๋””์ง€ํ„ธ ํฌ๋ Œ์‹ 4์ฃผ์ฐจ ์Šคํ„ฐ๋””
ยท
Study/Forensics
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ 3์ฃผ์ฐจ ์Šคํ„ฐ๋””
ยท
Study/Forensics
ํ•ด๋‹น ๊ฐ•์˜๋ฅผ ์ˆ˜๊ฐ•ํ•˜๋ฉฐ ์ •๋ฆฌํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค. [๋ฌด๋ฃŒ] ๊ธฐ์ดˆ๋ถ€ํ„ฐ ๋”ฐ๋ผํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ - ์ธํ”„๋Ÿฐ | ๊ฐ•์˜ ๊ธฐ์ดˆ๋ถ€ํ„ฐ ๋”ฐ๋ผํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ ๊ฐ•์˜์ž…๋‹ˆ๋‹ค. ๊ฐ•์˜๋ฅผ ๋”ฐ๋ผํ•˜๋‹ค๋ณด๋ฉด "๋ฌผ ํ๋ฅด๋“ฏ, ์ž์—ฐ์Šค๋Ÿฝ๊ฒŒ" ์‹ค๋ ฅ์ด ๋Š˜์–ด๊ฐ€๋Š” ๊ฐ•์˜๋ฅผ ์ถ”๊ตฌํ•ฉ๋‹ˆ๋‹ค., ์ดˆ๋ณด์ž ๋ˆˆ๋†’์ด์— ๋”ฑ ๋งž์ถ˜, ์›๋ฆฌ๋ฅผ ์ดํ•ดํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ ์ž… www.inflearn.com 1. ์œˆ๋„์šฐ ์•„ํ‹ฐํŒฉํŠธ (Windows Artifacts) Windows๊ฐ€ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ํŠน์œ ์˜ ๊ธฐ๋Šฅ๋“ค๊ณผ ๊ทธ ๊ธฐ๋Šฅ์„ ๊ตฌํ˜„ํ•˜๋Š”๋ฐ ํ•„์š”ํ•œ ์š”์†Œ Windows์˜ ์‚ฌ์šฉ์ž๊ฐ€ ์ˆ˜ํ–‰ํ•˜๋Š” ํ™œ๋™์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋ณด์œ ํ•˜๊ณ  ์žˆ๋Š” ๊ฐœ์ฒด ์ปดํ“จํ„ฐ์—์„œ ์•„ํ‹ฐํŒฉํŠธ๋ž€ ์‚ฌ์šฉ์ž๊ฐ€ ์–ด๋–ค ํ™œ๋™์„ํ–ˆ์„ ๋•Œ ์ž๋™์œผ๋กœ ์ƒ์„ฑ์ด ๋˜๋Š” ํŠน์ • ํฌ๋งท์˜ "ํ”์ " ์ด๋ผ๊ณ  ์ƒ๊ฐ ํ•˜๋ฉด ๋จ ์ฃผ๋กœ ์•„ํ‹ฐํŒฉํŠธ์—๋Š” ์ƒ์„ฑ์ฆ๊ฑฐ์™€ ๋ณด๊ด€์ฆ๊ฑฐ๋กœ ๋‚˜๋‰จ ์ƒ์„ฑ ์ฆ๊ฑฐ: ํ”„๋กœ์„ธ์Šค, ์‹œ์Šค..
