abex’ crackme #1, 2, 3
ยท
Study/Reversing
1. abex' crackme #1 ํŒŒ์ผ ์‹คํ–‰ -> 2๊ฐœ์˜ ๋ฉ”์‹œ์ง€ ์ฐฝ์„ ํ™•์ธ 3๊ฐœ์˜ ๋ฉ”์‹œ์ง€ ์ฐฝ์ด ๋œจ๋Š” ํ”„๋กœ๊ทธ๋žจ์ธ ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์ฆ‰, ํŒŒ์ผ์„ ์‹คํ–‰ํ–ˆ์„ ๋•Œ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•ด์„œ ์—๋Ÿฌ ๋ฉ”์‹œ์ง€ ์ฐฝ์ด ๋–ด๋˜ ๊ฒƒ์ด๊ณ , ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•˜์ง€ ์•Š์œผ๋ฉด ๋‹ค๋ฅธ ๋ฉ”์‹œ์ง€์ฐฝ์„ ๋œฐ ๊ฒƒ์ด๋‹ค. ์‹œ์ž‘ ์ฃผ์†Œ์™€ EP๊ฐ€ ๋™์ผ : ๋งค์šฐ ๊ฐ„๋‹จํ•˜๊ณ  ๋ช…ํ™•ํ•˜๊ฒŒ ์ž‘์„ฑ high language๋กœ ์ž‘์„ฑ๋˜์—ˆ์„ ๋•Œ ์•ž๋’ค์— ๋ถ™๋Š” stub code๊ฐ€ ์—†์Œ ์–ด์…ˆ๋ธ”๋ฆฌ๋กœ ์ž‘์„ฑ๋œ ์ฝ”๋“œ - ๋ฉ”์‹œ์ง€์ฐฝ์— ์ ํ˜€์žˆ๋˜ ๋Œ€๋กœ GetDriveType() ํ•จ์ˆ˜์—์„œ CD-ROM ํƒ€์ž…์„ ์–ป์–ด์•ผ ํ•  ๊ฒƒ์ด๋‹ค. - ํ˜„์žฌ๋Š” root path๋ฅผ c๋กœ ํ–ˆ์œผ๋ฏ€๋กœ ํ•˜๋“œ๋“œ๋ผ์ด๋ธŒ๊ฐ€ ๋˜์–ด์žˆ๋‹ค. - ExitProcess: ํ˜„์žฌ ํ”„๋กœ๊ทธ๋žจ์„ ์ข…๋ฃŒํ•˜๋ผ๋Š” ์˜๋ฏธ **ํ”„๋กœ์„ธ์Šค์™€ ํ”„๋กœ๊ทธ๋žจ์˜ ์ฐจ์ด : ์†Œํ”„ํŠธ์›จ์–ด๋กœ ํŒจํ‚ค์ง•๋œ ๋ชจ๋“  ๊ฑธ..
[Webhacking] Challenge(old) 14๋ฒˆ
ยท
CTF, War game
https://webhacking.kr/challenge/js-1/ Challenge 14 webhacking.kr #1 ๋ฌธ์ œ๋งํฌ๋กœ ์—ฐ๊ฒฐํ•˜๋ฉด ๊ฒ€์ •์ƒ‰ ํ™”๋ฉด์— ๋ฌธ์ž์—ด์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ์ฐฝ์ด ๋œฌ๋‹ค. #2 ๋จผ์ € ์•„๋ฌด ๋ฌธ์ž์—ด์ด๋‚˜ ์ž…๋ ฅํ•ด๋ณด์•˜๋‹ค, Wrong์ด๋ผ๋Š” alert์ฐฝ์ด ๋œจ๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. #3 ๋‹ค์‹œ ์ดˆ๊ธฐํ™”๋ฉด์œผ๋กœ ๋Œ์•„๊ฐ€ 'ํŽ˜์ด์ง€ ์†Œ์Šค๋ณด๊ธฐ'๋ฅผ ํ•˜์˜€๋‹ค ** indexOf( ) : ๋ฌธ์ž์—ด์—์„œ ์›ํ•˜๋Š” ๋ฌธ์ž์—ด์„ ๊ฒ€์ƒ‰ํ•˜๋Š” ๋‚ด์žฅํ•จ์ˆ˜๋กœ ์œ„์น˜๊ฐ’์„ index๋กœ ๋ฐ˜ํ™˜ํ•จ ๋”ฐ๋ผ์„œ, check ๋ฒ„ํŠผ์„ ํด๋ฆญํ–ˆ์„ ๋•Œ, ๋ณ€์ˆ˜ ul์— ํ˜„์žฌ URL์—์„œ '.kr'์— 30์ด ๊ณฑํ•ด์ง„ ๊ฐ’์ด ์ €์žฅ๋˜๊ณ , ์ด ul ๊ฐ’๊ณผ pw.input_pwd.value(์ž…๋ ฅ์ฐฝ์— ๋„ฃ์€ ๊ฐ’)์ด ์ผ์น˜ํ•˜๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฌ๋Š” ๊ฒƒ์ด๋‹ค. ํ˜„์žฌ URL์€ https://webhac..
