Home
1unaram
Cancel

[Wargame] Webhacking.kr old-61 (SQL Injection)

๐Ÿšฉ ๋ฌธ์ œ ํŒŒ์•… ๋ฌธ์ œ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด view-source ์ด์™ธ์—๋Š” ๋‹ค๋ฅธ ์š”์†Œ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์—†๋‹ค. ๋งํฌ๋ฅผ ํด๋ฆญํ•˜์—ฌ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์ž. // id ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋ฐ›์•„ addslashes ํ•จ์ˆ˜๋ฅผ ํ†ตํ•ด ๋ฌธ์ž์—ด ์ด์Šค์ผ€์ดํ”„ $_GET['id'] = addslashes($_GET['id']); // ๋ฌธ์ž์—ด ์ •๊ทœ์‹ ๊ฒ€์‚ฌ if(preg_match("...

[Wargame] Webhacking.kr old-42 (Base64)

๐Ÿšฉ ๋ฌธ์ œ ํŒŒ์•… ๋ฌธ์ œ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํ‘œ์™€ ํ•จ๊ป˜ ํ•ด๋‹น ํŒŒ์ผ๋“ค์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ๋“ฏํ•œ ๋งํฌ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ํ•˜๋‚˜์”ฉ ๋งํฌ๋ฅผ ํด๋ฆญํ•ด๋ณด๋ฉด, test.txt ํŒŒ์ผ์€ ์ •์ƒ์ ์œผ๋กœ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์•„์ง€๋Š” ๋ฐ˜๋ฉด์—, flag.docx ํŒŒ์ผ์€ Access Denied ์ฐฝ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ๐Ÿšฉ ๋ฌธ์ œ ํ’€์ด ๋ฌธ์ œ ํŽ˜์ด์ง€์— ๋Œ€ํ•œ ์š”์ฒญ ํ›„...

[Wargame] Webhacking.kr old-39 (SQL Injection)

๐Ÿšฉ ๋ฌธ์ œ ํŒŒ์•… ๋ฌธ์ œ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ํšŒ์›๊ฐ€์ž…๊ณผ ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ๋Š” ํผ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด JOIN ์‹œ ID๋Š” id, PHONE์€ phone์˜ name์„ ๊ฐ€์ง€๊ณ , LOGIN์‹œ ID๋Š” lid, PHONE์€ lphone์˜ name์„ ๊ฐ€์ง€๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. view-source๋ฅผ ํ†ตํ•ด ํ”„๋กœ๊ทธ๋žจ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์ž. ...

[Wargame] Over The Wire - Bandit

OverTheWire - Bandit Bandit Site: https://overthewire.org/wargames/bandit/ Environment: WSL2 Ubuntu 20.04.4 LTS Host: bandit.labs.overthewire.org Port: 2220 ssh bandit0@bandit.labs.overth...

๐Ÿšฉ์ œ 1ํšŒ IxC CTF ์šด์˜ ํ›„๊ธฐ๐Ÿšฉ

# ๊ธ€์„ ์‹œ์ž‘ํ•˜๋ฉฐ ย ์•„์ง ์—ฐ์ดˆ์ด์ง€๋งŒ ๋ฒŒ์จ๋ถ€ํ„ฐ ํฐ ์ด๋ฒคํŠธ ํ•˜๋‚˜๊ฐ€ ์ง€๋‚˜๊ฐ”์Šต๋‹ˆ๋‹ค,, ์ •๋ณด๋ณด์•ˆ์„ ๊ณต๋ถ€ํ•˜๋Š” ์‚ฌ๋žŒ์ด๋ผ๋ฉด ํ•œ ๋ฒˆ์ฏค ๋“ค์–ด๋ดค์„ CTF ๋Œ€ํšŒ๋ฅผ ์ง์ ‘ ๊ฐœ์ตœํ•˜์—ฌ ๋ฌธ์ œ ์ œ์ž‘๋ถ€ํ„ฐ ๋Œ€ํšŒ ์šด์˜๊นŒ์ง€ ๋ชจ๋‘ ๋งก์•„ ์ง„ํ–‰ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ๋Œ€ํšŒ๋ฅผ zero๋ถ€ํ„ฐ ์‹œ์ž‘ํ•˜์—ฌ ๋งˆ์น˜๊ธฐ๊นŒ์ง€ ์ €์—๊ฒŒ๋Š” ํฐ ์—…์ ์ด๋ผ๊ณ  ์ƒ๊ฐํ•˜๊ธฐ๋„ ํ•˜์˜€๊ณ , CTF ์šด์˜์„ ํ•˜๋ฉฐ ์—ฌ๋Ÿฌ ๋ธ”๋กœ๊ทธ์™€ ๊ธ€๋“ค์„ ์ฐธ๊ณ ํ•˜์˜€์ง€...

