SWLUG/์›น ํ•ดํ‚น 32

[Dreamhack/๋“œ๋ฆผํ•ต] csrf-1

https://dreamhack.io/wargame/challenges/26 csrf-1 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. CSRF ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.07.18 css, html ์ œ๊ณต ๋ฐ read_url() ์ฝ”๋“œ ์ผ๋ถ€๊ฐ€ ๋ณ€๊ฒฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Referen dreamhack.io [1] ๋ฌธ์ œ ๋ถ„์„ # ๋ฌธ์ œ ํŽ˜์ด์ง€ ๋ถ„์„ (1) ์ดˆ๊ธฐ ํ™”๋ฉด (Home) (1) /vuln(csrf) page script ๊ฐ€ *๋กœ ์น˜ํ™˜๋˜์–ด์žˆ๋‹ค. /script๋Š” ์ œ๊ฑฐ๋˜์—ˆ๋‹ค. ์†Œ์Šค ์ฝ”๋“œ์—์„œ๋Š” ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ด ์—†์—ˆ๋‹ค. (2) /memo URL์„ ๋ณด๋ฉด /memo ํŽ˜์ด์ง€์—์„œ memo ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ hello๋ฅผ ๋ฐ›์•„๋“ค์—ฌ์„œ ํŽ˜์ด์ง€ ํ™”๋ฉด์— ์ถœ๋ ฅํ•˜๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์ฆ‰ ..

[Dreamhack/๋“œ๋ฆผํ•ต] XSS Filtering Bypass

https://dreamhack.io/wargame/challenges/433 XSS Filtering Bypass Description Exercise: XSS Filtering Bypass์—์„œ ์‹ค์Šตํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.04 Dockerfile ์ œ๊ณต dreamhack.io ๋ฌธ์ œ ์ œ๋ชฉ์„ ๋ณด์•„ํ•˜๋‹ˆ, xss ํ•„ํ„ฐ๋ง์„ ์šฐํšŒํ•ด์„œ ํ‘ธ๋Š” ๋ฌธ์ œ์ธ ๊ฒƒ ๊ฐ™๋‹ค. ์ผ๋‹จ ๋ฌธ์ œ ์›นํŽ˜์ด์ง€๋ฅผ ๋ถ„์„ํ•˜๊ณ , ๊ทธ ๋‹ค์Œ์— ๋ฐ›์€ ๋ฌธ์ œ ํŒŒ์ผ๋„ ๋ถ„์„ํ•ด๋ณด๋„๋ก ํ•˜๊ฒ ๋‹ค. [1] ๋ฌธ์ œ ๋ถ„์„ # ๋ฌธ์ œ ํŽ˜์ด์ง€ ๋ถ„์„ ์ดˆ๊ธฐ ํ™”๋ฉด์ด๋‹ค. (1) /vuln(xss) page /vuln(xss) page ๋ฅผ ๋“ค์–ด๊ฐ€๋ณด๋ฉด ๋‚˜์˜ค๋Š” ํ™”๋ฉด. ํƒœ๊ทธ๊ฐ€ ์‚ฌ์šฉ๋˜์—ˆ๋‹ค. src๋Š” ์ด๋ฏธ์ง€ ํŒŒ์ผ์˜ URL์„ ์ง€์ •ํ•˜๊ณ , ๋”ฐ๋ผ์„œ ์›น ํŽ˜์ด์ง€์—์„œ ํ•ด๋‹น https://dr..