[๋„ค๊ด€์‚ฌ๋ฟŒ์‹œ๊ธฐ] Chapter1. ๋„คํŠธ์›Œํฌ ์ผ๋ฐ˜
ยท
Study/CS
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[webhacking] Challenge(old) 34๋ฒˆ
ยท
CTF, War game
https://webhacking.kr/challenge/js-7/ Challenge 34 webhacking.kr #1. ํ•ด๋‹น ๋งํฌ๋กœ ์ ‘์† ์‹œ, ์œ„์˜ ๊ฒฝ๊ณ ์ฐฝ์ด ๋ฐ”๋กœ ๋œจ๊ณ  ํ™•์ธ์„ ๋ˆ„๋ฅด๋ฉด ๊ฒฝ๊ณ ์ฐฝ์ด ์‚ฌ๋ผ์ง€๊ณ  ๊ฒ€์ •์ƒ‰ ํ™”๋ฉด๋งŒ ๋ณด์ธ๋‹ค. #2 ์šฐํด๋ฆญ์œผ๋กœ 'ํŽ˜์ด์ง€ ์†Œ์Šค๋ณด๊ธฐ'๋ฅผ ์ง„ํ–‰ํ•˜์˜€๋‹ค. #3 ๋ณด์ด๋Š” ์ฝ”๋“œ๋ฅผ ๋ณต๋ถ™ํ•ด๋ณด๋‹ˆ ์ƒ๊ฐ๋ณด๋‹ค ์—„์ฒญ ๋ณต์žกํ•˜๊ณ  ๊ธด ์ฝ”๋“œ์˜€๋‹ค. ์šฐ๋ฆฌ๊ฐ€ ์•Œ๊ณ ์žˆ๋Š” ์ •๋ณด๋Š” alert ์ฐฝ์ด ๋œฌ ๊ฒƒ ๋ฟ์ด๋ผ์„œ alert ๋ฌธ์ž์—ด์„ ๊ฒ€์ƒ‰ํ•ด๋ณด๋‹ˆ if๋ฌธ ์†์—์„œ ๋”ฑ 1๊ฐœ๊ฐ€ ๋ฐœ๊ฒฌ๋˜์—ˆ๋‹ค. if(location[b('0x19','iUmC')][b('0x1a','6]r1')](0x1)==b('0x1b','RLUb'))location[b('0x1c','4c%d')]=b('0x1d','llaF'); else alert(b('0x1e',..
