Home
1unaram
Cancel

[Wargame] Webhacking.kr Write-Ups

๐Ÿšฉ old-01 ๋ฌธ์ œ ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. view-source๋ฅผ ๋ˆŒ๋Ÿฌ ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์ž. <?php include "../../config.php"; if($_GET['view-source'] == 1){ view_source(); } if(!$_COOKIE['user_lv']){ Set...

[Study] Content Security Policy

Dreamhack - Web Hacking Advanced (Client Side) ๋ฅผ ๊ณต๋ถ€ํ•˜๋ฉฐ ์ •๋ฆฌํ•˜์˜€์Šต๋‹ˆ๋‹ค. # Content Security Policy Background ์›น ๋ธŒ๋ผ์šฐ์ €๋Š” ์›น ์„œ๋ฒ„๋กœ๋ถ€ํ„ฐ ๋ฐ›๋Š” ์ปจํ…์ธ ๊ฐ€ ์˜๋„๋œ ์ปจํ…์ธ ์ธ์ง€ ํ™•์ธํ•  ์ˆ˜ ์—†๊ธฐ์—, ํŽ˜์ด์ง€์˜ ์ปจํ…์ธ ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์ž์›๋“ค์ด ๋ชจ๋‘ ์›น ์„œ๋ฒ„์—์„œ ์˜๋„ํ•œ ์ž์›์ด ๋งž๋Š”...

[Study] XSS Filtering Bypass

๐Ÿ’ก [Dreamhack] Web Hacking Advanced - Client Side - XSS Filterfing Bypass I, II๋ฅผ ๊ณต๋ถ€ํ•˜๋ฉฐ ์ •๋ฆฌํ•˜์˜€์Šต๋‹ˆ๋‹ค. #1. ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ ์†์„ฑ ํƒœ๊ทธ์˜ ์†์„ฑ ๊ฐ’์œผ๋กœ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํฌํ•จํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ๊ฐ€ ์กด์žฌํ•œ๋‹ค. ๋Œ€ํ‘œ์ ์œผ๋กœ ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ๋ฅผ ์ง€์ •ํ•˜๋Š” on์œผ๋กœ ์‹œ์ž‘ํ•˜๋Š” ์†์„ฑ๋“ค์ด ์กด์žฌํ•œ๋‹ค. ...

[Certificate] ์ธํ„ฐ๋„ท๋ณด์•ˆ์ „๋ฌธ๊ฐ€2๊ธ‰ ๊ธฐ์ถœ๋ฌธ์ œ ์ •๋ฆฌ

์ •๋ฆฌ ๋Œ€์ƒ ๊ธฐ์ถœ ๋ฌธ์ œ ๋ชฉ๋ก 2022๋…„ 04์›” 10์ผ 2021๋…„ 10์›” 24์ผ 2021๋…„ 04์›” 11์ผ 2020๋…„ 10์›” 25์ผ 2020๋…„ 05์›” 24์ผ 2019๋…„ 10์›” 27์ผ 2019๋…„ 04์›” 14์ผ 2018๋…„ 10์›” 28์ผ 2018๋…„ 04์›” 08์ผ 1๊ณผ๋ชฉ: ์ •...

[Study] Stack All-in-One

#0. Intro ์‹œ์Šคํ…œ ํ•ดํ‚น์„ ๊ณต๋ถ€ํ•˜๋ฉด์„œ BOF, Stack Buffer Overflow, ROP ๋“ฑ์˜ ๊ฐœ๋…์„ ๊ณต๋ถ€ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” Stack์˜ ๊ตฌ์กฐ์™€ ๋™์ž‘ ๊ณผ์ •์„ ์ •ํ™•ํ•˜๊ฒŒ ์ดํ•ดํ•ด์•ผ ํ•จ์„ ํ†ต๊ฐํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ํฌ์ŠคํŠธ์—์„œ๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ๋™์ž‘ํ•˜๋ฉฐ Stack์ด ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉ๋˜๋Š”์ง€๋ฅผ Assebly, Register, Endian๋“ฑ์˜ ๋‚ด์šฉ์„ ํฌํ•จํ•˜์—ฌ ์ž์„ธํ•˜๊ฒŒ ๊ธฐ...

