๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
728x90
๋ฐ˜์‘ํ˜•

๐ŸดCTF/webhacking.kr4

webhacking.kr - old-39 view_source ๊ฒฐ๊ณผ sqli ๋ฐฉ์ง€์ฑ… 1 $_POST['id'] = str_replace("\\","",$_POST['id']); ์—ด์Šฌ๋ž˜์‰ฌ ๊ธฐํ˜ธ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†๋‹ค. ๋งŒ์•ฝ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด 'abc\''์ฒ˜๋Ÿผ ๋”ฐ์˜ดํ‘œ๋ฅผ ๋‹ซ์•„ ์šฐํšŒ๊ฐ€ ๊ฐ€๋Šฅํ•ด์งˆ ๊ฒƒ์ด๋‹ค. sqli ๋ฐฉ์ง€์ฑ… 2 $_POST['id'] = str_replace("'","''",$_POST['id']); ๋”ฐ์˜ดํ‘œ (')๋ฅผ ์ž…๋ ฅํ•  ์‹œ ๋”ฐ์˜ดํ‘œ๊ฐ€ ๋‘ ๊ฐœ๊ฐ€ ('') ์จ์ง„๋‹ค. $result = mysqli_fetch_array(mysqli_query($db,"select 1 from member where length(id) 2023. 5. 31.
webhacking.kr - old-04(Challenge 4) ์ฒซ ํ™”๋ฉด์€ ์–ด๋–ค ํ•ด์‹œ๊ฐ’์ด ์จ์ ธ ์žˆ๊ณ  ์•„๋ž˜์—๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ œ์ถœํ•˜๋Š” ๊ณณ์ด ์žˆ๋‹ค. [view-source]๋ฅผ ๋ˆŒ๋Ÿฌ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด ๋ณธ๋‹ค. if((isset($_SESSION['chall4'])) && ($_POST['key'] == $_SESSION['chall4'])) solve(4); ์‚ฌ์šฉ์ž๋กœ ๋ถ€ํ„ฐ key(๋น„๋ฐ€๋ฒˆํ˜ธ)๋ฅผ ์ž…๋ ฅ์„ ๋ฐ›์œผ๋ฉฐ, chall4 ์„ธ์…˜๊ณผ ์ผ์น˜ํ•˜๋ฉด solve(4)๋ฅผ ์‹คํ–‰ํ•œ๋‹ค. ์ œ์ผ ์ค‘์š”ํ•œ ์•„๋žซ๋ถ€๋ถ„์„ ์‚ดํŽด๋ณด๋ฉด $hash = rand(10000000,99999999)."salt_for_you"; 10000000~99999999๊นŒ์ง€์˜ ๋žœ๋ค์˜ ์ •์ˆ˜๋ฅผ ๊ฐ€์ ธ์™€์„œ "salt_for_you"๋ผ๋Š” ์†”ํŠธ๋ฅผ ํ•ฉ์นœ๋‹ค. ๊ทธ๋ž˜์„œ ์ด "๋žœ๋ค์ˆซ์ž_salt_for_you"๋Š” chall4 ์„ธ์…˜์— ํ• ๋‹นํ•œ๋‹ค. for($i=0.. 2023. 2. 15.
webhacking.kr - old-20(Challenge 20) 2์ดˆ ์•ˆ์— ๋‹‰๋„ค์ž„, ์ฝ”๋ฉ˜ํŠธ, ์บก์ฑ  ํผ์„ ์ฑ„์šฐ๊ณ  ๋ณด๋‚ด์ง€ ์•Š์œผ๋ฉด "Too Slow..."๋ผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜ค๋ฉด์„œ ๋‹ค์‹œ ์ž…๋ ฅ ํŽ˜์ด์ง€๋กœ ๋ฆฌ๋‹ค์ด๋ ‰์…˜ ๋œ๋‹ค. (function() { 'use strict'; document.querySelector("[name='id']").value="test"; document.querySelector("[name='cmt']").value="hello!"; lv5frm.captcha.value = lv5frm.captcha_.value; ck(); })(); ๋‚˜ ๊ฐ™์€ ๊ฒฝ์šฐ๋Š” ๋ธŒ๋ผ์šฐ์ € ํ™•์žฅ ๋„๊ตฌ๋ฅผ ํ†ตํ•ด์„œ ํ•ด๋‹น ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•Œ์•„์„œ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋˜๊ฒŒ ๋งŒ๋“ค์—ˆ๋‹ค. ๊ทธ๋žฌ๋”๋‹ˆ ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ฉด ์ˆœ์‹๊ฐ„์— ์ž…๋ ฅ ํ›„ ์ œ์ถœ์ด ๋˜๋ฉด์„œ ํ•ด๊ฒฐ์ด ๋˜์—ˆ๋‹ค. 2023. 2. 15.
webhacking.kr - old-11(Challenge 11) view-source view-source ์‚ฌ์šฉ์ž๋กœ๋ถ€ํ„ฐ val์ด๋ผ๋Š” ์ด๋ฆ„์˜ GET ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์ž…๋ ฅ๋ฐ›๋Š”๋‹ค, ๋งŒ์•ฝ์— ์•„๋ž˜์˜ ์ •๊ทœํ‘œํ˜„์‹์— ์ฐธ์˜ ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์˜ค๋ฉด ์ •๋‹ต์ฒ˜๋ฆฌ /[1-3][a-f]{5}_.*$_SERVER[REMOTE_ADDR].*\tp\ta\ts\ts/ $_SERVER[REMOTE_ADDR]๋Š” ์ ‘์†์ž์˜ ์•„์ดํ”ผ๋ฅผ ๊ฐ€์ ธ์˜ค๊ธฐ ๋•Œ๋ฌธ์— ์•„์ดํ”ผ ํ™•์ธ ์‚ฌ์ดํŠธ(https://ip.pe.kr/ )์—์„œ ์ž์‹ ์˜ ์ฃผ์†Œ๋ฅผ ์ฐพ๊ณ , ๋‚˜๋จธ์ง€ ์ •๊ทœํ‘œํ˜„์‹๋“ค์ด ๋งŒ์กฑํ•˜๊ฒŒ๋” ๊ฐ’์„ ์ถ”๊ฐ€ํ•˜๋ฉด ๋œ๋‹ค. ์•„๋ž˜์˜ ์—ฐ์Šต ์‚ฌ์ดํŠธ์—์„œ ์ •๊ทœํ‘œํ˜„์‹ ์กฐ๊ฑด์„ ๋„ฃ์–ด์„œ ์ง์ ‘ ํ™•์ธํ•ด ๋ณด์•˜๋‹ค. https://regexr.com/ RegExr: Learn, Build, & Test RegEx RegExr is an online tool to learn, build, &.. 2023. 2. 15.
728x90
๋ฐ˜์‘ํ˜•