๋ฆฌํ‹€์—”๋””์–ธ ํ‘œ๊ธฐ๋ฒ• / ๋ ˆ์ง€์Šคํ„ฐ / ์–ด์…ˆ๋ธ”๋ฆฌ ๋ช…๋ น์–ด / ์Šคํƒ ํ”„๋ ˆ์ž„
ยท
Study/Reversing
1. ๋ฆฌํ‹€์—”๋””์–ธ ํ‘œ๊ธฐ๋ฒ• (1) ๋ฐ”์ดํŠธ ์˜ค๋”๋ง ์ปดํ“จํ„ฐ์—์„œ ๋ฉ”๋ชจ๋ฆฌ์— ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” ๋ฐฉ์‹ ๋น… ์—”๋””์–ธ(Big Endian)๊ณผ ๋ฆฌํ‹€ ์—”๋””์–ธ(Little Endian) ๋‘ ๊ฐ€์ง€ ๋ฐฉ์‹์ด ์กด์žฌ ๋น…์—”๋””์–ธ - ์ˆœ์„œ๋Œ€๋กœ ํ‘œ๊ธฐ ๋ฆฌํ‹€ ์—”๋””์–ธ - ์—ญ์ˆœ์œผ๋กœ ํ‘œ๊ธฐ intel x86 CPU(Windows ๊ณ„์—ด)์ด ์‚ฌ์šฉ BYTE b = 0x12; //0x.. -> 16์ง„์ˆ˜ WORD w = 0x1234; DWORD dw = 0x12345678; char str[] = "abcde"; Type Name Size ๋น… ์—”๋””์–ธ ๋ฆฌํ‹€ ์—”๋””์–ธ BYTE b 1 [12] [12] WORD w 2 [12][34] [34][12] DWORD dw 4 [12][34][56][78] [78][56][34][12] char [] str 6 [61][62][..
๋…ผ๋ฌธ ๋ถ„์„ ๋ฐ ์‹ค์Šต ํ…Œ์ŠคํŠธ
ยท
Project/์˜์ƒ ํ”Œ๋žซํผ-์บ์‹œ
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Webhacking.kr-Challenge(old)-42๋ฒˆ
ยท
CTF, War game
https://webhacking.kr/challenge/web-20/ Challenge 42 webhacking.kr #1 test.txt์™€ read me๋ฅผ ๋‘˜ ๋‹ค ๋‹ค์šดํ•ด๋ณด์•˜์ง€๋งŒ, flag ํŒŒ์ผ์€ access denied #2 ํŽ˜์ด์ง€ ์†Œ์Šค๋ณด๊ธฐ - ์†”์งํžˆ ์—ฌ๊ธฐ์„œ ๋ญ ์ˆ˜์ƒํ•œ ์ ์„ ํ•˜๋‚˜๋„ ๋ชป ์ฐพ๊ฒ ์–ด์„œ ๊ตฌ๊ธ€๋งํ•ด๋ณด์•˜๋‹ค 2testtest.txt [download] -> ํ•ด๋‹น ๋ถ€๋ถ„์ด base 64๋กœ ์ธ์ฝ”๋”ฉ ๋˜์–ด ์žˆ๋Š” ๋ถ€๋ถ„์ด๋ผ๊ณ  ์ถ”์ธกํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•œ๋‹ค๊ณ  ํ•œ๋‹ค...... //ํ•˜์ง€๋งŒ ์–ด๋–ป๊ฒŒ..? #3 base64๋กœ ๋””์ฝ”๋”ฉํ•ด๋ณด์•˜๋‹ค https://www.convertstring.com/ko/EncodeDecode/Base64Decode - ์‹ค์ œ๋กœ base64๋กœ ๋””์ฝ”๋”ฉํ•˜๋ฉด test.txt๋ผ๊ณ  ๋œจ๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค #4 ..
[Dreamhack] Beginner: cookie
ยท
CTF, War game
https://dreamhack.io/wargame/challenges/6/ cookie ์ฟ ํ‚ค๋กœ ์ธ์ฆ ์ƒํƒœ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io #1 ๋ฌธ์ œ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ด๋ณด๋‹ˆ ์ด๋Ÿฐ ์ฝ”๋“œ๊ฐ€ ๋ณด์˜€๋‹ค. #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for app = Flask(__name__) try: FLAG = open('./flag.txt', 'r').read() except: FLAG = '[**FLAG**]' us..
