SWLUG/CTF ๋ฌธ์ œ ํ’€์ด (2) 17

[Dreamhack/๋“œ๋ฆผํ•ต] PHPreg

https://dreamhack.io/wargame/challenges/873 phpregDescription php๋กœ ์ž‘์„ฑ๋œ ํŽ˜์ด์ง€์ž…๋‹ˆ๋‹ค. ์•Œ๋งž์€ Nickname๊ณผ Password๋ฅผ ์ž…๋ ฅํ•˜๋ฉด Step 2๋กœ ๋„˜์–ด๊ฐˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Step 2์—์„œ system() ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜์—ฌ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” ../dream/flag.txt์— ์œ„์น˜ํ•ฉ๋‹ˆdreamhack.io[1] ๋ฌธ์ œ ํ’€์ด  ๋ฌธ์ œ ์„ค๋ช…์„ ๋‹ค์‹œ ๋ณด์ž๋ฉด, ์ด๋Ÿฌํ•˜๋‹ค! ๊ทธ๋Ÿฌ๋‹ˆ๊นŒ php๋กœ ์ž‘์„ฑํ•œ ํŽ˜์ด์ง€์— ์ ‘์†์„ ํ•˜๋ฉด, Ncickname๊ณผ Password๋ฅผ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค.๋จผ์ € ์•Œ๋งž์€ Nickname๊ณผ Password๋ฅผ ์ž…๋ ฅํ•˜์—ฌ Step 2๋กœ ๋„˜์–ด๊ฐ€๋ณด์ž!  Step 1 ํŽ˜์ด์ง€์˜ ์†Œ์Šค์ฝ”๋“œ ํŽ˜์ด์ง€๋ฅผ ์‚ดํŽด๋ณด์•˜๋Š”๋ฐ ๋ณ„ ๊ฒŒ ์—†์–ด์„œ ๋ฌธ์ œ ํŒŒ์ผ์„ ์‚ดํŽด..

[Dreamhack/๋“œ๋ฆผํ•ต] php7cmp4re

1. ๋ฌธ์ œ ์›น ํŽ˜์ด์ง€    ์ฒ˜์Œ์œผ๋กœ ๋‚˜์˜ค๋Š” ํŽ˜์ด์ง€๋Š”, input1๊ณผ input2๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ์ œ์ถœํ•  ์ˆ˜ ์žˆ๋„๋ก ๊ตฌ์„ฑ๋˜์–ด ์žˆ๋‹ค. ์ด ํŽ˜์ด์ง€ ์ด์™ธ์— ๋‹ค๋ฅธ ํŽ˜์ด์ง€๋Š” ์—†๋‹ค.   input1๊ณผ input2์— ๊ฐ๊ฐ 1์„ ์ž…๋ ฅํ•˜๊ณ  ์ œ์ถœ ๋ฒ„ํŠผ์„ ๋ˆŒ๋Ÿฌ๋ณด์•˜๋‹ค.    /check.php ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•˜๊ฒŒ ๋˜๋ฉด์„œ,"Try again"์ด๋ผ๋Š” ๋ฌธ๊ตฌ๊ฐ€ ์“ฐ์—ฌ์ง„ ์›นํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜จ๋‹ค.   ์ฒ˜์Œ ํŽ˜์ด์ง€ (์ž…๋ ฅ ํŽ˜์ด์ง€) ์ž…๋ ฅ ๊ฒฐ๊ณผ๊ฐ€ ์ถœ๋ ฅ๋˜๋Š” ์›นํŽ˜์ด์ง€ ๋‘ ํŽ˜์ด์ง€ ๋ชจ๋‘ ์†Œ์Šค ์ฝ”๋“œ์—์„œ ํŠน์ด์ ์„ ์ฐพ์„ ์ˆ˜ ์—†์—ˆ๋‹ค.   2. ๋‹ค์šด๋กœ๋“œ ๋ฌธ์ œ ํŒŒ์ผ   ๋‹ค์šด๋ฐ›์€ zip ํŒŒ์ผ ์•ˆ์—๋Š” 3๊ฐœ์˜ php ํŒŒ์ผ์ด ์žˆ๋‹ค.  โญ check.php php7cmp4re ..

