ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • Webhacking.kr :: old-42๋ฒˆ
    SECURITY/Webhacking 2021. 2. 2. 17:27

    2๊ฐœ์˜ ํŒŒ์ผ ๋ฆฌ์ŠคํŠธ๊ฐ€ ์žˆ๋‹ค.

    ๋‹ค์šด๋กœ๋“œ๋ฅผ ํด๋ฆญํ•˜๋ฉด test.txt ๋Š” ๋‹ค์šด์ด ๋˜์ง€๋งŒ, flag.docx ๋Š” Access Denied ๊ฐ€ ๋œฌ๋‹ค.

     

    ์†Œ์Šค๋ฅผ ๋ณด๋ฉด, ์–ด๋–ป๊ฒŒ ๋‹ค์šด๋ฐ›๋Š”์ง€ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

    test.txt ์˜ ๋‹ค์šด๋กœ๋“œ๋ฅผ ๋ˆ„๋ฅด๋ฉด

    <a href="?down=dGVzdC50eHQ=">download</a>

    ๊ฐ€ ์‹คํ–‰๋˜๋Š”๋ฐ, ์–ด๋–ค ํŒŒ์ผ์„ ๋‹ค์šด๋ฐ›์œผ๋ ค๋ฉด "?down=FILE" ์„ ํ•ด์•ผ ํ•œ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

     

    dGVzdC50eHQ= ์˜ = ๋กœ ๋ณด์•„ base64 ์ธ์ฝ”๋”ฉ์ด ๋˜์–ด์žˆ๋Š” ๊ฒƒ์ด๋‹ˆ,

    flag.docx ๋ฅผ base64 ์ธ์ฝ”๋”ฉ์„ ํ•˜์—ฌ url ์— ๋„ฃ์–ด์ค€๋‹ค.

     

     

    ์ด๋ ‡๊ฒŒ ์ž…๋ ฅํ•ด์ฃผ๋ฉด flag.docx ๊ฐ€ ๋ฐ›์•„์ง€๊ณ  docx ํŒŒ์ผ์„ ์—ด๋ฉด flag ๊ฐ€ ์žˆ๋‹ค!

    ๋.

    'SECURITY > Webhacking' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

    Webhacking.kr :: old-20๋ฒˆ  (0) 2021.02.16
    Webhacking.kr :: old-23๋ฒˆ  (0) 2021.02.15
    Webhacking.kr :: old-58๋ฒˆ  (0) 2021.02.02
    Webhacking.kr :: old-47๋ฒˆ  (0) 2021.02.02
    Webhacking.kr :: old-32๋ฒˆ  (0) 2021.02.02

    ๋Œ“๊ธ€

Designed by Tistory.