[Dreamhack] Level 1: proxy-1
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/13 proxy-1 Raw Socket Sender๊ฐ€ ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. ์š”๊ตฌํ•˜๋Š” ์กฐ๊ฑด์„ ๋งž์ถฐ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด 127.0.01 ๋กœ์ปฌํ˜ธ์ŠคํŠธ์ผ ๊ฒฝ์šฐ์—๋งŒ admin ์ ‘๊ทผ์„ ํ—ˆ๋ฝํ•œ๋‹ค. ์ฆ‰, Burp suite๋ฅผ ์ด์šฉํ•ด์„œ ์กฐ์ž‘ํ•  ์ˆ˜ ์—†์„ ๊ฒƒ์ด๋‹ค. @app.route('/admin', methods=['POST']) def admin(): if request.remote_addr != '127.0.0.1': return 'Only localhost' i..
abex’ crackme #4, 5
ยท
Study/Reversing
1. abex’ crackme #4 ์‹คํ–‰ํ•ด๋ณด๋‹ˆ ์‹œ๋ฆฌ์–ผ ๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๋ผ๋Š” ์ฐฝ์ด ๋œฌ๋‹ค. ๊ฐ’์„ ์ œ๋Œ€๋กœ ์ž…๋ ฅํ•˜์ง€ ์•Š์œผ๋ฉด Registered ๋ฒ„ํŠผ์ด ํ™œ์„ฑํ™”๋˜์ง€ ์•Š๋Š”๋‹ค. ๋”ฐ๋ผ์„œ, ์ด ์‹œ๋ฆฌ์–ผ ๋ฒˆํ˜ธ๋ฅผ ์•Œ์•„๋‚ด์•ผ ํ•œ๋‹ค. Immunity Debugger๋ฅผ ์ด์šฉํ•ด ๋””๋ฒ„๊น…ํ•ด๋ณผ ๊ฒƒ์ด๋‹ค. VB ์—”์ง„์˜ ๋ฉ”์ธํ•จ์ˆ˜(ThunRTMain)๋ฅผ ํ˜ธ์ถœ(CALL)๋˜๋Š” ๊ฒƒ์„ ๋ณด์•„ visual basicํŒŒ์ผ์ด๋‹ค. ์ ‘๊ทผ ๋ฐฉ์‹์„ ๋ชจ๋ฅด๊ฒ ์–ด์„œ ์‚ฌ์šฉํ•˜๋Š” ํ•จ์ˆ˜๋“ค์„ ํ™•์ธํ•ด๋ณด์•˜๋‹ค. ์‚ฌ์šฉํ•˜๋Š” ํ•จ์ˆ˜์˜ ๋ชฉ๋ก์„ ๋ณด๋ฉด __vbaStrCmp ํ•จ์ˆ˜๊ฐ€ ์žˆ๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ์ด ํ•จ์ˆ˜๋Š” ๋ฌธ์ž์—ด ๋น„๊ต ๊ฒฐ๊ณผ๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” Variant (Integer)๋ฅผ ๋ฐ˜ํ™˜ํ•œ๋‹ค. https://learn.microsoft.com/en-us/office/vba/language/reference/use..
[Dreamhack] Level 3: XSS Filtering Bypass Advanced
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/434 XSS Filtering Bypass Advanced Description Exercise: XSS Filtering Bypass์˜ ํŒจ์น˜๋œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.04 Dockerfile ์ œ๊ณต dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • ๋ฌธ์ œ ํŽ˜์ด์ง€์™€ ์ „๋ฐ˜์ ์ธ ์ฝ”๋“œ๋Š” ๋‹ค๋ฅธ xss ๋ฌธ์ œ์™€ ๊ฐ™๋‹ค. ํ•„ํ„ฐ๋ง ๋ถ€๋ถ„์˜ ์ฝ”๋“œ๋ฅผ ์‚ดํŽด๋ณด์•„์•ผ ํ•œ๋‹ค. ์ผ๋‹จ, script, on, javascript๋Š” ๋ชจ๋‘ ํ•„ํ„ฐ๋งํ•˜๊ณ  ์žˆ๋‹ค. ์ฆ‰, ์™€ location href, onerror, ๋“ฑ์ด ํ•„ํ„ฐ๋ง ๋œ๋‹ค. ์ถ”๊ฐ€๋กœ window ๋“ฑ์ด ํ•„ํ„ฐ๋ง ๋˜์–ด์žˆ๋‹ค. document.cookie alert(document["\u0063ook" + "ie..
