[Dreamhack] Level 1: xss-1
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/28 xss-1 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. ํ”Œ๋ž˜๊ทธ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ #!/usr/bin/python3 from flask import Flask, request, render_template from selenium import webdriver from selenium.webdriver.chrome.service import Service import urllib import os app = ..
[Dreamhack] Level 1: php-1
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/46 php-1 php๋กœ ์ž‘์„ฑ๋œ Back Office ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. LFI ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” /var/www/uploads/flag.php์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Server-side Basic dreamhack.io - ํ”Œ๋ž˜๊ทธ๊ฐ€ /var/www/uploads/flag.php์— ์กด์žฌํ•œ๋‹ค๊ณ  ๋ฌธ์ œ์— ์ œ์‹œ๋˜์–ด์žˆ๋‹ค. - LFI ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜๋ผ๊ณ  ๋ฌธ์ œ์— ๋ช…์‹œ๋˜์–ด ์žˆ๋‹ค. 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ - ๋‹ค์šด๋กœ๋“œ ํ›„ ์••์ถ•์„ ํ’€์–ด์ฃผ์—ˆ๋‹ค. 4๊ฐœ์˜ php ํŒŒ์ผ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. - ํ•ด๋‹น ํŒŒ์ผ์„ vscode๋ฅผ ํ†ตํ•ด ์—ด์–ด๋ณด์•˜๋‹ค. - index.php ์œ„ ์ฝ”๋“œ์—์„œ๋Š” index.php์—์„œ๋Š” G..
.
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
.
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[dreamhack]Level 1 - blind sql injection advanced
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[dreamhack]Level 1: simple_sqli
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/24/ simple_sqli ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. SQL INJECTION ์ทจ์•ฝ์ ์„ ํ†ตํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Server-side Basic dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • ์กฐ๊ฑด๋ฌธ์— userid ๊ฐ€ 'admin' ์ด๊ณ , ํŒจ์Šค์›Œ๋“œ๋ฅผ ์ž…๋ ฅํ•˜๋ฉด FLAG ๋ฅผ ๋ฆฌํ„ดํ•œ๋‹ค๊ณ  ๋˜์–ด์žˆ๋‹ค. ์ด๋•Œ, userid๋งŒ ์ œ๋Œ€๋กœ admin์œผ๋กœ ์ฃผ๊ณ  ๊ทธ ๋’ค์˜ ์ฟผ๋ฆฌ๋ฅผ ์ฃผ์„์ฒ˜๋ฆฌํ•˜๋ฉด admin์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋‹ค. @app.route('/login', methods=['GET', 'POST']) def login(): if request.method == 'GET': return ..
[Webhacking.kr] Challenge(old) 27๋ฒˆ
ยท
CTF, War game
admin์„ ์ž…๋ ฅํ–ˆ์„ ๋•Œ, preg_match ํ•จ์ˆ˜๋ฅผ ํ†ตํ•ด #,select, (, ๊ณต๋ฐฑ, limit, =, 16์ง„์ˆ˜ ํ•„ํ„ฐ๋งํ•œ๋‹ค.
[Webhacking] Challenge(old) 14๋ฒˆ
ยท
CTF, War game
https://webhacking.kr/challenge/js-1/ Challenge 14 webhacking.kr #1 ๋ฌธ์ œ๋งํฌ๋กœ ์—ฐ๊ฒฐํ•˜๋ฉด ๊ฒ€์ •์ƒ‰ ํ™”๋ฉด์— ๋ฌธ์ž์—ด์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ์ฐฝ์ด ๋œฌ๋‹ค. #2 ๋จผ์ € ์•„๋ฌด ๋ฌธ์ž์—ด์ด๋‚˜ ์ž…๋ ฅํ•ด๋ณด์•˜๋‹ค, Wrong์ด๋ผ๋Š” alert์ฐฝ์ด ๋œจ๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. #3 ๋‹ค์‹œ ์ดˆ๊ธฐํ™”๋ฉด์œผ๋กœ ๋Œ์•„๊ฐ€ 'ํŽ˜์ด์ง€ ์†Œ์Šค๋ณด๊ธฐ'๋ฅผ ํ•˜์˜€๋‹ค ** indexOf( ) : ๋ฌธ์ž์—ด์—์„œ ์›ํ•˜๋Š” ๋ฌธ์ž์—ด์„ ๊ฒ€์ƒ‰ํ•˜๋Š” ๋‚ด์žฅํ•จ์ˆ˜๋กœ ์œ„์น˜๊ฐ’์„ index๋กœ ๋ฐ˜ํ™˜ํ•จ ๋”ฐ๋ผ์„œ, check ๋ฒ„ํŠผ์„ ํด๋ฆญํ–ˆ์„ ๋•Œ, ๋ณ€์ˆ˜ ul์— ํ˜„์žฌ URL์—์„œ '.kr'์— 30์ด ๊ณฑํ•ด์ง„ ๊ฐ’์ด ์ €์žฅ๋˜๊ณ , ์ด ul ๊ฐ’๊ณผ pw.input_pwd.value(์ž…๋ ฅ์ฐฝ์— ๋„ฃ์€ ๊ฐ’)์ด ์ผ์น˜ํ•˜๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฌ๋Š” ๊ฒƒ์ด๋‹ค. ํ˜„์žฌ URL์€ https://webhac..