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ 2์ฃผ์ฐจ ์Šคํ„ฐ๋””
ยท
Study/Forensics
ํ•ด๋‹น ๊ฐ•์˜๋ฅผ ์ˆ˜๊ฐ•ํ•˜๋ฉฐ ์ •๋ฆฌํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค. [๋ฌด๋ฃŒ] ๊ธฐ์ดˆ๋ถ€ํ„ฐ ๋”ฐ๋ผํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ - ์ธํ”„๋Ÿฐ | ๊ฐ•์˜ ๊ธฐ์ดˆ๋ถ€ํ„ฐ ๋”ฐ๋ผํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ ๊ฐ•์˜์ž…๋‹ˆ๋‹ค. ๊ฐ•์˜๋ฅผ ๋”ฐ๋ผํ•˜๋‹ค๋ณด๋ฉด "๋ฌผ ํ๋ฅด๋“ฏ, ์ž์—ฐ์Šค๋Ÿฝ๊ฒŒ" ์‹ค๋ ฅ์ด ๋Š˜์–ด๊ฐ€๋Š” ๊ฐ•์˜๋ฅผ ์ถ”๊ตฌํ•ฉ๋‹ˆ๋‹ค., ์ดˆ๋ณด์ž ๋ˆˆ๋†’์ด์— ๋”ฑ ๋งž์ถ˜, ์›๋ฆฌ๋ฅผ ์ดํ•ดํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ ์ž… www.inflearn.com 1. ๋„๊ตฌ ์„ค์น˜, ํ™˜๊ฒฝ ์„ค์ •, ๋ฌธ์ œ ๋‹ค์šด๋กœ๋“œ (1) volatility ์„ค์น˜ https://www.volatilityfoundation.org/26 -> ํฌ๋กฌ์—์„œ ํ•˜๋ฉด ์„ค์น˜ ๋ถˆ๊ฐ€๋Šฅ. ์›จ์ผ์—์„œ ์„ค์น˜ ์ง„ํ–‰ (2) windows ํ„ฐ๋ฏธ๋„ ์„ค์น˜ - ์œˆ๋„์šฐ11์—๋Š” ๊ธฐ๋ณธ์œผ๋กœ ์„ค์น˜๋˜์–ด ์žˆ์Œ Windows Terminal ์‚ฌ์šฉ๋ฒ• Windows Terminal์ด ์ƒˆ๋กญ๊ฒŒ(?) ๋‚˜์™”๋‹ค.Linux๋‚˜ MacOS์— ๋น„ํ•ด..
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ 1์ฃผ์ฐจ ์Šคํ„ฐ๋””
ยท
Study/Forensics
ํ•ด๋‹น ๊ฐ•์˜๋ฅผ ์ˆ˜๊ฐ•ํ•˜๋ฉฐ ์ •๋ฆฌํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค. [๋ฌด๋ฃŒ] ๊ธฐ์ดˆ๋ถ€ํ„ฐ ๋”ฐ๋ผํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ - ์ธํ”„๋Ÿฐ | ๊ฐ•์˜ ๊ธฐ์ดˆ๋ถ€ํ„ฐ ๋”ฐ๋ผํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ ๊ฐ•์˜์ž…๋‹ˆ๋‹ค. ๊ฐ•์˜๋ฅผ ๋”ฐ๋ผํ•˜๋‹ค๋ณด๋ฉด "๋ฌผ ํ๋ฅด๋“ฏ, ์ž์—ฐ์Šค๋Ÿฝ๊ฒŒ" ์‹ค๋ ฅ์ด ๋Š˜์–ด๊ฐ€๋Š” ๊ฐ•์˜๋ฅผ ์ถ”๊ตฌํ•ฉ๋‹ˆ๋‹ค., ์ดˆ๋ณด์ž ๋ˆˆ๋†’์ด์— ๋”ฑ ๋งž์ถ˜, ์›๋ฆฌ๋ฅผ ์ดํ•ดํ•˜๋Š” ๋””์ง€ํ„ธํฌ๋ Œ์‹ ์ž… www.inflearn.com ๊ฐ•์˜ ์ง„ํ–‰ ์ „ ์ค€๋น„ ์‚ฌํ•ญ - C ๋“œ๋ผ์ด๋ธŒ ์ด์™ธ์— D, E ๋“œ๋ผ์ด๋ธŒ ๋“ฑ ์ถ”๊ฐ€ ๋“œ๋ผ์ด๋ธŒ๊ฐ€ ์กด์žฌํ•ด์•ผ ํ•จ - ์ถ”๊ฐ€ ๋“œ๋ผ์ด๋ธŒ๊ฐ€ ์—†๋‹ค๋ฉด, USB๊ฐ€ 1๊ฐœ ์ด์ƒ ์กด์žฌํ•ด์•ผ ํ•จ ํ•ด๋‹น ๊ฐ•์˜์—์„œ๋Š” ์ปดํ“จํ„ฐ, ๋””์Šคํฌ, ๋ฉ”๋ชจ๋ฆฌ๋ฅผ ๋‹ค๋ฃฐ ๊ฒƒ! (ํฌ๋ Œ์‹์—์„œ ๊ธฐ์ˆ ์ ์ธ ๋ถ€๋ถ„๋งŒ) - ์‹ค์Šต์— ํ•„์š”ํ•œ 7zip, Everthing, notepad++, HxD, FTK Imager ์ด๋ฏธ ์„ค์น˜๋œ ์ƒํƒœ์—์„œ ์‹œ์ž‘ - sysinternals s..