[webhacking.kr] Challenge old-23

[1] ๋ฌธ์ œ ํƒ์ƒ‰ ๋ฌธ์ œ ํ™”๋ฉด์ด๋‹ค. ๋‚ด ๋ฏธ์…˜์€ ๋ฌธ์ œ์—์„œ ์ œ๊ณตํ•˜๋Š” ์›นํŽ˜์ด์ง€์—์„œ ์ œ๊ณตํ•˜๋Š” ์ž…๋ ฅ ์นธ์—, ๋ฅผ ์‚ฝ์ž…ํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์‰ฝ๊ฒŒ ๋˜์ง€ ์•Š์œผ๋‹ˆ๊นŒ ๋ฌธ์ œ์ผ ๊ฒƒ์ด๊ณ , ์•„๋งˆ ์ž…๋ ฅ๋ฐ›์€ ์Šคํฌ๋ฆฝํŠธ ํƒœ๊ทธ๋ฅผ ํ•„ํ„ฐ๋งํ•˜๋Š” ๋“ฑ์˜ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์„๊นŒ ์‹ถ๋‹ค. ๋‹ค๋ฅธ ์ทจ์•ฝ์ ์„ ์ฐพ์•„๋‚ด๋Š” ๊ฒƒ์ด ๋ฌธ์ œ์˜ ํ•ต์‹ฌ์ผ ๊ฒƒ ๊ฐ™๋‹ค. # ๋ฌธ์ œ ํŽ˜์ด์ง€ ์†Œ์Šค์ฝ”๋“œ ๋ถ„์„ ๋ถ„์„ (1) ์š”์†Œ์˜ method ์†์„ฑ์€ ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ์„œ๋ฒ„์— ์ „์†กํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ง€์ •ํ•˜๋Š”๋ฐ, ์˜ต์…˜ ์ค‘ ํ•˜๋‚˜๋กœ GET ๋ฐฉ์‹์ด ์žˆ๋‹ค. GET ๋ฐฉ์‹์€ ์ž…๋ ฅํ•œ ๋ฐ์ดํ„ฐ๋ฅผ URL์˜ ์ผ๋ถ€๋กœ ๋ถ™์—ฌ์„œ ์„œ๋ฒ„์— ๋ณด๋‚ธ๋‹ค. ์ฆ‰, ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ ๋ฐ์ดํ„ฐ๊ฐ€ URL์— ๋…ธ์ถœ์ด ๋˜๋Š” ๊ฒƒ์ด๋‹ค. ๋ถ„์„ (2) action ์†์„ฑ์€ ์š”์†Œ์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ œ์ถœํ•  ๋•Œ ์–ด๋–ค ๊ฒฝ๋กœ๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๋‚ผ์ง€๋ฅผ ์ง€์ •ํ•œ๋‹ค. ์ด ๊ฒฝ๋กœ๋Š” ์„œ๋ฒ„ ์ธก์—..

[Dreamhack/๋“œ๋ฆผํ•ต] xss-2

https://dreamhack.io/wargame/challenges/268 xss-2 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. ํ”Œ๋ž˜๊ทธ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ dreamhack.io [1] ๋ฌธ์ œ ํƒ์ƒ‰ ์ดˆ๊ธฐ ํ™”๋ฉด์ด๋‹ค. /vuln(xss) page. ์•„๋ฌด๊ฒƒ๋„ ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. /memo ํŽ˜์ด์ง€ ๋“ค์–ด๊ฐ„ ํšŸ์ˆ˜๋งŒํผ "hello"๊ฐ€ ์ ํžˆ๊ฒŒ ๋œ๋‹ค. /flag ํŽ˜์ด์ง€ param๋ฅผ ๋งค๊ฐœ๋ณ€์ˆ˜๋กœํ•˜๋Š” ์–ด๋–ค ๊ฐ’์„ ์ œ์ถœํ•  ์ˆ˜ ์žˆ๋Š” ํŽ˜์ด์ง€์ด๋‹ค. [2] ๋ฌธ์ œ ํ’€์ด xss-1์™€ ๊ตฌ์„ฑ์€ ๊ฐ™์ง€๋งŒ ๋” ์ด์ƒ /vulnํŽ˜์ด์ง€์—์„œ ๊ตฌ๋ฌธ ์™ธ์— ์šฐํšŒํ•˜์—ฌ ๋™์ž‘ํ•˜๋Š” ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์žˆ๋Š”์ง€ ์ฐพ์•„๋ณด๊ณ , ์ฐพ์•„๋‚ธ ์ฝ”๋“œ๋ฅผ..

[xss-game] Level 5: Breaking protocol

https://xss-game.appspot.com/ XSS game Welcome, recruit! Cross-site scripting (XSS) bugs are one of the most common and dangerous types of vulnerabilities in Web applications. These nasty buggers can allow your enemies to steal or modify user data in your apps and you must learn to dispatch the xss-game.appspot.com [1] ๋ฌธ์ œ ํƒ์ƒ‰ ๋ฌธ์ œ ํ™”๋ฉด์ด๋‹ค. ํ•ด์„์„ ํ•ด๋ณด๋ฉด, ์ž„๋ฌด ์„ค๋ช… ํฌ๋กœ์Šค ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŒ…์€ ๋‹จ์ˆœํžˆ ๋ฐ์ดํ„ฐ๋ฅผ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ด์Šค์ผ€์ดํ”„ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹™๋‹ˆ๋‹ค. ๋•Œ๋กœ..