[webhacking] Challenge(old) 34๋ฒˆ
ยท
CTF, War game
https://webhacking.kr/challenge/js-7/ Challenge 34 webhacking.kr #1. ํ•ด๋‹น ๋งํฌ๋กœ ์ ‘์† ์‹œ, ์œ„์˜ ๊ฒฝ๊ณ ์ฐฝ์ด ๋ฐ”๋กœ ๋œจ๊ณ  ํ™•์ธ์„ ๋ˆ„๋ฅด๋ฉด ๊ฒฝ๊ณ ์ฐฝ์ด ์‚ฌ๋ผ์ง€๊ณ  ๊ฒ€์ •์ƒ‰ ํ™”๋ฉด๋งŒ ๋ณด์ธ๋‹ค. #2 ์šฐํด๋ฆญ์œผ๋กœ 'ํŽ˜์ด์ง€ ์†Œ์Šค๋ณด๊ธฐ'๋ฅผ ์ง„ํ–‰ํ•˜์˜€๋‹ค. #3 ๋ณด์ด๋Š” ์ฝ”๋“œ๋ฅผ ๋ณต๋ถ™ํ•ด๋ณด๋‹ˆ ์ƒ๊ฐ๋ณด๋‹ค ์—„์ฒญ ๋ณต์žกํ•˜๊ณ  ๊ธด ์ฝ”๋“œ์˜€๋‹ค. ์šฐ๋ฆฌ๊ฐ€ ์•Œ๊ณ ์žˆ๋Š” ์ •๋ณด๋Š” alert ์ฐฝ์ด ๋œฌ ๊ฒƒ ๋ฟ์ด๋ผ์„œ alert ๋ฌธ์ž์—ด์„ ๊ฒ€์ƒ‰ํ•ด๋ณด๋‹ˆ if๋ฌธ ์†์—์„œ ๋”ฑ 1๊ฐœ๊ฐ€ ๋ฐœ๊ฒฌ๋˜์—ˆ๋‹ค. if(location[b('0x19','iUmC')][b('0x1a','6]r1')](0x1)==b('0x1b','RLUb'))location[b('0x1c','4c%d')]=b('0x1d','llaF'); else alert(b('0x1e',..
Webhacking.kr-Challenge(old)-42๋ฒˆ
ยท
CTF, War game
https://webhacking.kr/challenge/web-20/ Challenge 42 webhacking.kr #1 test.txt์™€ read me๋ฅผ ๋‘˜ ๋‹ค ๋‹ค์šดํ•ด๋ณด์•˜์ง€๋งŒ, flag ํŒŒ์ผ์€ access denied #2 ํŽ˜์ด์ง€ ์†Œ์Šค๋ณด๊ธฐ - ์†”์งํžˆ ์—ฌ๊ธฐ์„œ ๋ญ ์ˆ˜์ƒํ•œ ์ ์„ ํ•˜๋‚˜๋„ ๋ชป ์ฐพ๊ฒ ์–ด์„œ ๊ตฌ๊ธ€๋งํ•ด๋ณด์•˜๋‹ค 2testtest.txt [download] -> ํ•ด๋‹น ๋ถ€๋ถ„์ด base 64๋กœ ์ธ์ฝ”๋”ฉ ๋˜์–ด ์žˆ๋Š” ๋ถ€๋ถ„์ด๋ผ๊ณ  ์ถ”์ธกํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•œ๋‹ค๊ณ  ํ•œ๋‹ค...... //ํ•˜์ง€๋งŒ ์–ด๋–ป๊ฒŒ..? #3 base64๋กœ ๋””์ฝ”๋”ฉํ•ด๋ณด์•˜๋‹ค https://www.convertstring.com/ko/EncodeDecode/Base64Decode - ์‹ค์ œ๋กœ base64๋กœ ๋””์ฝ”๋”ฉํ•˜๋ฉด test.txt๋ผ๊ณ  ๋œจ๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค #4 ..
mnzy๐ŸŒฑ
'CTF, War game' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (4 Page)
-->