Netflix and AWS
ยท
ETC/Issues
https://aws.amazon.com/ko/blogs/security/introducing-first-video-new-series-verified-featuring-netflix-jason-chan/ Introducing the first video in our new series, Verified, featuring Netflix’s Jason Chan | Amazon Web Services The year has been a profoundly different one for us all, and like many of you, I’ve been adjusting, both professionally and personally, to this “new normal.” Here at AWS we’..
[Dreamhack] Level 1: php-1
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/46 php-1 php๋กœ ์ž‘์„ฑ๋œ Back Office ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. LFI ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” /var/www/uploads/flag.php์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Server-side Basic dreamhack.io - ํ”Œ๋ž˜๊ทธ๊ฐ€ /var/www/uploads/flag.php์— ์กด์žฌํ•œ๋‹ค๊ณ  ๋ฌธ์ œ์— ์ œ์‹œ๋˜์–ด์žˆ๋‹ค. - LFI ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜๋ผ๊ณ  ๋ฌธ์ œ์— ๋ช…์‹œ๋˜์–ด ์žˆ๋‹ค. 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ - ๋‹ค์šด๋กœ๋“œ ํ›„ ์••์ถ•์„ ํ’€์–ด์ฃผ์—ˆ๋‹ค. 4๊ฐœ์˜ php ํŒŒ์ผ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. - ํ•ด๋‹น ํŒŒ์ผ์„ vscode๋ฅผ ํ†ตํ•ด ์—ด์–ด๋ณด์•˜๋‹ค. - index.php ์œ„ ์ฝ”๋“œ์—์„œ๋Š” index.php์—์„œ๋Š” G..
[์ทจ์•ฝ์ ] File Inclusion ์ทจ์•ฝ์ : LFI (Local File Inclusion)
ยท
Study/WebHacking
LFI(Local File Inclusion) ์ทจ์•ฝ์ ์ด๋ž€? LFI๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ํ†ตํ•ด ์„œ๋ฒ„์˜ ํŒŒ์ผ์„ ๋ถˆ๋Ÿฌ์˜ค๊ฑฐ๋‚˜ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜๋Š” ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด๋‹ค. ์ด ์ทจ์•ฝ์ ์€ PHP์™€ ๊ฐ™์€ ์„œ๋ฒ„ ์ธก ์Šคํฌ๋ฆฝํŠธ ์–ธ์–ด์—์„œ ๋ฐœ๊ฒฌ๋˜๋ฉฐ, ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ์ž…๋ ฅ ๊ฒ€์ฆ ๋ถ€์กฑ์œผ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•œ๋‹ค. ์ฃผ๋กœ php ์ฝ”๋“œ์ƒ์—์„œ include() ์‚ฌ์šฉ ์‹œ input์— ๋Œ€ํ•œ ์ ์ ˆํ•œ ํ•„ํ„ฐ๋ง์ด ์ด๋ฃจ์–ด์ง€์ง€ ์•Š์•„ ๋ฐœ์ƒํ•œ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์ด ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜์—ฌ ์›น ์„œ๋ฒ„์—์„œ ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ์ฝ๊ฑฐ๋‚˜, ๋กœ์ปฌ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ๋ณด์•ˆ์„ ์šฐํšŒํ•˜๊ณ  ์‹œ์Šคํ…œ์„ ์†์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค. include($_GET['file'] . '.php'); ์œ„ ์ฝ”๋“œ๋Š” ์‚ฌ์šฉ์ž ์ž…๋ ฅ($_GET['file'])์„ ๊ฒ€์ฆํ•˜์ง€ ์•Š๊ณ  ํŒŒ์ผ์„ includeํ•œ๋‹ค. ์ด๋•Œ, ๊ณต๊ฒฉ์ž๊ฐ€ URL์„ ์กฐ์ž‘ํ•˜์—ฌ ..
