ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • Webhacking.kr :: old-38๋ฒˆ
    SECURITY/Webhacking 2021. 1. 25. 11:54

    Injection ๋ฌธ์ œ๋‹ค.

    ๊ทธ๋ƒฅ admin ์„ ๋„ฃ์–ด๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋œฌ๋‹ค.

    ์†Œ์Šค๋ฅผ ๋ณด๋ฉด, admin.php ๊ฐ€ admin page ๋ผ๊ณ  ์„ค๋ช…ํ•ด์ฃผ๊ณ  ์žˆ๋‹ค.

    ๊ฑฐ๊ธฐ๋กœ ์ด๋™ํ•ด๋ณด์ž.

     

     

    ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋œฌ๋‹ค.

    ๋‚ด ip ์ฃผ์†Œ์™€ ๋‚ด๊ฐ€ ์ž…๋ ฅํ–ˆ๋˜ ๊ฐ’๋“ค๊ณผ ํ•จ๊ป˜..

     

    ์Œ.. ๋กœ๊ทธ๋‹ˆ๊นŒ \r\n ๋กœ ์ƒˆ๋กœ์šด ๋กœ๊ทธ๋กœ ์ธ์‹ํ•˜๊ฒŒ ๋งŒ๋“ค ์ˆ˜ ์žˆ๊ฒ ๋‹ค.

     

    log ingection ์ด ๋กœ๊ทธ ํŒŒ์ผ์„ ์กฐ์ž‘ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฑด๋ฐ,

    log ์— [์ง„์งœ ๋‚ด์šฉ] \r\n [๊ฐ€์งœ ๋‚ด์šฉ] ์„ ๋„ฃ์–ด์ฃผ๋ฉด

    log ํŒŒ์ผ์—๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ €์žฅ๋˜๋Š” ๊ฒƒ์„ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด๋‹ค.

     

    [ip์ฃผ์†Œ]: [์ง„์งœ ๋‚ด์šฉ]

    [๊ฐ€์งœ ๋‚ด์šฉ]

     

     

    ์–ด์จŒ๋“  ์—”ํ„ฐ์˜ ํšจ๊ณผ๋ฅผ ๋ณด๋ฉด ๋˜๋‹ˆ๊นŒ

    ๊ฐ„๋‹จํ•˜๊ฒŒ, ์ € input ๊ณต๊ฐ„์„ textarea ๋กœ ๋ฐ”๊ฟ”์ฃผ๊ณ , ์—”ํ„ฐ์น˜๊ณ  ์ž๊ธฐ ip:admin ์œผ๋กœ ํ•˜๋ฉด ํ’€๋ฆฐ๋‹ค.

     

    ์—ฌ๊ธฐ์— 

    test

    [ip์ฃผ์†Œ]:admin

    ์„ ์ž…๋ ฅํ•œ ํ›„ admin.php ๋กœ ๊ฐ€๋ฉด ํ’€๋ ธ๋‹ค๊ณ  ๋‚˜์˜จ๋‹ค.

     

    'SECURITY > Webhacking' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

    Webhacking.kr:: old-54๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-39๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-26๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-06๋ฒˆ  (0) 2021.01.25
    Webhacking.kr :: old-24๋ฒˆ  (0) 2021.01.25

    ๋Œ“๊ธ€

Designed by Tistory.