[Dreamhack] Level 1: Easy Login
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/1213 easy-loginDescription ๊ด€๋ฆฌ์ž๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”! ํ”Œ๋ž˜๊ทธ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค.dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ์ ‘์† - ์•„์ด๋”” / ํŒจ์Šค์›Œ๋“œ / OTP ์ž…๋ ฅ - admin์œผ๋กœ ๋กœ๊ทธ์ธํ•ด์•ผ ํ•˜๋ฏ€๋กœ, ํŒจ์Šค์›Œ๋“œ์™€ OTP ๋ถ€๋ถ„์„ ์ฐพ๊ฑฐ๋‚˜ ์šฐํšŒํ•ด์„œ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•ด์•ผ ํ•œ๋‹ค.   (2) ์ฝ”๋“œ ๋ถ„์„- index.phpgeneratePassword ํ•จ์ˆ˜๋Š” 16์ง„์ˆ˜ ๋ฌธ์ž(0-9, a-f)๋กœ ๊ตฌ์„ฑ๋œ ์ง€์ •๋œ ๊ธธ์ด์˜ ์ž„์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ƒ์„ฑํ•œ๋‹ค.generateOTP ํ•จ์ˆ˜๋Š” 'P'๋กœ ์‹œ์ž‘ํ•˜๋Š” 6์ž๋ฆฌ์˜ ์ˆซ์ž OTP๋ฅผ ์ƒ์„ฑํ•œ๋‹คadmin_pw์™€ otp๋Š” ๊ฐ๊ฐ 32์ž๋ฆฌ ๋น„๋ฐ€๋ฒˆํ˜ธ์™€ OTP๋ฅผ ์ €..
[Dreamhack] Level 3: chocoshop
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/106 chocoshopDescription ๋“œ๋ฆผ์ด๋Š” ๋นผ๋นผ๋กœ๋ฐ์ด๋ฅผ ๋งž์•„ ํ‹ฐ์˜ค๋ฆฌ์ œ๊ณผ์—์„œ ๋นผ๋นผ๋กœ ๊ตฌ๋งค๋ฅผ ์œ„ํ•œ ์ฟ ํฐ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์šฐ๋ฆฌ์˜ ๋ชฉ์ ์€ FLAG! ๊ทธ๋Ÿฐ๋ฐ ์ด๋Ÿฐ, FLAG๋Š” ๋„ˆ๋ฌด ๋น„์‹ธ ์‚ด ์ˆ˜๊ฐ€ ์—†๋„ค์š”... ์ฟ ํฐ์„ ์—ฌ๋Ÿฌ ๋ฒˆ ๋ฐœ๊ธ‰dreamhack.io ๋“œ๋ฆผ์ด๋Š” ๋นผ๋นผ๋กœ๋ฐ์ด๋ฅผ ๋งž์•„ ํ‹ฐ์˜ค๋ฆฌ์ œ๊ณผ์—์„œ ๋นผ๋นผ๋กœ ๊ตฌ๋งค๋ฅผ ์œ„ํ•œ ์ฟ ํฐ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค.ํ•˜์ง€๋งŒ ์šฐ๋ฆฌ์˜ ๋ชฉ์ ์€ FLAG! ๊ทธ๋Ÿฐ๋ฐ ์ด๋Ÿฐ, FLAG๋Š” ๋„ˆ๋ฌด ๋น„์‹ธ ์‚ด ์ˆ˜๊ฐ€ ์—†๋„ค์š”...์ฟ ํฐ์„ ์—ฌ๋Ÿฌ ๋ฒˆ ๋ฐœ๊ธ‰๋ฐ›๊ณ  ์‹ถ์—ˆ๋Š”๋ฐ ์ด๊ฒƒ๋„ ๋ถˆ๊ฐ€๋Šฅํ•ด์š”. ๋‚ด๋ถ€์ž ๋ง์— ์˜ํ•˜๋ฉด ์‚ฌ์šฉ๋œ ์ฟ ํฐ์„ ๊ฒ€์‚ฌํ•˜๋Š” ๋กœ์ง์ด ์ทจ์•ฝํ•˜๋‹ค๋Š”๋ฐ,๋“œ๋ฆผ์ด๋ฅผ ๋„์™€ FLAG๋ฅผ ๊ตฌ๋งคํ•˜์„ธ์š”!2. ํ•ด๊ฒฐ ๊ณผ์ •secret.pyfrom os impor..
