[Dreamhack] Level 3: Switching Command
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/1081 Switching CommandDescription Not Friendly service... Can you switching the command?dreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ์ ‘์†- username์„ ์ž…๋ ฅํ•˜๋Š” form ํ™”๋ฉด์ด ๋œฌ๋‹ค.  ์•„๋ฌด ์ •๋ณด๋‚˜ ์ž…๋ ฅํ•  ๊ฒฝ์šฐ fail ํ™”๋ฉด์ด ๋ณด์ธ๋‹ค. ์ž…๋ ฅ๊ฐ’์„ ํ†ตํ•ด JSON ๋ฐ์ดํ„ฐ๋ฅผ ํŒŒ์‹ฑํ•ด์˜ค๋Š” ๋ฌธ์ œ๋กœ ๋ณด์ธ๋‹ค.  (2) ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ  flag.cํ”Œ๋ž˜๊ทธ๋Š” flag.c ํŒŒ์ผ์„ ์‹คํ–‰์‹œํ‚ค๋ฉด ์ถœ๋ ฅ๋˜์–ด ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. #include void main(){ puts("DH{**fake_flag**}\n");} ์‹ค์ œ๋กœ ๋„์ปค ํŒŒ์ผ์„ ํ™•์ธํ•ด๋ณด๋ฉด flag.c ํŒŒ..
[Dreamhack] Level 2: safe input
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/1671 safe inputDescription It's so safe that it can't be seen.dreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •๋ฌธ์ œ ํŽ˜์ด์ง€์— ์ ‘์†ํ•ด๋ณด๋ฉด /test๋กœ ์—ฐ๊ฒฐ๋œ๋‹ค.  ๋ฌธ์ œ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์•„๋ณด๋ฉด report์™€ test ํŽ˜์ด์ง€์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค.  ๋จผ์ € app.py ์ฝ”๋“œ๋Š” ์…€๋ ˆ๋‹ˆ์›€์„ ํ†ตํ•ด ํฌ๋กฌ ๋ธŒ๋ผ์šฐ์ €๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ฝ”๋“œ์ด๋‹ค.driver = webdriver.Chrome(service=service, options=options)driver.implicitly_wait(3)driver.set_page_load_timeout(3)driver.get(f"http://127.0.0.1:800..
[Dreamhack] Level 2: weblog-1
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/71 weblog-1์ฃผ์–ด์ง„ ์ฝ”๋“œ์™€ ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•ด ์ฃผ์–ด์ง„ ์งˆ๋ฌธ์— ํ•ด๋‹นํ•˜๋Š” ๋‹ต์„ ์ฐพ์•„๋ณด์„ธ์š”. Reference Server-side Basic Server-side Advanced - SQL Injectiondreamhack.io  2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ์ ‘์†- ๋จผ์ € ํƒˆ์ทจ๋œ admin ๊ณ„์ •์˜ PW๋ฅผ ์•Œ์•„๋‚ด๋Š” ๋ฌธ์ œ์˜€๋‹ค.  (2) ๋ฌธ์ œ ํŒŒ์ผ ๋ถ„์„  - ๋ฌธ์ œ ํŒŒ์ผ์„ ํ†ตํ•ด ๋กœ๊ทธ์ธ์˜ username๊ณผ password๊ฐ€ ์–ด๋–ค์‹์œผ๋กœ ์ž…๋ ฅ๋˜๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.  username ์•”ํ˜ธ Login ..
[Dreamhack] Level 1: basic_exploitation_001
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/3 basic_exploitation_001Description ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(basic_exploitation_001)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ์„ ์ฝ์œผ์„ธ์š”. "flag" ํŒŒ์ผ์˜ ๋‚ด์šฉdreamhack.io ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(basic_exploitation_001)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค.ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ์„ ์ฝ์œผ์„ธ์š”."flag" ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ์›Œ๊ฒŒ์ž„ ์‚ฌ์ดํŠธ์— ์ธ์ฆํ•˜๋ฉด ์ ์ˆ˜๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.ํ”Œ๋ž˜๊ทธ์˜ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค.2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ๋ฌธ์ œ ๋ถ„..
