[PHP] Type Juggling ์ทจ์•ฝ์ 
ยท
Study/WebHacking
PHP๋Š” ๋น„๊ต ์—ฐ์‚ฐ์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด == ์—ฐ์‚ฐ์ž์™€  === ์—ฐ์‚ฐ์ž๋ฅผ ์ง€์›ํ•œ๋‹ค.์ด๋•Œ, PHP๋Š” ๋‘ ๊ฐ’์„ ๋น„๊ตํ•˜๊ธฐ ์ „์— ํ•„์š”์— ๋”ฐ๋ผ ํƒ€์ž…์„ ๋ณ€ํ™˜ํ•œ๋‹ค.์ด๋Ÿฌํ•œ ๋ณ€ํ™˜์€ ์˜๋„ํ•˜์ง€ ์•Š์€ ๋ฐฉ์‹์œผ๋กœ ์ž‘๋™ํ•˜์—ฌ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ๋ฐœ์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค. loose (๋Š์Šจํ•œ) ๋น„๊ต ==     vs    strict (์—„๊ฒฉํ•œ) ๋น„๊ต === ==: ๋‘ ๊ฐ’์˜ ํƒ€์ž…์ด ๋‹ค๋ฅด๋ฉด ํƒ€์ž…์„ ๋ณ€ํ™˜ํ•œ ํ›„ ๋น„๊ต (์ฆ‰, ๊ฐ’๋งŒ ๋น„๊ต)===: ๋‘ ๊ฐ’์˜ ํƒ€์ž…๊ณผ ๊ฐ’ ๋ชจ๋‘ ๊ฐ™์•„์•ผ TRUE ๋ฆฌํ„ด ๊ธฐ๋ณธ ์˜ˆ์ œ var_dump(0 == '0'); // truevar_dump(0 == '0.0'); // truevar_dump(0 == ''); // truevar_dump(0 == null); // truevar_dump(0 == 'string'); // true (PHP..
[Dreamhack] Level 3: chocoshop
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/106 chocoshopDescription ๋“œ๋ฆผ์ด๋Š” ๋นผ๋นผ๋กœ๋ฐ์ด๋ฅผ ๋งž์•„ ํ‹ฐ์˜ค๋ฆฌ์ œ๊ณผ์—์„œ ๋นผ๋นผ๋กœ ๊ตฌ๋งค๋ฅผ ์œ„ํ•œ ์ฟ ํฐ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์šฐ๋ฆฌ์˜ ๋ชฉ์ ์€ FLAG! ๊ทธ๋Ÿฐ๋ฐ ์ด๋Ÿฐ, FLAG๋Š” ๋„ˆ๋ฌด ๋น„์‹ธ ์‚ด ์ˆ˜๊ฐ€ ์—†๋„ค์š”... ์ฟ ํฐ์„ ์—ฌ๋Ÿฌ ๋ฒˆ ๋ฐœ๊ธ‰dreamhack.io ๋“œ๋ฆผ์ด๋Š” ๋นผ๋นผ๋กœ๋ฐ์ด๋ฅผ ๋งž์•„ ํ‹ฐ์˜ค๋ฆฌ์ œ๊ณผ์—์„œ ๋นผ๋นผ๋กœ ๊ตฌ๋งค๋ฅผ ์œ„ํ•œ ์ฟ ํฐ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค.ํ•˜์ง€๋งŒ ์šฐ๋ฆฌ์˜ ๋ชฉ์ ์€ FLAG! ๊ทธ๋Ÿฐ๋ฐ ์ด๋Ÿฐ, FLAG๋Š” ๋„ˆ๋ฌด ๋น„์‹ธ ์‚ด ์ˆ˜๊ฐ€ ์—†๋„ค์š”...์ฟ ํฐ์„ ์—ฌ๋Ÿฌ ๋ฒˆ ๋ฐœ๊ธ‰๋ฐ›๊ณ  ์‹ถ์—ˆ๋Š”๋ฐ ์ด๊ฒƒ๋„ ๋ถˆ๊ฐ€๋Šฅํ•ด์š”. ๋‚ด๋ถ€์ž ๋ง์— ์˜ํ•˜๋ฉด ์‚ฌ์šฉ๋œ ์ฟ ํฐ์„ ๊ฒ€์‚ฌํ•˜๋Š” ๋กœ์ง์ด ์ทจ์•ฝํ•˜๋‹ค๋Š”๋ฐ,๋“œ๋ฆผ์ด๋ฅผ ๋„์™€ FLAG๋ฅผ ๊ตฌ๋งคํ•˜์„ธ์š”!2. ํ•ด๊ฒฐ ๊ณผ์ •secret.pyfrom os impor..