[Dreamhack/๋“œ๋ฆผํ•ต] Carve Party

[1] ๋ฌธ์ œ ํ’€๊ธฐ jack-o-lantern.html ํŒŒ์ผ์„ ํฌ๋กฌ์œผ๋กœ ์—ด๋ฉด ๋‚˜์˜ค๋Š” ์ฒซ ํ™”๋ฉด ํ˜ธ๋ฐ•์„ ํด๋ฆญํ•  ๋•Œ๋งˆ๋‹ค ์•„๋ž˜ ๋ฌธ๊ตฌ์— ์žˆ๋Š” ์ˆซ์ž๊ฐ€ ์ค„์–ด๋“ ๋‹ค. 10000๋ฒˆ์„ ํด๋ฆญํ•ด์•ผ ํ’€ ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ œ์ธ๋ฐ, ์ง„์งœ๋กœ 10000๋ฒˆ์„ ํด๋ฆญํ•˜์ง€๋Š” ๋ง์ž... ์ฝ”๋“œ ๋ถ„์„ click the pumpkin to make a jack-o-lantern! 10000 more clicks to go! ์ตœ์ดˆ ์„ ์–ธ๋œ count=0 ์ด 10000์ด ๋ ๋•Œ๊นŒ์ง€ 1์”ฉ ์นด์šดํŠธ๋ฅผ ๋Š˜๋ ค๊ฐ€๋ฉฐ pumkin[] ๋ฆฌ์ŠคํŠธ์— ๊ฐ’๋“ค์„ ๋ฐ”๊พผ๋‹ค. count๊ฐ€ 10000์ด ๋˜๋ฉด, make() ํ•จ์ˆ˜๋ฅผ ํ˜ธ์ถœํ•˜์—ฌ flag๋ฅผ ๋„์šฐ๋Š” ๊ฒƒ ๊ฐ™๋‹ค. ํ˜ธ๋ฐ•์„ ํด๋ฆญํ•˜๋Š” ๋Œ€์‹  ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ˆ˜์ •ํ•˜์—ฌ ํ”Œ๋ž˜๊ทธ๋ฅผ ์ฐพ๋Š” ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด๋ณด์ž. ํ˜ธ๋ฐ•์„ ํด๋ฆญํ•  ๋•Œ count๊ฐ€ 1์ด ์ฆ๊ฐ€ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹Œ ๋ฐ˜๋ณต..

[Dreamhack/๋“œ๋ฆผํ•ต] devtools-sources

[1] ๋ฌธ์ œ ํ’€์ด ๊ฐœ๋ฐœ์ž ๋„๊ตฌ์˜ Sources ํƒญ ๊ธฐ๋Šฅ์„ ํ™œ์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ์ฐพ์•„๋ณด๋ผ๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ์ฝ๊ณ , ๋ชจ๋“  ์†Œ์Šค ํŒŒ์ผ์„ ์ผ์ผ์ด ๋“ค์–ด๊ฐ€์„œ ์ฐพ์•„๋ณด๋‹ค๊ฐ€ 'webpack:///styles/main.scss'์— ๋“ค์–ด๊ฐ€๋ณด์•˜๋Š”๋ฐ ์ฃผ์„์— ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ์žˆ์—ˆ๋‹ค... ๋‹ต์„ ๋„ˆ๋ฌด ์‰ฝ๊ฒŒ ์ฐพ์€ ๊ฒƒ ๊ฐ™์•„์„œ, ์–ด๋–ค ์˜๋„๋ฅผ ๊ฐ€์ง„ ๋ฌธ์ œ์ธ์ง€ ๊ถ๊ธˆํ–ˆ๋‹ค. [2] ํ•ด์„ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ๋ฅผ ์—ด๊ณ , ctrl + shift + F ๋ฅผ ๋ˆ„๋ฅด๋ฉด ๊ฒ€์ƒ‰ ๊ธฐ๋Šฅ์„ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค. ํ”Œ๋ž˜๊ทธ ํ˜•์‹์ธ DH{...}๋ฅผ ์ฐพ๊ธฐ ์œ„ํ•ด 'DH'๋ฅผ ์ž…๋ ฅํ•ด๋ณด์•˜๋‹ค. ํ”Œ๋ž˜๊ทธ ๊ฐ’๊ณผ ์œ„์น˜๋ฅผ ๋ฐ”๋กœ ์ฐพ์„ ์ˆ˜ ์žˆ์—ˆ๋‹ค. [3] ๋Š๋‚€ ์  ๊ฐ„๋‹จํ•œ ๋ฌธ์ œ!