[Dreamhack/๋“œ๋ฆผํ•ต] xss-1

[1] ๋ฌธ์ œ ํŽ˜์ด์ง€ ํƒ์ƒ‰ - vuln(xss) page ๋ฌธ์ œ์˜ ์ฒซ ํ™”๋ฉด์ด๋‹ค. vuln(xss) page์— ๋“ค์–ด๊ฐ€๋ณด์•˜๋‹ค. vuln ํŽ˜์ด์ง€์— param ๊ฐ’์œผ๋กœ ์ด ์ „๋‹ฌ๋˜์–ด "1"์ด๋ผ๋Š” ๋‚ด์šฉ์˜ ํŒ์—…์ฐฝ์ด ๋œจ๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์†Œ์Šค์ฝ”๋“œ ๋˜ํ•œ ํŠน์ด์ ์ด ์—†์—ˆ๋‹ค. - memo memo ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ณด์•˜๋‹ค. ๋“ค์–ด๊ฐ„ ํšŸ์ˆ˜๋งŒํผ "hello"๋ผ๋Š” ๋‚ด์šฉ์˜ ๋ฉ”๋ชจ๊ฐ€ ๋‚˜ํƒ€๋‚ฌ๊ณ , url ์ฃผ์†Œ์—์„œ๋Š” /memo ํŽ˜์ด์ง€์— memo ๊ฐ’์œผ๋กœ hello๊ฐ€ ์ „๋‹ฌ๋˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ ‡๊ฒŒ memo ํŒŒ๋ผ๋ฏธํ„ฐ์— ์ž„์˜์˜ ๊ฐ’์„ ๋„ฃ์€ ์ฃผ์†Œ๋กœ ์ด๋™ํ•˜๋ฉด ๊ทธ ๊ฐ’์ด ํŽ˜์ด์ง€์— ์ „๋‹ฌ์ด ๋˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ์ด ํŽ˜์ด์ง€์˜ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์•˜๋‹ค. - flag /flag ํŽ˜์ด์ง€๋ฅผ ํ™•์ธํ•ด๋ณด์•˜๋‹ค. ์ด ํŽ˜์ด์ง€์˜ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์•˜๋‹ค. [2] ๋ฌธ์ œ ํŒŒ์ผ ํƒ..

[Dreamhack/๋“œ๋ฆผํ•ต] DOM XSS

(1) ๋ฌธ์ œ ์‚ดํŽด๋ณด๊ธฐ ์ฒซ ํ™”๋ฉด์ด๋‹ค. vuln(xss) page ๋ฅผ ๋ˆ„๋ฅด๋ฉด ์ด์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜จ๋‹ค. memo๋ฅผ ๋ˆ„๋ฅด๋ฉด "hello"๋ผ๋Š” ๋ฌธ๊ตฌ๊ฐ€ ์ ํžŒ ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜จ๋‹ค. flag๋ฅผ ๋ˆŒ๋Ÿฌ๋ณด๋ฉด ์•„๋งˆ ๋‹ต์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ์–‘์‹์ด ๋‚˜์˜ค๋Š” ๊ฒƒ ๊ฐ™๋‹ค. (2) ๋ฌธ์ œ ํ’€์ด (์‹œ๋„) ๋จผ์ €, vuln(xss) page๋ฅผ ์‚ดํŽด๋ณด๊ฒ ๋‹ค. ์ด๋ฏธ์ง€ ํƒœ๊ทธ๊ฐ€ ์‚ฌ์šฉ๋˜์—ˆ๋‹ค๋Š” ๊ฒƒ์„ ์ถ”์ธกํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. ctrl + u ๋ฅผ ๋ˆŒ๋Ÿฌ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์•˜๋‹ค. url ์ฃผ์†Œ๋ฅผ ๋ณด๋‹ˆ ์ด๋ฏธ์ง€ ํƒœ๊ทธ๊ฐ€ ์‚ฌ์šฉ๋œ ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์—ˆ๋‹ค. ์ฐธ๊ณ ๋กœ "%20"์€ ์ŠคํŽ˜์ด์Šค ํ•œ ์นธ์„ url ์ธ์ฝ”๋”ฉํ•œ ๊ฒฐ๊ด๊ฐ’์ด๋‹ค. ๋” ์ด์ƒ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ด ์—†์–ด์„œ ๋‹ค๋ฅธ ํŽ˜์ด์ง€์— ๋Œ€ํ•ด์„œ๋„ ์•Œ์•„๋ณด๊ธฐ๋กœ ํ–ˆ๋‹ค. memo ํŽ˜์ด์ง€๋ฅผ ๋‚˜๊ฐ”๋‹ค๊ฐ€ ๋‹ค์‹œ ๋“ค์–ด์˜ค๋ฉด ๋ฐฉ๋ฌธํ•œ ํšŸ์ˆ˜์— ๋”ฐ๋ผ "hello"๋ผ๋Š” ๋ฌธ๊ตฌ๊ฐ€ ๋Š˜..