[Dreamhack] Level 2: Dream Gallery
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/552 Dream Gallery๋“œ๋ฆผ์ด๋Š” ๊ฐค๋Ÿฌ๋ฆฌ ์‚ฌ์ดํŠธ๋ฅผ ๊ตฌ์ถ•ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ ์™ธ๋ถ€๋กœ ์š”์ฒญํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์•ˆ์ „ํ•œ ๊ฑด์ง€ ๋ชจ๋ฅด๊ฒ ๋‹ค๊ณ  ํ•˜๋„ค์š”... ๊ฐค๋Ÿฌ๋ฆฌ ์‚ฌ์ดํŠธ์—์„œ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  flag๋ฅผ ํš๋“ํ•˜์„ธ์š”! flag๋Š” /flag.txt์— ์žˆ์Šต๋‹ˆ๋‹ค.dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ •/ -> /view๋กœ ๋ฆฌ๋‹ค์ด๋ ‰ํŠธ ๋œ๋‹ค. /view์—์„œ๋Š” mini_database ๋ฆฌ์ŠคํŠธ์— ํฌํ•จ๋˜์–ด ์žˆ๋Š” ์ด๋ฏธ์ง€๋ฅผ ๋ณด์—ฌ์ค€๋‹ค. @app.route('/')def index(): return redirect(url_for('view'))@app.route('/view')def view(): return render_template('view.html', ..
[Dreamhack] Level 2: Relative Path Overwrite Advanced
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/440 Relative Path Overwrite AdvancedDescription Exercise: Relative Path Overwrite์˜ ํŒจ์น˜๋œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.10 bot.py ์ˆ˜์ •, Dockerfile ์ œ๊ณตdreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • ๊ธฐ๋ณธ์ ์ธ ์ฝ”๋“œ๋Š” Relative Path Overwrite์™€ ๊ฑฐ์˜ ๋™์ผํ•˜๋‹ค.  index.php์˜ ์ฝ”๋“œ์ด๋‹ค. GET๋ฐฉ์‹์œผ๋กœ page๋ฅผ ๋ฐ›๊ณ , ์ด page์— ..์ด๋‚˜ : ๋˜๋Š” / ์ด ํฌํ•จ๋˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค. ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š๋Š”๋‹ค๋ฉด ํ•ด๋‹น ํŒŒ์ผ์„ include ํ•œ๋‹ค.  Relative-Path-O..
[Dreamhack] Level 2: sql injection bypass WAF Advanced
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/416 sql injection bypass WAF AdvancedDescription Exercise: SQL Injection Bypass WAF์˜ ํŒจ์น˜๋œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.07.24 Dockerfile ์ œ๊ณตdreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •init.sql admin์˜ ํŒจ์Šค์›Œ๋“œ๊ฐ€ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด๋‹ค. INSERT INTO user(uid, upw) values('abcde', '12345');INSERT INTO user(uid, upw) values('admin', 'DH{**FLAG**}');INSERT INTO user(uid, upw) values('guest', 'guest');INSERT INT..
[Dreamhack] Level 2: CSP Bypass
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/435 CSP BypassDescription Exercise: CSP Bypass์—์„œ ์‹ค์Šตํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.07 Dockerfile ์ œ๊ณตdreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •์ฝ”๋“œ ์ค‘ add_header ๋ถ€๋ถ„์—์„œ ์‘๋‹ต๊ฐ’์— CSP๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. default-src 'self': ๊ธฐ๋ณธ์ ์œผ๋กœ ๋™์ผ ์ถœ์ฒ˜(d ๊ฐ™์€ ๋„๋ฉ”์ธ)์˜ ๋ฆฌ์†Œ์Šค๋งŒ ๋กœ๋“œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.img-src https://dreamhack.io: ์ด๋ฏธ์ง€๋Š” https://dreamhack.io ๋„๋ฉ”์ธ์—์„œ๋งŒ ๋กœ๋“œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.style-src 'self' 'unsafe-inline': CSS๋Š” ๋™์ผ ์ถœ์ฒ˜์—์„œ ๋กœ๋“œํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ,..
[Dreamhack] Level 2: file-csp-1
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/36 file-csp-1๋ฌธ์ œ์—์„œ ์š”๊ตฌํ•˜๋Š” ์กฐ๊ฑด์— ๋งž๊ฒŒ CSP๋ฅผ ์ž‘์„ฑํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhackingdreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด, verify ๋ถ€๋ถ„์˜ ์ฝ”๋“œ๊ฐ€ ์ค‘์š”ํ•ด๋ณด์ธ๋‹ค.@APP.route('/verify', methods=['GET', 'POST'])def verify_csp(): global CSP if request.method == 'POST': csp = request.form.get('csp') try: options = webdriver.ChromeOptions() ..