[Dreamhack] Level 2: TODO List 0.0.1
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/1533 TODO List 0.0.1 dreamhack.io*Dreamhack CTF Season 6 Round #8 (๐ŸŒฑDiv2) ์— ์ถœ์ œ2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ๋ถ„์„ ์ ‘์†ํ•˜๋ฉด ๋กœ๊ทธ์ธ๊ณผ ํšŒ์›๊ฐ€์ž… ํ•˜๋ผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ๋œฌ๋‹ค. ํšŒ์›๊ฐ€์ž…์€ username, ์ด๋ฉ”์ผ, ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ์ด๋ฃจ์–ด์ง„๋‹ค. test/ test@gmail.com /test1234๋กœ ํšŒ์›๊ฐ€์ž…ํ•œ ๋’ค ๋กœ๊ทธ์ธ์„ ์ง„ํ–‰ํ•ด๋ณด์•˜๋‹ค.๋‚˜์˜ ํˆฌ๋‘ ๋ฆฌ์ŠคํŠธ๋ฅผ ์ถ”๊ฐ€ํ•˜๋ผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ๋œฌ ๋’ค, ํˆฌ๋‘ ๋ฆฌ์ŠคํŠธ์˜ ์ œ๋ชฉ๊ณผ ๋‚ด์šฉ, ๋‚ ์งœ๋ฅผ ์ž…๋ ฅ๋ฐ›๋Š”๋‹ค.  ์ œ๋ชฉ : ๋‚ด์šฉ์œผ๋กœ ์ถœ๋ ฅ๋˜๋ฉฐ, ์ฒดํฌ๋ฐ•์Šค๋ฅผ ํ†ตํ•ด ์™„๋ฃŒํ•œ ์ผ์ •์— ๋Œ€ํ•ด ํ‘œ์‹œ๋ฅผ ํ•  ์ˆ˜ ์žˆ๋‹ค.๋‚ ์งœ๋ฅผ ์ž…๋ ฅ๋ฐ›์•˜๋Š”๋ฐ ๋‚ ์งœ ๋‚ด์šฉ์ด ์ถœ๋ ฅ๋˜์ง€๋Š” ์•Š๋Š” ๊ฒƒ ๊ฐ™๋‹ค. (2)..
[์Šคํ”„๋ง ๋ถ€ํŠธ ์›น ๊ฐœ๋ฐœ ์ž…๋ฌธ - ๋”ฐ๋ผํ•˜๋ฉฐ ๋ฐฐ์šฐ๊ธฐ] ์„น์…˜4, 5
ยท
Programming/spring
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[์Šคํ”„๋ง ๋ถ€ํŠธ ์›น ๊ฐœ๋ฐœ ์ž…๋ฌธ - ๋”ฐ๋ผํ•˜๋ฉฐ ๋ฐฐ์šฐ๊ธฐ] ์„น์…˜3
ยท
Programming/spring
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[์Šคํ”„๋ง ๋ถ€ํŠธ ์›น ๊ฐœ๋ฐœ ์ž…๋ฌธ - ๋”ฐ๋ผํ•˜๋ฉฐ ๋ฐฐ์šฐ๊ธฐ] ์„น์…˜2
ยท
Programming/spring
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[Dreamhack] Beginner: shell_basic
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
์‰˜์ฝ”๋“œ ์ž‘์„ฑํ•ด๋ณด๊ธฐ (2)
ยท
Study/Pwnable
1.execve ์‰˜์ฝ”๋“œ์‰˜์€ ์šด์˜์ฒด์ œ๋ฅผ ๊ฐ์‹ธ๊ณ  ์žˆ๋Š” ๊ป์งˆ์ด๋‹ค.์ฆ‰, ์‚ฌ์šฉ์ž๊ฐ€ ์šด์˜์ฒด์ œ์— ๋ช…๋ น์„ ๋‚ด๋ฆฌ๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ์‚ฌ์šฉ์ž์˜ ์ธํ„ฐํŽ˜์ด์Šค๋กœ,  ์‰˜์„ ํš๋“ํ•˜๋ฉด ์‹œ์Šคํ…œ์„ ์ œ์–ดํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๋ฏ€๋กœ ํ†ต์ƒ์ ์œผ๋กœ ์…ธ ํš๋“์„ ์‹œ์Šคํ…œ ํ•ดํ‚น์˜ ์„ฑ๊ณต์œผ๋กœ ์—ฌ๊ธฐ๋Š” ๊ฒƒ์ด๋‹ค. execve ์…ธ์ฝ”๋“œ๋Š” ์ž„์˜์˜ ํ”„๋กœ๊ทธ๋žจ์„ ์‹คํ–‰ํ•˜๋Š” ์‰˜์ฝ”๋“œ์ธ๋ฐ, ์ด๋ฅผ ์ด์šฉํ•ด์„œ execve("/bin/sh") ์™€ ๊ฐ™์€ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰์‹œ์ผœ ์„œ๋ฒ„์˜ ์‰˜์„ ํš๋“ํ•  ์ˆ˜ ์žˆ๋‹ค.//๋”ฐ๋ผ์„œ ๋‹ค๋ฅธ ์–ธ๊ธ‰์—†์ด ์…ธ์ฝ”๋“œ๋ผ๊ณ  ํ•˜๋ฉด ์ด๋ฅผ ์˜๋ฏธํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ๋‹ค. ์ตœ์‹ ์˜ ๋ฆฌ๋ˆ…์Šค๋Š” ๋Œ€๋ถ€๋ถ„ sh, bash๋ฅผ ๊ธฐ๋ณธ ์…ธ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ํƒ‘์žฌํ•˜๊ณ  ์žˆ์œผ๋ฉฐ, ์ด ์™ธ์—๋„ zsh, tsh ๋“ฑ์˜ ์…ธ์„ ์œ ์ €๊ฐ€ ์„ค์น˜ํ•ด์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค.  Ubuntu 22.04์—๋„ /bin/sh๊ฐ€ ์กด์žฌํ•˜๋ฏ€๋กœ, ์ด๋ฅผ ์‹คํ–‰ํ•˜๋Š” execve..
mnzy๐ŸŒฑ
'๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (2 Page)
-->