[3์ฃผ์ฐจ] Django ๊ณผ์ œ2
ยท
Study
ํ•ด๋‹น ํ™”๋ฉด์€ ์˜ˆ์‹œ์ž…๋‹ˆ๋‹ค. ๋””ํ…Œ์ผ์ด ์ฝ”๋“œ๋งˆ๋‹ค ์กฐ๊ธˆ ๋‹ค๋ฅผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. 1. form ์ ์šฉ ํ™”๋ฉด 2. detail.html ์ฝ”๋“œ {% csrf_token %} {{ question.question_text }} {% if error_message %}{{ error_message }}{% endif %} {% for choice in question.choice_set.all %} {{ choice.choice_text }} {% endfor %} 3. ๊ณผ์ œ2: ์œ„ html ์ฝ”๋“œ๋ฅผ ์ ์šฉํ•œ ํ™”๋ฉด ์บก์ณ (form ์ ์šฉ) + ์ฝ”๋“œ ์„ค๋ช… * ์ฝ”๋“œ ์„ค๋ช…์— ๊ผญ ๋“ค์–ด๊ฐ€์•ผ ํ•  ๋‚ด์šฉ (ํ•„์ˆ˜) - ๋ฐ์ดํ„ฐ์˜ ํ๋ฆ„์— ๋Œ€ํ•œ ์„ค๋ช… csrf_token์ด๋ž€? ์‚ฌ์šฉ์ž๊ฐ€ ์„œ๋ฒ„๋กœ ์–ด๋–ป๊ฒŒ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๋‚ผ๊นŒ์š”? (input type๊ณผ submit..
[3์ฃผ์ฐจ] Django View ์‹ค์Šต
ยท
Study
๋ทฐ(view) ๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ "๋กœ์ง"์„ ๋„ฃ๋Š” ๊ณณ์ž…๋‹ˆ๋‹ค. ์ฆ‰, View๋Š” ํ•„์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ชจ๋ธ (ํ˜น์€ ์™ธ๋ถ€)์—์„œ ๊ฐ€์ ธ์™€์„œ ์ ์ ˆํžˆ ๊ฐ€๊ณตํ•˜์—ฌ ์›น ํŽ˜์ด์ง€ ๊ฒฐ๊ณผ๋ฅผ ๋งŒ๋“ค๋„๋ก ์ปจํŠธ๋กคํ•˜๋Š” ์—ญํ• ์„ ํ•˜๋Š”๊ฑฐ์ฃ ! ๋ทฐ๋Š” ์–ด๋ ค์›Œ๋ณด์ด์ง€๋งŒ ์‚ฌ์‹ค ํŒŒ์ด์ฌ ํ•จ์ˆ˜์ผ ๋ฟ์ž…๋‹ˆ๋‹ค. ๋ทฐ๋“ค์€ Django App์•ˆ์˜ views.py ๋ผ๋Š” ํŒŒ์ผ์— ์ •์˜ํ•˜๊ฒŒ ๋˜๋Š”๋ฐ, ๊ฐ ํ•จ์ˆ˜๊ฐ€ ํ•˜๋‚˜์˜ View๋ฅผ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” views๋ฅผ polls/views.py ํŒŒ์ผ ์•ˆ์— ์ถ”๊ฐ€ํ•˜๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. 1. polls/view.py ์ˆ˜์ • (๊ธฐ์กด ์ฝ”๋“œ์—์„œ ๋ฐ‘์˜ ์ฝ”๋“œ ์ถ”๊ฐ€) view๋Š” request๋ผ๋Š” ์ธ์ž๋ฅผ ๊ฐ–๊ณ , HttpResponse()๋ผ๋Š” ๋ฆฌํ„ด๊ฐ’์„ ๊ฐ€์ง„๋‹ค. ํด๋ผ์ด์–ธํŠธ๋กœ๋ถ€ํ„ฐ ์—ฌ๋Ÿฌ๊ฐ€์ง€ ์ •๋ณด๊ฐ€ ๋‹ด๊ธด request๋ฅผ ๋ฐ›๊ณ , ํ–‰๋™์„ ๋งˆ์นœ ํ›„ HttpResponse() ์‘๋‹ต..