[los.rubiya.kr] orc

https://los.rubiya.kr/ Lord of SQLInjection los.rubiya.kr ๋ฌธ์ œ ํ’€์ด์— ์ฐธ๊ณ ํ•œ ๋ธ”๋กœ๊ทธ: https://power-girl0-0.tistory.com/237 ๋ฌธ์ œ ํ’€์ด ํ™”๋ฉด. # ๋ฌธ์ œ ์กฐ๊ฑด ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด ๋ฌธ์ œ๋ฅผ ํ’€๊ธฐ ์œ„ํ•ด ๋งŒ์กฑํ•ด์•ผ ํ•˜๋Š” ์กฐ๊ฑด์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. if(($result['pw']) && ($result['pw'] == $_GET['pw'])) solve("orc"); ์ฆ‰, $result['pw']๊ฐ€ ์กด์žฌํ•˜๊ณ  ์ด ๊ฐ’์ด ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ $_GET['pw']์™€ ์ผ์น˜ํ•ด์•ผ ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฐ๋‹ค. # Blind SQL Injection ์ด ๋ถ€๋ถ„์„ ๋ณด๋ฉด, ์ด ๋ฌธ์ œ๋Š” Blind SQL Injection์„ ์ด์šฉํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ถ”์ธกํ•˜์—ฌ ํ’€์–ด์•ผ ํ•จ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. Blin..

[los.rubiya.kr] goblin

https://los.rubiya.kr/ Lord of SQLInjection los.rubiya.kr ๋ฌธ์ œ ํ’€์ด๋ฅผ ์œ„ํ•ด ์ฐธ๊ณ ํ•œ ๊ธ€: https://dohunny.tistory.com/7, https://power-girl0-0.tistory.com/233 ๋ฌธ์ œ ํ™”๋ฉด. ์ฝ”๋“œ๋ฅผ ์‚ดํŽด๋ณด๋ฉด ์ฒซ ๋ฒˆ์งธ ์ฃผ์˜ํ•  ์  ์ด ๋ถ€๋ถ„์ธ๋ฐ... preg_match ๋Š” PHP4, 5, 7์—์„œ ์ง€์›ํ•˜๋Š” ํ•จ์ˆ˜๋กœ, ์ •๊ทœํ‘œํ˜„์‹ ์ค‘ ํ•˜๋‚˜์ด๋ฉฐ ์ง€์ •ํ•œ ํŒจํ„ด์ด ์ผ์น˜ํ•˜๋ฉด, ๊ฒ€์ƒ‰ ๊ฒฐ๊ณผ๋ฅผ ๋ฐ˜ํ™˜ํ•ด์ฃผ๋Š” ํ•จ์ˆ˜์ด๋‹ค. ์ฆ‰, ํ•ด๋‹น ํŽ˜์ด์ง€๋Š” preg_matchํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜์—ฌ ' (์‹ฑ๊ธ€ ์ฟผํ„ฐ), " (๋”๋ธ” ์ฟผํ„ฐ), \(๋ฐฑ ์ฟผํ„ฐ) ๋ฅผ ํ•„ํ„ฐ๋งํ•˜๊ณ  ์žˆ๋‹ค. ๋’ท ๋ถ€๋ถ„์— No Quotes์˜ ์˜๋ฏธ๋Š” ์ฟผํ„ฐ๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ๋ง๋ผ๋Š” ์˜๋ฏธ์ธ ๊ฒƒ์ด๋‹ค. ๋‘ ๋ฒˆ ์งธ๋กœ ์ฃผ์˜ํ•  ์  ์ด์ „ ๋ฌธ์ œ๋“ค์ฒ˜..

[los.rubiya.kr] cobolt

https://los.rubiya.kr/ Lord of SQLInjection los.rubiya.kr ๋ฌธ์ œ ํ™”๋ฉด. query : select id from prob_cobolt where id='' and pw=md5('') ๋ฅผ ๋ณด๊ณ  md5 ํ•ด์‹œ ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜๋‚˜? ์‹ถ์—ˆ๋‹ค. ์ผ๋‹จ php ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด id๊ฐ€ admin์ด ๋˜์–ด์•ผ coblot๊ฐ€ ํ’€๋ฆฐ๋‹ค๊ณ  ํ•œ๋‹ค. id๊ฐ’์— admin์„ ๋„ฃ์–ด์ฃผ๊ณ  ๋’ค๋ฅผ ์ฃผ์„์ฒ˜๋ฆฌํ•ด์ฃผ๋ฉด ๋  ๊ฒƒ ๊ฐ™๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ๋‹ค. ?id=admin'%23 ํด๋ฆฌ์–ด~