[Dreamhack] Level 2: baby-sqlite
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/1 baby-sqlite๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. SQL INJECTION ์ทจ์•ฝ์ ์„ ํ†ตํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”! ํ•ด๋‹น ๋ฌธ์ œ๋Š” ์ˆ™๋ จ๋œ ์›นํ•ด์ปค๋ฅผ ์œ„ํ•œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.dreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •๋กœ๊ทธ์ธ์„ ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” uid,upw ๊ฐ’์„ ์ž…๋ ฅํ•ด์•ผ ํ•œ๋‹ค. (๋ชจ๋‘ ์†Œ๋ฌธ์ž๋กœ ์ž…๋ ฅ๋จ) level๊ฐ’์€ 9๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋˜์–ด์žˆ๋‹ค. SQL Injection ๊ณต๊ฒฉ์„ ๋ฐฉ์–ดํ•˜๊ธฐ ์œ„ํ•ด ๊ฐ ์ž…๋ ฅ๊ฐ’์— ๋ชจ๋‘ ํ•„ํ„ฐ๋ง์„ ๊ฑธ์–ด๋‘”๋‹ค.  [ , ]: ํŠน์ • SQL ๋ฌธ๋ฒ•์— ์˜ํ–ฅ์„ ์ค„ ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ž.,: SQL ๋ช…๋ น์–ด์—์„œ ์—ฌ๋Ÿฌ ๊ฐ’์„ ๊ตฌ๋ถ„ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ.admin: ๊ด€๋ฆฌ์ž ๊ณ„์ •๊ณผ ๊ด€๋ จ๋œ ์ž…๋ ฅ์„ ์ œํ•œ.select: ๋ฐ์ดํ„ฐ๋ฅผ ์กฐํšŒํ•  ๋•Œ ์‚ฌ์šฉ๋˜๋Š” SQL ๋ช…๋ น์–ด.', ": SQL ๋ฌธ์ž์—ด..
[Dreamhack] Level 2: Relative Path Overwrite
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/439 Relative Path OverwriteDescription Exercise: Relative Path Overwrite์—์„œ ์‹ค์Šตํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.10 bot.py ์ˆ˜์ •, Dockerfile ์ œ๊ณตdreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •index.php ํŽ˜์ด์ง€์˜ ์ฝ”๋“œ์ด๋‹ค. page ๋ผ๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋ฐ›์•„ ํ•ด๋‹น ํŽ˜์ด์ง€์— ๋งž๋Š” php ํŒŒ์ผ์„ includeํ•œ๋‹ค. ํ•ด๋‹น ์ฝ”๋“œ์—์„œ .., :, / ๊ณผ ๊ฐ™์€ ๋ฌธ์ž๋Š” ํ•„ํ„ฐ๋งํ•˜๊ธฐ ๋•Œ๋ฌธ์— LFI ๊ณต๊ฒฉ์€ ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.  vuln.php ์ฝ”๋“œ๋Š” filter.js ๋ผ๋Š” ํŒŒ์ผ์„ ์Šคํฌ๋ฆฝํŠธ ํƒœ๊ทธ์˜ src๋กœ ๋กœ๋“œํ•˜๊ณ (filter๋ผ๋Š” ๋ฐฐ์—ด์ด ์ •์˜๋˜์–ด ์žˆ์Œ),..
[Dreamhack] Level 4: Flask-Dev
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/74 Flask-Dev์ทจ์•ฝ์ ์„ ์ฐพ์•„ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•ด๋ณด์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” /flag ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฌธ์ œ๋Š” ์ˆ™๋ จ๋œ ์›นํ•ด์ปค๋ฅผ ์œ„ํ•œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ •์ฝ”๋“œ์˜ ์•„๋ž˜ ๋ถ€๋ถ„์„ ๋ณด๋ฉด, debug=True๋ผ๊ณ  ๋˜์–ด์žˆ๋‹ค. Flask์—์„œ Dubugger ๋ชจ๋“œ๊ฐ€ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์„ ๋•Œ, ์—๋Ÿฌ ๋ฐœ์ƒ ์‹œ ์—๋Ÿฌ๋ฅผ ๋ณด์—ฌ์ฃผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ์ถœ๋ ฅ๋œ๋‹ค. ํ•ด๋‹น ์—๋Ÿฌ ํŽ˜์ด์ง€์—์„œ๋Š” ์ฝ˜์†”์„ ์‹คํ–‰์‹œํ‚ฌ ์ˆ˜ ์žˆ๋Š”๋ฐ, ์ด๋•Œ ์ฝ˜์†”์„ ์‹คํ–‰์‹œํ‚ค๊ธฐ ์œ„ํ•ด์„œ๋Š” PIN์ด ํ•„์š”ํ•˜๋‹ค. #!/usr/bin/python3from flask import Flaskimport osapp = Flask(__name__)app.secret_key = os...
mnzy๐ŸŒฑ
'CTF, War game' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (2 Page)
-->