ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • Webhacking.kr :: old-47๋ฒˆ
    SECURITY/Webhacking 2021. 2. 2. 14:11

    ์ผ๋‹จ ๋ญ๊ฐ€ ์ ํ˜€์žˆ์œผ๋‹ˆ send ๋ฅผ ๋ˆŒ๋Ÿฌ๋ณด์ž.

     

     

    ๋ฉ”์ผ์ด ๋ณด๋‚ด์กŒ์ง€๋งŒ, FLAG ๊ฐ’์€ ์•Œ ์ˆ˜ ์—†๋‹ค.

     

    ๊ทธ๋ž˜์„œ send ๊ฐ’์„ ๋ฐ”๊ฟ”์„œ ๊ฒฐ๊ณผ๋ฅผ ํ™•์ธํ•ด๋ดค๋‹ค.

     

    Message-ID ์™€ ๋ณด๋‚ธ ์‹œ๊ฐ„ ๋นผ๊ณ ๋Š” ํฌ๊ฒŒ ๋‹ฌ๋ผ์ง„ ๊ฒƒ์ด ์—†๋‹ค.

    ๊ทผ๋ฐ Message-ID ๋Š” ๊ทธ๋ƒฅ ๋งค๋ฒˆ ๋ฐ”๋€Œ๋Š” ๊ฒƒ ๊ฐ™๊ณ ,, ํ 

     

    ๊ทธ๋Ÿฌ๋‹ค Mail Injection ๊ด€๋ จํ•ด์„œ ์•Œ์•„๋ณด๋‹ˆ,

    Mail Header Injection ์ด๋ผ๋Š” ๊ฒƒ์ด ์žˆ์—ˆ๋‹ค.

    'Cc' ๋ผ๋Š” ํ‚ค์›Œ๋“œ๋กœ injection ์„ ํ•  ์ˆ˜ ์žˆ๋Š”๋ฐ, Cc ๋ž€ ์ˆจ์€ ์ฐธ์กฐ๋ฅผ ์˜๋ฏธํ•œ๋‹ค.

    ๊ทธ๋ž˜์„œ Cc : id@mail.com ์„ ๋„ฃ์œผ๋ฉด ๊ทธ ๋ฉ”์ผ ์ฃผ์†Œ์—๋„ ํ•ด๋‹น ๋ฉ”์ผ์ด ์ฐธ์กฐ ํ˜•์‹์œผ๋กœ ๋ณด๋‚ด์ง€๋Š” ๊ฒƒ์ด๋‹ค. 

     

    ๊ธฐ๋ณธ์œผ๋กœ ๋“ค์–ด๊ฐ€๋Š”๊ฒŒ Flag of webhacking.kr old-47 chall 

    ๋’ค์— enter ๋กœ ๊ตฌ๋ถ„ํ•˜์—ฌ ์ž…๋ ฅํ•œ ๋ฌธ์ž๊ฐ€ mail ์„ ๋ณด๋‚ด๋Š” ์ž‘์—…์˜ '์ถ”๊ฐ€ ํ—ค๋”'๊ฐ€ ๋˜์–ด ๋“ค์–ด๊ฐ„๋‹ค.

    ๊ทธ๋Ÿฌ๋‹ˆ, input ์ƒ์ž๋ฅผ textarea ๋กœ ๋ฐ”๊พผ ๋’ค

    ์—”ํ„ฐ์น˜๊ณ ,

    Cc: MAIL_ADDR

    ์„ ์ž…๋ ฅํ•ด์ฃผ์ž.

     

    ๊ทธ๋ฆฌ๊ณ  send ๋ฅผ ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์ด Cc ๋กœ ๋‚ด ์ด๋ฉ”์ผ์ด ๋“ค์–ด๊ฐ„ ๊ฑธ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

     

    ์ด์ œ ๋ฉ”์ผํ•จ์„ ํ™•์ธํ•ด๋ณด์ž. 

     

    FLAG ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๊ฑธ Auth ์— ์ž…๋ ฅํ•ด์ฃผ์ž!

    ๋.

    'SECURITY > Webhacking' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

    Webhacking.kr :: old-42๋ฒˆ  (0) 2021.02.02
    Webhacking.kr :: old-58๋ฒˆ  (0) 2021.02.02
    Webhacking.kr :: old-32๋ฒˆ  (0) 2021.02.02
    Webhacking.kr :: old-25๋ฒˆ  (0) 2021.02.02
    Webhacking.kr :: old-19๋ฒˆ  (0) 2021.02.02

    ๋Œ“๊ธ€

Designed by Tistory.