[Dreamhack] Level 3: Movie time table
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[Dreamhack] Level 3: Pybrid
ยท
CTF, War game
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[Dreamhack] Level 4: PATCH-1
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/70 PATCH-1์ฃผ์–ด์ง„ ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•˜๊ณ , ํ•ด๋‹น ์ฝ”๋“œ์— ์กด์žฌํ•˜๋Š” ์ทจ์•ฝ์ ๋“ค์„ ํŒจ์น˜ํ•ด๋ณด์„ธ์š”. ๋ฌธ์ œ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์„ค๋ช…์€ /usage ํŽ˜์ด์ง€๋ฅผ ํ™•์ธํ•˜์—ฌ ๋ณด์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๋ชจ๋“  ํŒจ์น˜๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆdreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ์ ‘์†Usage ํŽ˜์ด์ง€์— ๋ฌธ์ œ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์„ค๋ช…์ด ์ ํ˜€์žˆ๋‹ค.์ฃผ์–ด์ง„ ์ฝ”๋“œ (๋ฌธ์ œ ํŒŒ์ผ)๋ฅผ ์ˆ˜์ •ํ•˜์—ฌ ์ทจ์•ฝ์ ์„ ํŒจ์น˜ํ•œ ๋’ค ์ œ์ถœํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค.  ์ด๋•Œ, ์ˆ˜์ • ๊ฐ€๋Šฅํ•œ ์ฝ”๋“œ๋Š” app,py ํŒŒ์ผ ํ•˜๋‚˜์ด๋‹ค.  (2) ์ฝ”๋“œ ๋ถ„์„ ์ „์ฒด ์ฝ”๋“œ ๋”๋ณด๊ธฐ#!/usr/bin/python3from flask import Flask, request, render_template_..
[wargame.kr] Level 3: dun worry about the vase
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/325 [wargame.kr] dun worry about the vaseDescription Do you know about "padding oracle vulnerability" ?dreamhack.io ์ด ๋ฌธ์ œ๋Š” Pading Oracle ์ทจ์•ฝ์ ์— ๋Œ€ํ•œ ๋ฌธ์ œ์ž„์„ ๋ช…์‹œํ•˜๊ณ  ์žˆ๋‹ค.๋”ฐ๋ผ์„œ ๋ฌธ์ œ๋ฅผ ํ’€๊ธฐ์ „ ํŒจ๋”ฉ ์˜ค๋ผํด ์ทจ์•ฝ์ ์— ์ •๋ฆฌํ•˜์˜€๋‹ค. 2025.03.07 - [Study/WebHacking] - Padding Oracle ์ทจ์•ฝ์ 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ์ ‘์† ๋กœ๊ทธ์ธ form์ด ๋ณด์ด๊ณ  guest/guest๊ฐ€ ๊ธฐ๋ณธ๊ฐ’์œผ๋กœ ์ž…๋ ฅ๋˜์–ด ์žˆ๋‹ค.   ๊ฐ’ ๊ทธ๋Œ€๋กœ ๋กœ๊ทธ์ธ์„ ํ•˜๋ฉด admin ์„ธ์…˜์„ ์–ป์œผ๋ผ๋Š” ๋‚ด์šฉ์ด ์ถœ๋ ฅ๋œ๋‹ค. ์„ธ์…˜ ๊ฐ’์€ ..
[wargame.kr] Level 2: crack crack crack it
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/330 [wargame.kr] crack crack crack itDescription .htaccess crack! can you local bruteforce attack?dreamhack.io 2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ํ™•์ธ htpasswd ํŒŒ์ผ์„ ๋ถ„์„ํ•ด์„œ Brute Force๋ฅผ ํ†ตํ•ด ํŒจ์Šค์›Œ๋“œ๋ฅผ ์•Œ์•„๋‚ด์•ผ ํ•˜๋Š” ๋ฌธ์ œ์ด๋‹ค. htpasswd ํŒŒ์ผ์€ ์ผ๋ฐ˜์ ์œผ๋กœ HTTP ์ธ์ฆ์„ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ํŒŒ์ผ์ด๋‹ค. $์•Œ๊ณ ๋ฆฌ์ฆ˜$์†”ํŠธ$ํ•ด์‹œ๋œ๋น„๋ฐ€๋ฒˆํ˜ธ์œผ๋กœ ๊ตฌ์„ฑ๋œ๋‹ค. ์ด๋•Œ ํŒจ์Šค์›Œ๋“œ๋Š” ํ•ด์‹œํ™”๋˜์–ด ์ €์žฅ๋˜๊ธฐ ๋•Œ๋ฌธ์— G4HeulB๋กœ ์‹œ์ž‘ํ•œ๋‹ค๋Š” ํžŒํŠธ๋ฅผ ํ†ตํ•ด ์ตœ๋Œ€ํ•œ ํšจ์œจ์ ์œผ๋กœ ๋ธŒ๋ฃจํŠธ ํฌ์Šค ๊ณต๊ฒฉ์„ ์‚ฌ์šฉํ•ด์„œ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์•Œ์•„๋‚ด์•ผ ํ•œ๋‹ค. username..
