SECURITY/Webhacking

Webhacking.kr :: old-20๋ฒˆ

\b\t 2021. 2. 16. 10:17

 

2์ดˆ์˜ ์ œํ•œ์‹œ๊ฐ„์ด ์žˆ๋‹ค๊ณ  ํ•˜์ง€๋งŒ, 2์ดˆ๊ฐ€ ์ง€๋‚˜๋„ ๋ณ„๋‹ค๋ฅธ ๋ณ€ํ™”๊ฐ€ ์—†๋‹ค.

๊ทธ๋ž˜์„œ script ๋ฅผ ๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

 

nickname, comment ๋Š” ๊ณต๋ฐฑ์ด ์•„๋‹ˆ๊ธฐ๋งŒ ํ•˜๋ฉด ๋˜๊ณ , (๊ณต๋ฐฑ์ด๋ฉด ํ•ด๋‹น ์ž…๋ ฅ๋ž€์— focus ๊ฐ€ ๊ฐ€๊ฒŒ ๋œ๋‹ค)

captcha ๋Š” captcha_.value ์™€ ๊ฐ™์€ ๊ฐ’์„ ์ž…๋ ฅํ•ด์•ผ ํ•œ๋‹ค. 

function ck() {
	if(lv5frm.id.value=="") { lv5frm.id.focus(); return; } 
    if(lv5frm.cmt.value=="") { lv5frm.cmt.focus(); return; } 
    if(lv5frm.captcha.value=="") { lv5frm.captcha.focus(); return; }
    if(lv5frm.captcha.value!=lv5frm.captcha_.value) { lv5frm.captcha.focus(); return; } 
    lv5frm.submit(); }

 

ํ•ด๋‹น ํ…Œ์ด๋ธ”์—์„œ captcha_.value ๋ฅผ ํ™•์ธํ•ด๋ณด๋‹ˆ, f3l5wXw3h5 ์ด์—ˆ๊ณ , ์ด๊ฑธ ์ž…๋ ฅํ•ด์ฃผ์—ˆ๋‹ค.

 

 

๊ทธ๋žฌ๋”๋‹ˆ.. ๋Š๋ฆฌ๋‹ค๊ณ  ๊ฑฐ์ ˆ๋‹นํ–ˆ๋‹ค

(์–˜๋„ ์ดํ›„์— ๋‹ค์‹œ ์›๋ž˜ ํŽ˜์ด์ง€๋กœ ๋Œ์•„๊ฐ€๋Š”๊ฑฐ ๋ณด๋‹ˆ, Too Slow... ์ถœ๋ ฅ ํŽ˜์ด์ง€๋„ 2์ดˆ์ž„์„ ์œ ์ถ”ํ•  ์ˆ˜ ์žˆ๋‹ค)

 

 

ํ•˜์ง€๋งŒ 2์ดˆ ์•ˆ์— ์ € ๊ฐ’์„ ๊ทธ๋Œ€๋กœ ์ž…๋ ฅํ•˜๊ณ  Submit ํ•˜๊ธฐ๋Š”.. ๊ฑฐ์˜ ๋ถˆ๊ฐ€๋Šฅ์ด๋‹ค.

 

ํ•œ ๋ฒˆ ํ•จ์ˆ˜๋ฅผ ์กฐ์ž‘ํ•ด๋ณด์ž.

 

์ด๊ฑธ ์ƒˆ๋กœ console ์— ๋‘๊ณ  ๊ทธ๋ƒฅ submit ์„ ํ–ˆ๋‹ค.

๊ทธ๋žฌ๋”๋‹ˆ..

 

Wrong Captcha ๊ฐ€ ๋œฌ๋‹ค.

 

๊ฒฐ๊ตญ Captcha ๊ฐ’์ด submit ํ•  ๋•Œ๋„ ๋งž์œผ๋ฉด์„œ, ๋Šฆ์ง€ ์•Š๊ฒŒ ์ œ์ถœํ•ด์•ผ ํ•œ๋‹ค.

 

๊ทธ๋ž˜์„œ ๋ฐ”๋กœ console ๋กœ ๊ฐ’์„ ๋„ฃ์–ด๋ณด๋„๋ก ํ•˜์ž.

 

lv5frm.id.value="a"

lv5frm.cmt.value="a"

lv5frm.captcha.value=lv5frm.captcha_.value

lv5frm.submit();

 

์„ ๋ณต์‚ฌํ•ด๋‘๊ณ , ํŽ˜์ด์ง€๋ฅผ ์ƒˆ๋กœ๊ณ ์นจํ•œ ๋’ค console ์— ์žฝ์‹ธ๊ฒŒ! ์ž…๋ ฅํ•ด์ฃผ์ž.

 

 

๋—!