ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • Webhacking.kr :: old-18๋ฒˆ
    SECURITY/Webhacking 2021. 1. 25. 10:31

    ๋“ค์–ด๊ฐ€๋ฉด ๋‹ค์Œ ํ™”๋ฉด์ด๋‹ค.

     

    ์ฝ”๋“œ๋ฅผ ๋ณด์ž.

     

     

    guest ์˜ id ๊ฐ€ 1, admin ์€ 2 ์ž„์„ ํ™•์ธํ–ˆ๋‹ค.

    ๊ทผ๋ฐ ์ผ๋‹จ id ๊ฐ€ guest ๋กœ ๋˜์–ด์žˆ์œผ๋‹ˆ.. 1์„ ๋„ฃ์–ด๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

     

     

    ๊ทธ๋ฆฌ๊ณ  ์ฝ”๋“œ๋ฅผ ๋ณด๋ฉด ์•Œ๋“ฏ.. ์ ๋‹นํžˆ SQL Injection ๊ตฌ๋ฌธ์„ ๋„ฃ์œผ๋ฉด no hack ์ด ๋œฌ๋‹ค.

    ์šฐํšŒ ๋ฐฉ๋ฒ•์ด ํ•„์š”.

     

    ์ผ๋‹จ ๋„ฃ์€ ๊ตฌ๋ฌธ์€ =0 or no=2 ์ด๋‹ค. 

    (select id from chall18 where id='guest' and no=0 or no=2)

    (no=2 ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๊ฒŒ ํ•˜๋Š” ๊ตฌ๋ฌธ์ด๋‹ค)

     

    ์—ฌ๊ธฐ์— ์ŠคํŽ˜์ด์Šค๊ฐ€ ์žˆ๋Š”๊ฒŒ ๋ฌธ์ œ์ด๋‹ˆ url code ๋ฅผ ์‚ฌ์šฉํ•ด๋ณธ๋‹ค.

    url code ๋กœ space ๋Š” %20, tab ์€ %09 ์ด๋‹ค.

     

    %20์œผ๋กœ ํ–ˆ๋”๋‹ˆ ์•ˆ๋ผ์„œ %09๋กœ ํ–ˆ๋‹ค.

     

    ๊ฒฐ๊ณผ๋Š” ์ด๊ฑฐ~

     

     

    'SECURITY > Webhacking' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

    Webhacking.kr :: old-24๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-14๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-17๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-16๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-1๋ฒˆ  (0) 2021.01.24

    ๋Œ“๊ธ€

Designed by Tistory.