[Dreamhack] Level 3: Switching Command
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/1081 Switching CommandDescription Not Friendly service... Can you switching the command?dreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ์ ‘์†- username์„ ์ž…๋ ฅํ•˜๋Š” form ํ™”๋ฉด์ด ๋œฌ๋‹ค.  ์•„๋ฌด ์ •๋ณด๋‚˜ ์ž…๋ ฅํ•  ๊ฒฝ์šฐ fail ํ™”๋ฉด์ด ๋ณด์ธ๋‹ค. ์ž…๋ ฅ๊ฐ’์„ ํ†ตํ•ด JSON ๋ฐ์ดํ„ฐ๋ฅผ ํŒŒ์‹ฑํ•ด์˜ค๋Š” ๋ฌธ์ œ๋กœ ๋ณด์ธ๋‹ค.  (2) ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ  flag.cํ”Œ๋ž˜๊ทธ๋Š” flag.c ํŒŒ์ผ์„ ์‹คํ–‰์‹œํ‚ค๋ฉด ์ถœ๋ ฅ๋˜์–ด ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. #include void main(){ puts("DH{**fake_flag**}\n");} ์‹ค์ œ๋กœ ๋„์ปค ํŒŒ์ผ์„ ํ™•์ธํ•ด๋ณด๋ฉด flag.c ํŒŒ..
[Dreamhack] Level 2: safe input
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/1671 safe inputDescription It's so safe that it can't be seen.dreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ •๋ฌธ์ œ ํŽ˜์ด์ง€์— ์ ‘์†ํ•ด๋ณด๋ฉด /test๋กœ ์—ฐ๊ฒฐ๋œ๋‹ค.  ๋ฌธ์ œ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์•„๋ณด๋ฉด report์™€ test ํŽ˜์ด์ง€์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค.  ๋จผ์ € app.py ์ฝ”๋“œ๋Š” ์…€๋ ˆ๋‹ˆ์›€์„ ํ†ตํ•ด ํฌ๋กฌ ๋ธŒ๋ผ์šฐ์ €๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ฝ”๋“œ์ด๋‹ค.driver = webdriver.Chrome(service=service, options=options)driver.implicitly_wait(3)driver.set_page_load_timeout(3)driver.get(f"http://127.0.0.1:800..
[Dreamhack] Level 2: weblog-1
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/71 weblog-1์ฃผ์–ด์ง„ ์ฝ”๋“œ์™€ ๋กœ๊ทธ๋ฅผ ๋ถ„์„ํ•ด ์ฃผ์–ด์ง„ ์งˆ๋ฌธ์— ํ•ด๋‹นํ•˜๋Š” ๋‹ต์„ ์ฐพ์•„๋ณด์„ธ์š”. Reference Server-side Basic Server-side Advanced - SQL Injectiondreamhack.io  2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ๋ฌธ์ œ ์ ‘์†- ๋จผ์ € ํƒˆ์ทจ๋œ admin ๊ณ„์ •์˜ PW๋ฅผ ์•Œ์•„๋‚ด๋Š” ๋ฌธ์ œ์˜€๋‹ค.  (2) ๋ฌธ์ œ ํŒŒ์ผ ๋ถ„์„  - ๋ฌธ์ œ ํŒŒ์ผ์„ ํ†ตํ•ด ๋กœ๊ทธ์ธ์˜ username๊ณผ password๊ฐ€ ์–ด๋–ค์‹์œผ๋กœ ์ž…๋ ฅ๋˜๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.  username ์•”ํ˜ธ Login ..