[Dreamhack] Level 2: Dream Gallery
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/552 Dream Gallery๋“œ๋ฆผ์ด๋Š” ๊ฐค๋Ÿฌ๋ฆฌ ์‚ฌ์ดํŠธ๋ฅผ ๊ตฌ์ถ•ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ๋ฐ ์™ธ๋ถ€๋กœ ์š”์ฒญํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์•ˆ์ „ํ•œ ๊ฑด์ง€ ๋ชจ๋ฅด๊ฒ ๋‹ค๊ณ  ํ•˜๋„ค์š”... ๊ฐค๋Ÿฌ๋ฆฌ ์‚ฌ์ดํŠธ์—์„œ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  flag๋ฅผ ํš๋“ํ•˜์„ธ์š”! flag๋Š” /flag.txt์— ์žˆ์Šต๋‹ˆ๋‹ค.dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ •/ -> /view๋กœ ๋ฆฌ๋‹ค์ด๋ ‰ํŠธ ๋œ๋‹ค. /view์—์„œ๋Š” mini_database ๋ฆฌ์ŠคํŠธ์— ํฌํ•จ๋˜์–ด ์žˆ๋Š” ์ด๋ฏธ์ง€๋ฅผ ๋ณด์—ฌ์ค€๋‹ค. @app.route('/')def index(): return redirect(url_for('view'))@app.route('/view')def view(): return render_template('view.html', ..
[Dreamhack] Level 2: Relative Path Overwrite Advanced
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/440 Relative Path Overwrite AdvancedDescription Exercise: Relative Path Overwrite์˜ ํŒจ์น˜๋œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.10 bot.py ์ˆ˜์ •, Dockerfile ์ œ๊ณตdreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • ๊ธฐ๋ณธ์ ์ธ ์ฝ”๋“œ๋Š” Relative Path Overwrite์™€ ๊ฑฐ์˜ ๋™์ผํ•˜๋‹ค.  index.php์˜ ์ฝ”๋“œ์ด๋‹ค. GET๋ฐฉ์‹์œผ๋กœ page๋ฅผ ๋ฐ›๊ณ , ์ด page์— ..์ด๋‚˜ : ๋˜๋Š” / ์ด ํฌํ•จ๋˜๋Š”์ง€ ํ™•์ธํ•œ๋‹ค. ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š๋Š”๋‹ค๋ฉด ํ•ด๋‹น ํŒŒ์ผ์„ include ํ•œ๋‹ค.  Relative-Path-O..
[Dreamhack] Level 2: sql injection bypass WAF Advanced
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/416 sql injection bypass WAF AdvancedDescription Exercise: SQL Injection Bypass WAF์˜ ํŒจ์น˜๋œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.07.24 Dockerfile ์ œ๊ณตdreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •init.sql admin์˜ ํŒจ์Šค์›Œ๋“œ๊ฐ€ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด๋‹ค. INSERT INTO user(uid, upw) values('abcde', '12345');INSERT INTO user(uid, upw) values('admin', 'DH{**FLAG**}');INSERT INTO user(uid, upw) values('guest', 'guest');INSERT INT..
[๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค] ๋” ์•Œ์•„๋ณด๊ธฐ
ยท
Study/CS
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค] - MySQL CRUD
ยท
Study/CS
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค] MySQL ํ…Œ์ด๋ธ”์˜ ์ƒ์„ฑ
ยท
Study/CS
ํ•ด๋‹น ๊ฐ•์˜๋ฅผ ์ˆ˜๊ฐ•ํ•˜๋ฉฐ ์ •๋ฆฌํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค. [๋ฌด๋ฃŒ] DATABASE 1&2 - MySQL - ์ธํ”„๋Ÿฐ | ๊ฐ•์˜์ •๋ณด๊ธฐ์ˆ ์˜ ์‹ฌ์žฅ์ธ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋Œ€ํ•œ ํฌ๊ด„์ ์ธ ์†Œ๊ฐœ๋ฅผ ๋‹ด๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ๋ณธ์งˆ์„ ๊ณต๋ถ€ํ•˜๋ฉฐ ๊ฐ€์žฅ ๋Œ€ํ‘œ์ ์ธ ๊ด€๊ณ„ํ˜• ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์ธ MYSQL ์„ ํ•™์Šตํ•ด ๋ด…๋‹ˆ๋‹ค., [์ž„๋ฒ ๋”ฉ ์˜์ƒ] ๊ฐ•์ขŒwww.inflearn.com1. ํ…Œ์ด๋ธ” ์ƒ์„ฑ์ฐธ๊ณ ํ•œ cheat sheet: https://windtrap.tistory.com/m/119 (1) ํ…Œ์ด๋ธ” ์ƒ์„ฑCREATE TABLE ํ…Œ์ด๋ธ”์ด๋ฆ„๋ฐ์ดํ„ฐ์˜ ํƒ€์ž…INT: ์ •์ˆ˜VARCHAR: ์ •ํ•ด์ง„ ๊ธธ์ด๋งŒํผ๋งŒ ๋ฌธ์ž์—ด์„ ์ €์žฅํ•จ DATATIME: ๋‚ ์งœ์™€ ์‹œ๊ฐ„์„ ๋ชจ๋‘ ์ถœ๋ ฅํ•ด์คŒ ('0000-00-00 00:00:00')(): ๋ฐ์ดํ„ฐ๋ฅผ ๋ช‡ ์ž๋ฆฌ๊นŒ์ง€ '์ถœ๋ ฅ'ํ• ๊ฒƒ์ธ์ง€_VARCHAR์€ ์ €์žฅ!N..
[๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค] MySQL ๊ธฐ๋ณธ
ยท
Study/CS
ํ•ด๋‹น ๊ฐ•์˜๋ฅผ ์ˆ˜๊ฐ•ํ•˜๋ฉฐ ์ •๋ฆฌํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค. [๋ฌด๋ฃŒ] DATABASE 1&2 - MySQL - ์ธํ”„๋Ÿฐ | ๊ฐ•์˜์ •๋ณด๊ธฐ์ˆ ์˜ ์‹ฌ์žฅ์ธ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋Œ€ํ•œ ํฌ๊ด„์ ์ธ ์†Œ๊ฐœ๋ฅผ ๋‹ด๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ๋ณธ์งˆ์„ ๊ณต๋ถ€ํ•˜๋ฉฐ ๊ฐ€์žฅ ๋Œ€ํ‘œ์ ์ธ ๊ด€๊ณ„ํ˜• ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์ธ MYSQL ์„ ํ•™์Šตํ•ด ๋ด…๋‹ˆ๋‹ค., [์ž„๋ฒ ๋”ฉ ์˜์ƒ] ๊ฐ•์ขŒwww.inflearn.com0. Mysql ์„ค์น˜ https://www.mysql.com/products/community/ MySQL :: MySQL Community EditionMySQL Community Edition MySQL Community Edition is the freely downloadable version of the world's most popular open source database...
[์ปดํ“จํ„ฐ๊ตฌ์กฐ] ํ”„๋กœ๊ทธ๋žจ ์‹คํ–‰ ๊ณผ์ • (gcc ์ปดํŒŒ์ผ๋Ÿฌ)
ยท
Study/CS
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
mnzy๐ŸŒฑ
'๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (3 Page)
-->