[Dreamhack] Background - Computer Science

๐Ÿ”ธ Linux Memory Layout [Study]Memory Layout Quiz: Linux Memory Layout #include <stdlib.h> int a = 0xa; const char b[] = "d_str"; int c; int foo(int arg) { int d = 0xd; return 0; } i...

[H4CKING GAME] REV - Keygen

# ๋ฌธ์ œ ํŒŒ์•… ๋ฌธ์ œ์—์„œ ์ฃผ์–ด์ง„ keygen.exe ํŒŒ์ผ์„ ์‹คํ–‰ํ•ด๋ณด๋‹ˆ ์•Œ๋งž์€ flag๋ฅผ ์ž…๋ ฅํ•ด์•ผ ํ•จ์„ ์•Œ ์ˆ˜ ์žˆ์—ˆ๋‹ค. IDA๋ฅผ ์ด์šฉํ•˜์—ฌ ์‹คํ–‰ ํŒŒ์ผ์„ ์—ด์–ด๋ณด์•˜๋‹ค. main ํ•จ์ˆ˜๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์—ˆ๊ณ , ๊ทธ๋ž˜ํ”„์—์„œ โ€œInput flag : โ€œ, โ€œNoโ€ฆ This is not flagโ€ฆโ€ ๋“ฑ์˜ ๋ฌธ์ž์—ด์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. ๋‹คํ–‰ํžˆ๋„ ๋””์ปดํŒŒ์ผ...

[Study] Shell Metacharacter

๋ฉ”ํƒ€ ๋ฌธ์ž(Shell Metacharacter) ๋ฉ”ํƒ€ ๋ฌธ์ž ์„ค๋ช… ~ ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ . ํ˜„์žฌ ๋””๋ ‰ํ† ๋ฆฌ .. ์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ # ์ฃผ์„ ...

[Study] Objdump Opcode ์ถ”์ถœ ๋ช…๋ น์–ด

for i in $(objdump -d [file] | grep "^ " | cut -f 2); do echo -n \\x$i; done for i in $( ) : $( ) ๋‚ด์˜ ๋ช…๋ น์„ ์‹คํ–‰ํ•œ ๊ฐ’์„ ๋ฐ˜๋ณตํ•˜์—ฌ i๋กœ ์ ‘๊ทผ objdump -d [file_path] : [file] ๊ฒฝ๋กœ์˜ ์˜ค๋ธŒ์ ํŠธ ํŒŒ์ผ์„ ๊ธฐ๊ณ„์–ด๋กœ ์—ญ์–ด์…ˆ๋ธ” grep "^ " ...

[Study] pwntools & pwndbg

pwntools์™€ pwndbg๋ฅผ ์‚ฌ์šฉํ•˜๋ฉฐ ๊ณต๋ถ€ํ•˜๋Š” ๋‚ด์šฉ์„ ๊ณ„์† ์—…๋ฐ์ดํŠธ ํ•  ์˜ˆ์ •์ž…๋‹ˆ๋‹ค Reference : Dreamhack - [Tool: pwntools] # pwntools ๐Ÿ”Ž pwntools๋ž€? : ์‹œ์Šคํ…œ ํ•ดํ‚น์„ ์ˆ˜ํ–‰ํ•˜๋ฉฐ ์ž์ฃผ ์‚ฌ์šฉํ•˜๋Š” ํ•จ์ˆ˜๋“ค์„ ๊ตฌํ˜„ ํ•ด๋†“์€ ํŒŒ์ด์ฌ ๋ชจ๋“ˆ ๐Ÿ”ง pwntools ์„ค์น˜ & import # p...