๋„คํŠธ์›Œํฌ๊ด€๋ฆฌ์‚ฌ 2๊ธ‰ ํ•„๊ธฐ/์‹ค๊ธฐ ํ›„๊ธฐ (ํ•ฉ๊ฒฉ ๊ฟ€ํŒ ๋ฐ ๊ณต๋ถ€๋ฒ•)
ยท
Study/CS
0. ๋„คํŠธ์›Œํฌ๊ด€๋ฆฌ์‚ฌ๋ฅผ ๋ณด๊ฒŒ ๋œ ์ด์œ ์‚ฌ์‹ค ์ €๋Š”,,, ๋„คํŠธ์›Œํฌ๊ฐ€ ๋„ˆ๋ฌด ์–ด๋ ต๋”๋ผ๊ตฌ์š”. ๊ธฐ์กด์— ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด๋“ค์„ ๋ฐฐ์šธ ๋•Œ์—๋Š” ๊ฒฐ๊ณผ๋ฌผ์ด ๋”ฑ๋”ฑ ๋‚˜์˜ค๋‹ˆ๊นŒ ๋ญ๊ฐ€ ๋ญ”์ง€ ๋ฐ”๋กœ ๊ฐ์ด ์žกํžˆ๋Š”๋ฐ ํŠนํžˆ ๋„คํŠธ์›Œํฌ๋‚˜ ์šด์˜์ฒด์ œ ์ด๋Ÿฐ๊ฒƒ๋“ค์€ ๋ชจ์กฐ๋ฆฌ ๋‹ค ์–ด๋ ค์› ์–ด์š”. ์ €๋ฒˆํ•™๊ธฐ์— ๋„คํŠธ์›Œํฌ ๊ณผ๋ชฉ์ด ์žˆ์—ˆ๋Š”๋ฐ ๊ณต๋ถ€ํ•˜๋Š”๋ฐ์— ์–ด๋ ค์›€์„ ๋Š๋ผ๊ณ  ํ—ˆ์šฐ์ ๋Œ€๋‹ค๊ฐ€ ๊ฒฐ๊ตญ์—๋Š” ๊ณต๋ถ€๋ฅผ ์ œ๋Œ€๋กœ ๋ชปํ•˜๊ณ  ํ•™๊ธฐ๋ฅผ ๋งˆ๋ฌด๋ฆฌํ•ด์•ผํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ '์ด๋ฒˆํ•™๊ธฐ์—๋Š” ๋ญ๋ผ๋„ ์ข€ ํ•ด๋ณด์ž!' ํ•ด์„œ ๋„คํŠธ์›Œํฌ๊ด€๋ฆฌ์‚ฌ ์ž๊ฒฉ์ฆ์„ ์ƒ๊ฐํ•˜๊ฒŒ ๋์Šต๋‹ˆ๋‹ค. ์‚ฌ์‹ค ์—„์ฒญ ์–ด๋ ค์šด ์ž๊ฒฉ์ฆ๋„ ์•„๋‹ˆ๊ณ , ์ด๊ฑธ ๋”ด๋‹ค๊ณ  ์ŠคํŽ™ ์ƒ์—์„œ ๊ต‰์žฅํžˆ ๋ฉ”๋ฆฌํŠธ๊ฐ€ ์žˆ์„์ง€๋Š”...? ์Œ.. ์•ž์„œ ๋งํ•œ ๊ฒƒ๋“ค์ด ๋ชฉํ‘œ๋ผ๋ฉด ๋‹ค๋ฅธ ์ž๊ฒฉ์ฆ์„ ์•Œ์•„๋ณด๋Š” ๊ฑธ ์ถ”์ฒœ๋“œ๋ ค์š”์ œ ์ƒ๊ฐ์— ๋„ค๊ด€์‚ฌ 2๊ธ‰์€ ์ €์ฒ˜๋Ÿผ ๋„คํŠธ์›Œํฌ ๊ณต๋ถ€๋ฅผ ์• ๋งคํ•˜๊ฒŒ ํ•œ ํ•™์ƒ๋ถ„๋“ค์ด ๋‹ค์‹œ ๊ณต๋ถ€๋ฅผ ํ•˜๋ฉด์„œ ..
mnzy๐ŸŒฑ
'๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (8 Page)
-->