[Dreamhack] Beginner: Carve Party
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/96 Carve Party Description ํ• ๋กœ์œˆ ํŒŒํ‹ฐ๋ฅผ ๊ธฐ๋…ํ•˜๊ธฐ ์œ„ํ•ด ํ˜ธ๋ฐ•์„ ์ค€๋น„ํ–ˆ์Šต๋‹ˆ๋‹ค! ํ˜ธ๋ฐ•์„ 10000๋ฒˆ ํด๋ฆญํ•˜๊ณ  ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”! dreamhack.io - ํ˜ธ๋ฐ•์„ 10000๋ฒˆ ํด๋ฆญํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ๋ฌธ์ œ์— ์ œ์‹œ๋˜์–ด ์žˆ๋‹ค. 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ - jack-o-lantern์ด๋ผ๋Š” ํŒŒ์ผ๋ช…์˜ html ๋ฌธ์„œ๊ฐ€ ๋ณด์ธ๋‹ค. - pumpkin์„ ํด๋ฆญํ•˜๋ผ๋Š” ๋ฌธ๊ตฌ์™€ ํ˜ธ๋ฐ• ๊ทธ๋ฆผ, ๊ทธ ๋ฐ‘์—๋Š” ํด๋ฆญ์ˆ˜๋งŒํผ ์ค„์–ด๋“œ๋Š” ๋ฌธ์ž์—ด์ด ๋ณด์ธ๋‹ค. (2) ์ฝ”๋“œ ํ™•์ธ - F12๋ฅผ ๋ˆŒ๋Ÿฌ ๊ฐœ๋ฐœ์ž ๋„๊ตฌ๋ฅผ ํ†ตํ•ด ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•œ๋‹ค. $(function() { $('#jack-target').click(function () ..
HTTP ํ†ต์‹ ์— ์“ฐ์ด๋Š” ์ฟ ํ‚ค์™€ ์„ธ์…˜์— ๋Œ€ํ•œ ์ดํ•ด
ยท
Study/WebHacking
https://dreamhack.io/lecture/courses/166 ์™€ ๋‹ค์–‘ํ•œ ์ž๋ฃŒ๋ฅผ ์ฐธ๊ณ ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์ž˜๋ชป๋œ ์ •๋ณด๊ฐ€ ์žˆ์œผ๋ฉด ๋Œ“๊ธ€ ๋‹ฌ์•„์ฃผ์„ธ์š”! ํ˜„๋Œ€์˜ ์›น ์„œ๋น„์Šค๋Š” ๋Œ€๋ถ€๋ถ„ ๋กœ๊ทธ์ธ์„ ํ†ตํ•ด ๋งˆ์ดํŽ˜์ด์ง€, ์œ ๋ฃŒ ์„œ๋น„์Šค ๋“ฑ ๊ฐœ์ธ๋งŒ์˜ ์„œ๋น„์Šค๋ฅผ ์ด์šฉํ•œ๋‹ค. ์›น ์„œ๋ฒ„๋Š” ์ˆ˜๋งŽ์€ ํด๋ผ์ด์–ธํŠธ์™€ HTTP ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•ด ํ†ต์‹ ํ•œ๋‹ค. ์†๋‹˜ ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ ํ–ˆ๋‹ค๋ฉด ์†๋‹˜์ด ์ด์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•˜๊ณ , ๊ด€๋ฆฌ์ž ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ ํ–ˆ๋‹ค๋ฉด ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค, ํšŒ์› ๊ด€๋ฆฌ ๋“ฑ์˜ ๊ด€๋ฆฌ์ž ํŽ˜์ด์ง€๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค. ๊ทธ๋ ‡๋‹ค๋ฉด ์›น ์„œ๋ฒ„๋Š” ์ˆ˜๋งŽ์€ ํด๋ผ์ด์–ธํŠธ๋ฅผ ์–ด๋–ป๊ฒŒ ๊ตฌ๋ณ„ํ•˜๊ณ  ์„œ๋กœ ๋‹ค๋ฅธ ๊ฒฐ๊ณผ๋ฅผ ๋ฐ˜ํ™˜ํ•ด์ค„๊นŒ? HTTP ํ”„๋กœํ† ์ฝœ๋กœ ์›น ์„œ๋ฒ„์™€ ํ†ต์‹ ํ•  ๋•Œ์—๋Š” ์›น ์„œ๋ฒ„์— ๋ช…๋ น์„ ๋‚ด๋ฆฌ๊ธฐ ์œ„ํ•ด GET, POST์™€ ๊ฐ™์€ ๋ฉ”์†Œ๋“œ์™€ ์ž์›์˜ ์œ„์น˜๋ฅผ ๊ฐ€๋ฆฌํ‚ค๋Š” URL ๋“ฑ์ด ํฌํ•จ..
mnzy๐ŸŒฑ
'๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (10 Page)
-->