SWLUG/์›น ํ•ดํ‚น

[Root Me] HTTP - COOKIES

waterproof 2023. 9. 23. 19:10

https://www.root-me.org/en/Challenges/Web-Server/HTTP-Cookies?debut_dernieres_validations=30&lang=#pagination_dernieres_validations 

 

Challenges/Web - Server : HTTP - Cookies [Root Me : Hacking and Information Security learning platform]

TCP - Back to school just blocks when i try to read the flag after i have sent the calculation. Not sure if my calculation is wrong or what is is?

www.root-me.org

 

 

 


https://chrome.google.com/webstore/detail/editthiscookie/fngmhnnpilhplaeedifhccceomclgfbg?hl=ko

 

EditThisCookie

EditThisCookie๋Š” ์ฟ ํ‚ค ๊ด€๋ฆฌ์ž์ž…๋‹ˆ๋‹ค. ์ด๊ฒƒ์„ ์ด์šฉํ•˜์—ฌ ์ฟ ํ‚ค๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ , ์‚ญ์ œํ•˜๊ณ , ํŽธ์ง‘ํ•˜๊ณ , ์ฐพ๊ณ , ๋ณดํ˜ธํ•˜๊ฑฐ๋‚˜ ๋ง‰์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค!

chrome.google.com

๋ฌธ์ œ ํ’€์ด ์ด์ „์—, EditthisCookie๋ฅผ ์„ค์น˜ํ•ด์ฃผ์—ˆ๋‹ค.

์œ„์˜ ๋งํฌ์— ๋“ค์–ด๊ฐ€๋ฉด EditthisCookie ๊ฐ€ ๋ฌด์—‡์ธ์ง€ ์†Œ๊ฐœ๊ฐ€ ๋‚˜์™€์žˆ๋Š”๋ฐ,

EditthisCookie๋Š” ์ฟ ํ‚ค ํŽธ์ง‘, ์ฟ ํ‚ค ์‚ญ์ œ, ์ƒˆ ์ฟ ํ‚ค ์ถ”๊ฐ€, ์ฟ ํ‚ค ๋งŒ๋“ค๊ธฐ, ์ฟ ํ‚ค ๊ฒ€์ƒ‰ ๋“ฑ์˜ ๊ธฐ๋Šฅ์„ ํ•˜๋Š” ํ™•์žฅ ํ”„๋กœ๊ทธ๋žจ์ด๋‹ค.

 

 

 

 

 

 

 

 

Root Me์˜ HTTP - Cookies ๋ฌธ์ œ๋ฅผ ํ’€์–ด๋ณด๊ฒ ๋‹ค.

Start the challange ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๋ฉด ๋ฌธ์ œ ํ’€์ด๋ฅผ ์‹œ์ž‘ํ•œ๋‹ค.

 

 

 

 

์ฒ˜์Œ ํ™”๋ฉด์ด๋‹ค.

์ด๋ฉ”์ผ์„ ๋„ฃ์„ ์ˆ˜ ์žˆ๋Š” ์นธ์ด ์žˆ๊ณ , send ๋ฒ„ํŠผ์ด ์žˆ๋‹ค.

๊ทธ ์•„๋ž˜์—๋Š” "Saved email adresses" ๋ผ๊ณ  ๋งํฌ๊ฐ€ ์—ฐ๊ฒฐ๋œ ๋ฌธ๊ตฌ๊ฐ€ ์žˆ๋‹ค.

 

 

 

 

๊ถ๊ธˆํ•ด์„œ "Saved email adresses" ๋ฅผ ๋ˆŒ๋Ÿฌ๋ณด์•˜๋‹ค.

