๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

Web Hacking4

[Dreamhack] Simple-web-request ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿฟ Simple-web-request ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ app.py ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ #!/usr/bin/python3 import os from flask import Flask, request, render_template, redirect, url_for import sys app = Flask(__name__) try: # flag is here! FLAG = open("./flag.txt", "r").read() except: FLAG = "[**FLAG**]" @app.route("/") def index(): return render_template("index.html") @app.route("/step1",.. 2023. 8. 17.
[Dreamhack] Web-Deserialize-Python ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿฆ Web-Deserialize-Python ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ app.py ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ 2 - 1. ํ•„์š”ํ•œ ํ”„๋ ˆ์ž„์›Œํฌ์™€ ๋ชจ๋“ˆ ๊ฐ€์ ธ์˜ค๊ธฐ #!/usr/bin/env python3 from flask import Flask, request, render_template, redirect import os, pickle, base64 ์ฝ”๋“œ ์„ค๋ช… Flask ํ”„๋ ˆ์ž„์›Œํฌ ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐœ๋ฐœ ๋ฐ ์‹คํ–‰์— ํ•„์š” OS ๋ชจ๋“ˆ ์šด์˜์ฒด์ œ ๊ด€๋ จ ๊ธฐ๋Šฅ ์ˆ˜ํ–‰ Pickle Python ๊ฐ์ฒด ์ง๋ ฌํ™” & ์—ญ์งˆ๋ ฌํ™” Base64 ๋ฐ์ดํ„ฐ์˜ Base64 ํ˜•์‹ ์ธ์ฝ”๋”ฉ & ๋””์ฝ”๋”ฉ 2 - 2. Flask ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ฐ ์‹œํฌ๋ฆฟ ํ‚ค ์ƒ์„ฑ app = Flask(__n.. 2023. 8. 15.
[Dreamhack] Command-Injection-ChatGPT ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐ŸŽ Command-Injection-ChatGPT ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ์„œ๋ฒ„ ์ƒ์„ฑ 2. ์ƒ์„ฑ๋œ ๋งํฌ๋กœ ์ ‘์† ํ›„ Ping ๋ฉ”๋‰ด๋กœ ์ด๋™ 3. ์ž…๋ ฅ๋ž€์— ์•„๋ฌด ๊ฐ’์ด๋‚˜ ์ž…๋ ฅ --> Error ๋ฌธ์ด ์ถœ๋ ฅ๋˜๋ฉฐ ๋ช…๋ น์–ด ํ˜•์‹ ํ™•์ธ ๊ฐ€๋Šฅ 4. ; ls ๋ฅผ ์ž…๋ ฅ๋ž€์— ๋„ฃ๊ณ  Ping! ํด๋ฆญ --> ์กด์žฌํ•˜๋Š” ํŒŒ์ผ ๋ชฉ๋ก ํ™•์ธ ๊ฐ€๋Šฅ 5. cat ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ flag.py ํŒŒ์ผ ์—ด๊ธฐ --> FLAG ํ™•์ธ ๊ฐ€๋Šฅ 2023. 8. 15.
[Dreamhack] Session ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐ŸŽž๏ธ Session ๋“œ๋ฆผํ•ต ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ์ฝ์€ ํ›„ ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋‹ค์šด๋ฐ›์€ app.py ํŒŒ์ผ ์˜คํ”ˆ ํ›„ ์ฝ”๋“œ ๋ถ„์„ #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for app = Flask(__name__) try: FLAG = open('./flag.txt', 'r').read() except: FLAG = '[**FLAG**]' ์ฝ”๋“œ ์„ค๋ช… from flask import Flask, request, render_template, make_response, redirect, url_for ์›น ์„œ๋ฒ„ ์ƒ์„ฑ, ์š”์ฒญ ์ฒ˜๋ฆฌ, ํ…œํ”Œ๋ฆฟ ๋ Œ๋”๋ง ๋“ฑ์— ํ•„.. 2023. 8. 12.