[Dreamhack/๋“œ๋ฆผํ•ต] session

[1] ๋ฌธ์ œ ํ’€์ด (1) ์›น ํŽ˜์ด์ง€ ๋ถ„์„ cookie ๋ฌธ์ œ์™€ ํŽ˜์ด์ง€ ๊ตฌ์„ฑ์ด ๋™์ผํ•˜๋‹ค. Home ํŽ˜์ด์ง€์™€ AboutํŽ˜์ด์ง€๋Š” ์ฐจ์ด๊ฐ€ ์—†๋‹ค. (About์„ ๋ˆ„๋ฅด๋ฉด URL๋งํฌ ๋งˆ์ง€๋ง‰์— '#'์ด ๋ถ™๋Š”๋‹ค๋Š” ์ •๋„...?) Login ํ™”๋ฉด๊นŒ์ง€ ๋˜‘๊ฐ™์•˜๋‹ค. ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ด ์—†์–ด์„œ ๋ฐ”๋กœ ๋ฌธ์ œ ํŒŒ์ผ์„ ๋ถ„์„ํ•ด๋ณด์•˜๋‹ค. (2) ๋ฌธ์ œ ํŒŒ์ผ ๋ถ„์„ โš™๏ธapp.py #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for app = Flask(__name__) try: FLAG = open('./flag.txt', 'r').read() except: FLAG = '[**FLAG**]' users = { 'g..

[Dreamhack/๋“œ๋ฆผํ•ต] cookie

[1] ๋ฌธ์ œ ๋ถ„์„ (1) ์›น ํŽ˜์ด์ง€ ๋ถ„์„ ๋ฌธ์ œ ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ฉด ๋‚˜์˜ค๋Š” ํŽ˜์ด์ง€์ด๋‹ค. ์œ„์˜ ํŽ˜์ด์ง€ ๋ชฉ๋ก ์ค‘์— Home, About ์„ ํด๋ฆญํ•ด๋„ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. Login ์„ ๋ˆ„๋ฅด๋ฉด ์œ„์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜จ๋‹ค. username์— 1234 password์— 1234๋ฅผ ์ž…๋ ฅํ•˜์˜€๋”๋‹ˆ ์œ„์™€ ๊ฐ™์€ ๋ฉ”์„ธ์ง€ ํŒ์—…์ฐฝ์ด ๋‚˜์™”๋‹ค. ๋ฌธ์ œ์—์„œ "admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ..." ์ด๋ผ๊ณ  ํ–ˆ๋˜ ๋ฌธ๊ตฌ๋ฅผ ๋– ์˜ฌ๋ ค, username์— admin์„, password์— admin์„ ์ž…๋ ฅํ•˜์˜€๋‹ค. ๊ทธ๋žฌ๋”๋‹ˆ "wrong password"๋ผ๋Š” ๋ฉ”์„ธ์ง€ ํŒ์—…์ฐฝ์ด ๋‚˜ํƒ€๋‚ฌ๋‹ค. ์•„๊นŒ๋Š” "not found user"๋ผ๊ณ  ํ–ˆ๋Š”๋ฐ, ์ด๋ฒˆ์—” ํ‹€๋ฆฐ ํŒจ์Šค์›Œ๋“œ๋ผ๋Š” ์•Œ๋ฆผ์ด ๋œจ๋Š” ๊ฑธ๋กœ ๋ด์„œ, username์ด admin์€ ๋งž๋Š” ๊ฒƒ ๊ฐ™์•˜๋‹ค. (2) ๋ฌธ์ œ ํŒŒ์ผ..