[Wargame] Webhacking.kr Write-Ups

๐Ÿšฉ old-01 ๋ฌธ์ œ ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํ™”๋ฉด์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. view-source๋ฅผ ๋ˆŒ๋Ÿฌ ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์ž. <?php include "../../config.php"; if($_GET['view-source'] == 1){ view_source(); } if(!$_COOKIE['user_lv']){ Set...

[Study] Content Security Policy

Dreamhack - Web Hacking Advanced (Client Side) ๋ฅผ ๊ณต๋ถ€ํ•˜๋ฉฐ ์ •๋ฆฌํ•˜์˜€์Šต๋‹ˆ๋‹ค. # Content Security Policy Background ์›น ๋ธŒ๋ผ์šฐ์ €๋Š” ์›น ์„œ๋ฒ„๋กœ๋ถ€ํ„ฐ ๋ฐ›๋Š” ์ปจํ…์ธ ๊ฐ€ ์˜๋„๋œ ์ปจํ…์ธ ์ธ์ง€ ํ™•์ธํ•  ์ˆ˜ ์—†๊ธฐ์—, ํŽ˜์ด์ง€์˜ ์ปจํ…์ธ ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์ž์›๋“ค์ด ๋ชจ๋‘ ์›น ์„œ๋ฒ„์—์„œ ์˜๋„ํ•œ ์ž์›์ด ๋งž๋Š”...

[Study] XSS Filtering Bypass

๐Ÿ’ก [Dreamhack] Web Hacking Advanced - Client Side - XSS Filterfing Bypass I, II๋ฅผ ๊ณต๋ถ€ํ•˜๋ฉฐ ์ •๋ฆฌํ•˜์˜€์Šต๋‹ˆ๋‹ค. #1. ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ ์†์„ฑ ํƒœ๊ทธ์˜ ์†์„ฑ ๊ฐ’์œผ๋กœ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํฌํ•จํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ๊ฐ€ ์กด์žฌํ•œ๋‹ค. ๋Œ€ํ‘œ์ ์œผ๋กœ ์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ๋ฅผ ์ง€์ •ํ•˜๋Š” on์œผ๋กœ ์‹œ์ž‘ํ•˜๋Š” ์†์„ฑ๋“ค์ด ์กด์žฌํ•œ๋‹ค. ...

[Certificate] ์ธํ„ฐ๋„ท๋ณด์•ˆ์ „๋ฌธ๊ฐ€ 2๊ธ‰ ํ•„๊ธฐ ๊ธฐ์ถœ๋ฌธ์ œ ์ •๋ฆฌ

์ •๋ฆฌ ๋Œ€์ƒ ๊ธฐ์ถœ ๋ฌธ์ œ ๋ชฉ๋ก 2022๋…„ 04์›” 10์ผ 2021๋…„ 10์›” 24์ผ 2021๋…„ 04์›” 11์ผ 2020๋…„ 10์›” 25์ผ 2020๋…„ 05์›” 24์ผ 2019๋…„ 10์›” 27์ผ 2019๋…„ 04์›” 14์ผ 2018๋…„ 10์›” 28์ผ 2018๋…„ 04์›” 08์ผ 1๊ณผ๋ชฉ: ์ •...

[Study] Stack All-in-One

#0. Intro ์‹œ์Šคํ…œ ํ•ดํ‚น์„ ๊ณต๋ถ€ํ•˜๋ฉด์„œ BOF, Stack Buffer Overflow, ROP ๋“ฑ์˜ ๊ฐœ๋…์„ ๊ณต๋ถ€ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” Stack์˜ ๊ตฌ์กฐ์™€ ๋™์ž‘ ๊ณผ์ •์„ ์ •ํ™•ํ•˜๊ฒŒ ์ดํ•ดํ•ด์•ผ ํ•จ์„ ํ†ต๊ฐํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ํฌ์ŠคํŠธ์—์„œ๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ๋™์ž‘ํ•˜๋ฉฐ Stack์ด ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉ๋˜๋Š”์ง€๋ฅผ Assebly, Register, Endian๋“ฑ์˜ ๋‚ด์šฉ์„ ํฌํ•จํ•˜์—ฌ ์ž์„ธํ•˜๊ฒŒ ๊ธฐ...