[Dreamhack] Level 1: XSS Filtering Bypass
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/433 XSS Filtering Bypass Description Exercise: XSS Filtering Bypass์—์„œ ์‹ค์Šตํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ 2023.08.04 Dockerfile ์ œ๊ณต dreamhack.io 2. ํ•ด๊ฒฐ๊ณผ์ • ์ „๋ฐ˜์ ์ธ ์ฝ”๋“œ๋Š” ๋“œ๋ฆผํ•ต ๋‚ด์˜ xss ๋ฌธ์ œ์˜ ์ฝ”๋“œ์™€ ๋น„์Šทํ•˜๋‹ค. ํ•˜์ง€๋งŒ ํ•ด๋‹น ์ฝ”๋“œ๋Š” ๋ฌธ์ž์—ด์„ ๊ณต๋ฐฑ์œผ๋กœ ํ•„ํ„ฐ๋งํ•˜๋Š” ์ฝ”๋“œ๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ๋‹ค. def xss_filter(text): _filter = ["script", "on", "javascript:"] for f in _filter: if f in text.lower(): text = text.replace(f, "") return tex..
[Dreamhack] Level 1: xss-2
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/268 xss-2 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. ํ”Œ๋ž˜๊ทธ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค. ๋ฌธ์ œ ์ˆ˜์ • ๋‚ด์—ญ dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • xss-1๊ณผ ์ฝ”๋“œ๋Š” ๋น„์Šทํ•˜์ง€๋งŒ, ํฐ ์ฐจ์ด์ ์ด ์žˆ๋‹ค. @app.route("/vuln") def vuln(): return render_template("vuln.html") ์ด ๋ถ€๋ถ„์ด๋‹ค. ๋™์ ์œผ๋กœ ํ…œํ”Œ๋ฆฟ์„ ๋ Œ๋”๋งํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ด์ „ xss-1์—์„œ๋Š” ํŒŒ๋ฆฌ๋ฏธํ„ฐ๋ฅผ ์ง์ ‘ ๋ฐ˜ํ™˜ํ•˜๋Š” ๋ฐฉ์‹๊ณผ ๋‹ค๋ฅด๋‹ค. ๋”ฐ๋ผ์„œ, vuln ํŽ˜์ด์ง€์—์„œ ๋‹ค์–‘ํ•œ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋„ฃ์–ด ์–ด๋–ค ํƒœ๊ทธ๊ฐ€ ์‹คํ–‰..
XSS ๊ณต๊ฒฉ ๋ฐฉ์–ด์™€ ์šฐํšŒ
ยท
Study/WebHacking
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[ํ˜ผ๊ณต ๋จธ์‹ ๋Ÿฌ๋‹+๋”ฅ๋Ÿฌ๋‹] k-ํ‰๊ท 
ยท
Study/AI
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[ํ˜ผ๊ณต ๋จธ์‹ ๋Ÿฌ๋‹+๋”ฅ๋Ÿฌ๋‹] ํŠธ๋ฆฌ์˜ ์•™์ƒ๋ธ”
ยท
Study/AI
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[ํ˜ผ๊ณต ๋จธ์‹ ๋Ÿฌ๋‹+๋”ฅ๋Ÿฌ๋‹] ํ™•๋ฅ ์  ๊ฒฝ์‚ฌ ํ•˜๊ฐ•๋ฒ•
ยท
์นดํ…Œ๊ณ ๋ฆฌ ์—†์Œ
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[ํ˜ผ๊ณต ๋จธ์‹ ๋Ÿฌ๋‹+๋”ฅ๋Ÿฌ๋‹] ๋กœ์ง€์Šคํ‹ฑ ํšŒ๊ท€
ยท
Study/AI
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
mnzy๐ŸŒฑ
'๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (6 Page)
-->