[Dreamhack] Level 2: TODO List 0.0.1
ยท
CTF, War game
1. ๋ฌธ์ œhttps://dreamhack.io/wargame/challenges/1533 TODO List 0.0.1 dreamhack.io*Dreamhack CTF Season 6 Round #8 (๐ŸŒฑDiv2) ์— ์ถœ์ œ2. ํ•ด๊ฒฐ ๊ณผ์ •(1) ๋ฌธ์ œ ํŽ˜์ด์ง€ ๋ถ„์„ ์ ‘์†ํ•˜๋ฉด ๋กœ๊ทธ์ธ๊ณผ ํšŒ์›๊ฐ€์ž… ํ•˜๋ผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ๋œฌ๋‹ค. ํšŒ์›๊ฐ€์ž…์€ username, ์ด๋ฉ”์ผ, ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ์ด๋ฃจ์–ด์ง„๋‹ค. test/ test@gmail.com /test1234๋กœ ํšŒ์›๊ฐ€์ž…ํ•œ ๋’ค ๋กœ๊ทธ์ธ์„ ์ง„ํ–‰ํ•ด๋ณด์•˜๋‹ค.๋‚˜์˜ ํˆฌ๋‘ ๋ฆฌ์ŠคํŠธ๋ฅผ ์ถ”๊ฐ€ํ•˜๋ผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ๋œฌ ๋’ค, ํˆฌ๋‘ ๋ฆฌ์ŠคํŠธ์˜ ์ œ๋ชฉ๊ณผ ๋‚ด์šฉ, ๋‚ ์งœ๋ฅผ ์ž…๋ ฅ๋ฐ›๋Š”๋‹ค.  ์ œ๋ชฉ : ๋‚ด์šฉ์œผ๋กœ ์ถœ๋ ฅ๋˜๋ฉฐ, ์ฒดํฌ๋ฐ•์Šค๋ฅผ ํ†ตํ•ด ์™„๋ฃŒํ•œ ์ผ์ •์— ๋Œ€ํ•ด ํ‘œ์‹œ๋ฅผ ํ•  ์ˆ˜ ์žˆ๋‹ค.๋‚ ์งœ๋ฅผ ์ž…๋ ฅ๋ฐ›์•˜๋Š”๋ฐ ๋‚ ์งœ ๋‚ด์šฉ์ด ์ถœ๋ ฅ๋˜์ง€๋Š” ์•Š๋Š” ๊ฒƒ ๊ฐ™๋‹ค. (2)..
[Dreamhack] Level 2: youth-Case
ยท
CTF, War game
1. ๋ฌธ์ œ https://dreamhack.io/wargame/challenges/1402 youth-CaseDescription Bypass ๐Ÿ‘จโ€๐Ÿ’ปfilterdreamhack.io2. ํ•ด๊ฒฐ ๊ณผ์ • (1) ์ฝ”๋“œ ๋ถ„์„ ์ „์— ํ‘ผ baby-case ๋ฌธ์ œ์˜ ์—…๊ทธ๋ ˆ์ด๋“œ ๋ฒ„์ „์ด๋‹ค.2024.08.19 - [CTF, War game] - [Dreamhack] Level 1: baby-Case ์ฝ”๋“œ๋Š” ์ „์ฒด์ ์ธ ๊ธฐ๋Šฅ์€ ๋™์ผํ•˜๊ณ  , app.set('case sensitive routing', true) ์„ค์ •์„ ํ†ตํ•ด ๋Œ€์†Œ๋ฌธ์ž๋ฅผ ๊ตฌ๋ถ„ํ•˜์—ฌ ์ฒ˜๋ฆฌํ•˜๊ฒŒ ๋œ๋‹ค. (๋Œ€์†Œ๋ฌธ์ž๋ฅผ ์ด์šฉํ•œ ์šฐํšŒ ๋ถˆ๊ฐ€๋Šฅ)๋˜ํ•œ ์š”์ฒญ์—์„œ leg์˜ ๊ฐ’์„ ๋ฐ›์•„์˜ฌ ๋•Œ ์†Œ๋ฌธ์ž๋กœ ๋ฐ˜ํ™˜ํ•˜์—ฌ ๋ฐ›์•„์˜ค๊ณ  ์ด ๊ฐ’์ด flag๋ผ๋ฉด access denied๋ฅผ ๋„์šด๋‹ค.words์—์„œ ๋ฌธ์ž์—ด..
mnzy๐ŸŒฑ
-->