 

๋ˆ„๋ฅด๊ธฐ ์ „์˜ ํŽ˜์ด์ง€์™€ ๋‹ฌ๋ผ์ง„ ์  ๋‘ ๊ฐ€์ง€๊ฐ€ ์žˆ์—ˆ๋Š”๋ฐ,

1. "You need to be admin" ์ด๋ผ๋Š” ๋ฌธ๊ตฌ๊ฐ€ ์ƒ๊ฒผ๊ณ 

2. http://challenge01.root-me.org/web-serveur/ch7/?c=visiteur ์ด ์ฃผ์†Œ์˜ ์›นํŽ˜์ด์ง€๋กœ ์ด๋™ํ–ˆ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค.

 

 "?c=visiteur" ๋Š” ์ฟผ๋ฆฌ ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ, "c"๋ผ๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ์˜ ๊ฐ’์œผ๋กœ "visiteur"๊ฐ€ ์„ค์ •๋˜์–ด ์žˆ๋‹ค.

 "You need to be admin" ์—์„œ admin์ด์–ด์•ผ ํ•œ๋‹ค๊ณ  ํ–ˆ์œผ๋‹ˆ, ์ฃผ์†Œ ๋’ท๋ถ€๋ถ„์„ ?c=admin์œผ๋กœ ๋ฐ”๊ฟ”์ฃผ๊ฒ ๋‹ค.

 

 

 

 

์ฃผ์†Œ ๋’ท๋ถ€๋ถ„์„ ?c=admin ์œผ๋กœ ๋ฐ”๊ฟ”์ฃผ์—ˆ๋”๋‹ˆ

"Problem with cookie"๋ผ๋Š” ๋ฌธ๊ตฌ๊ฐ€ ๋‚˜ํƒ€๋‚ฌ๋‹ค.

์ฟ ํ‚ค์— ๋ฌธ์ œ๊ฐ€ ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค!

 

 

 

 

ํŽ˜์ด์ง€ ์œ„์—์„œ ๋งˆ์šฐ์Šค ์šฐํด๋ฆญ์„ ํ•ด์„œ Editthiscookie๋ฅผ ์‹คํ–‰ํ•˜์˜€๋‹ค.

 

 

 

 

 

์ฟ ํ‚ค๋ฅผ ํ™•์ธํ•ด์ฃผ์—ˆ๋‹ค.

์ฟ ํ‚ค์˜ ๊ฐ’์ด "visiteur" ๋กœ ์„ค์ •๋˜์–ด ์žˆ์—ˆ๋‹ค.

 

 

 

 

"You need to be admin"์ด๋ผ๋Š” ๋ฌธ๊ตฌ๋ฅผ ๋– ์˜ฌ๋ ค visitueradmin ์œผ๋กœ ๋ฐ”๊ฟ”์ค€๋‹ค.

์ดˆ๋ก์ƒ‰ ์ฒดํฌ ๋ฒ„ํŠผ์„ ๋ˆ„๋ฅด๊ณ  ์ƒˆ๋กœ๊ณ ์นจ์„ ํ•ด์ค€๋‹ค.

 

 

 

 

 

๊ทธ๋ฆฌ๊ณ ๋‚˜์„œ ๋ฌธ์ œ ํ’€์ด ํ™”๋ฉด์œผ๋กœ ๋‹ค์‹œ ๋Œ์•„๊ฐ€ ์ƒˆ๋กœ๊ณ ์นจ์„ ํ•˜๋ฉด

์œ„์™€ ๊ฐ™์ด ํ™”๋ฉด์ด ๋ฐ”๋€๋‹ค.

 

 

 

 

 

Validation password๋ฅผ ์“ฐ๋Š” ์นธ์— "ml-SYMPA"๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋œ๋‹ค.

 

 

 

 

 

์ •๋‹ต! 

'SWLUG > ์›น ํ•ดํ‚น' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[webhacking.kr] old-12๋ฒˆ  (0) 2023.09.27
[Root Me] Javascript - Webpack  (0) 2023.09.26
[Root Me] Javascript - Authentication 2  (0) 2023.09.23
[webhacking.kr] old-19๋ฒˆ  (0) 2023.09.19
[webhacking.kr] old-42๋ฒˆ  (0) 2023.09.18