๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

webhakcing.kr3

[Webhacking.kr] old-53 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ”ญ old-53 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ 2023. 8. 31.
[Webhacking.kr] old-39 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿท old-39 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ 2023. 8. 30.
[Webhacking.kr] old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด ๐Ÿ›ผ old-11 ์›Œ๊ฒŒ์ž„ ๋ฌธ์ œ ํ’€์ด 1. ๋ฌธ์ œ ํ™”๋ฉด์œผ๋กœ ๋“ค์–ด๊ฐ€ view-source ํด๋ฆญ 2. ์ฝ”๋“œ ๋ถ„์„๊ณผ ํ•จ๊ป˜ ๋ฌธ์ œ ํ’€์ด ์กฐ๊ฑด ํƒ์ƒ‰ view-source ++ Line 15์˜ ์ •๊ทœํ‘œํ˜„์‹ ์ •์˜์— ์ฃผ๋ชฉ $pat="/[1-3][a-f]{5}_.*$_SERVER[REMOTE_ADDR].*\tp\ta\ts\ts/"; ์ฝ”๋“œ ์˜๋ฏธ [1-3] 1๋ถ€ํ„ฐ 3 ์‚ฌ์ด์˜ ์ˆซ์ž๋กœ ์‹œ์ž‘ [a-f]{5} ์•ŒํŒŒ๋ฒณ a๋ถ€ํ„ฐ f๊นŒ์ง€์˜ ๋ฌธ์ž ์ค‘ ๋™์ผํ•œ 5๊ฐœ๊ฐ€ ์—ฐ์†์œผ๋กœ ์œ„์น˜ .*$_SERVER[REMOTE_ADDR].* ์‚ฌ์šฉ์ž์˜ IP ์ฃผ์†Œ ํฌํ•จ \tp\ta\ts\ts ํƒญ ๋ฌธ์ž๋กœ ๊ตฌ๋ถ„๋˜๋Š” "ptass" ๋ฌธ์ž์—ด ํฌํ•จ --> ์œ„ 4๊ฐœ์˜ ์กฐ๊ฑด์„ ๋งŒ์กฑํ•œ ๋ฌธ์ž์—ด์„ $_GET['val'] ์— ์ „๋‹ฌํ•ด์•ผ ํ•จ 3. ์œ„์˜ ์กฐ๊ฑด์— ์œ ์˜ํ•˜๋ฉฐ ๋ฌธ์ž์—ด ์ž‘์„ฑ val = 2.. 2023. 8. 26.