λŠ” λ“― ν•˜λ‹€.

4.  Console νƒ­μœΌλ‘œ μ΄λ™ν•˜μ—¬ unlock λ³€μˆ˜κ°’μ„ 확인

console.log(unlock);

 

5.  Console μ—μ„œ 얻은 값을 μž…λ ₯ ν›„ check λ²„νŠΌ 클릭  -->  문제 ν•΄κ²° 성곡