๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Welcome.

:: DreamHack ๐Ÿšฉ18

[ dreamhack ] - [systemhacking | shell_basic] ๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€ ์ž…๋‹ˆ๋‹ค. 2022. 9. 4.
[ dreamhack ] - [ reversing | rev-basic-7] https://dreamhack.io/wargame/challenges/21/ rev-basic-7 Reversing Basic Challenge #7 ์ด ๋ฌธ์ œ๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฌธ์ž์—ด ์ž…๋ ฅ์„ ๋ฐ›์•„ ์ •ํ•ด์ง„ ๋ฐฉ๋ฒ•์œผ๋กœ ์ž…๋ ฅ๊ฐ’์„ ๊ฒ€์ฆํ•˜์—ฌ correct ๋˜๋Š” wrong์„ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ correct๋ฅผ ์ถœ dreamhack.io ์ด๋ฒˆ ๋ฆฌ๋ฒ„์‹ฑ ๋ฌธ์ œ๋„ ์ด์ „๊ณผ ์œ ํ˜•์€ ๋น„์Šทํ•˜๋‹ค. ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ๋””์ปดํŒŒ์ผ๋œ ์ฝ”๋“œ์—์„œ if๋ฌธ์˜ ์กฐ๊ฑด๋ฌธ์„ ํ™•์ธํ•˜์—ฌ Correct๋ฅผ ์ถœ๋ ฅํ•˜๊ฒŒ ํ•˜๋Š” ์ž…๋ ฅ๊ฐ’์„ ์ฐพ์•„๋‚ด๋Š” ๊ฒƒ์ด๋‹ค. if ๋ฌธ์˜ ์กฐ๊ฑด๋ฌธ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. (i ^ (unsigned __int8)__ROL1__(*(_BYTE *)(a1 + i), i & 7)) != byte_140003000[i] ์ด ์‹์„ ๋น„๊ต์  .. 2022. 6. 1.
[ dreamhack ] - [ reversing | rev-basic-6] https://dreamhack.io/wargame/challenges/20/ rev-basic-6 Reversing Basic Challenge #6 ์ด ๋ฌธ์ œ๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฌธ์ž์—ด ์ž…๋ ฅ์„ ๋ฐ›์•„ ์ •ํ•ด์ง„ ๋ฐฉ๋ฒ•์œผ๋กœ ์ž…๋ ฅ๊ฐ’์„ ๊ฒ€์ฆํ•˜์—ฌ correct ๋˜๋Š” wrong์„ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ correct๋ฅผ ์ถœ dreamhack.io ์ด๋ฒˆ rev-basic-6 ๋ฌธ์ œ๋„ ์ด์ „ ๋ฌธ์ œ๋“ค๊ณผ ๊ฐ™์€ ์œ ํ˜•์ด๋‹ค. ์ด๋ฒˆ์—๋„ ์—ญ์‹œ if ์ ˆ์— ์กด์žฌํ•˜๋Š” ์กฐ๊ฑด๋ฌธ์„ ๋ถ„์„ํ•˜์—ฌ ํŠน์ • ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ๋งŒ๋“ค์–ด์„œ ์—ญ์œผ๋กœ Correct๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ์ž…๋ ฅ๊ฐ’์„ ์ฐพ์•„๋‚ด์•ผ ํ•œ๋‹ค. ์กฐ๊ฑด๋ฌธ์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. byte_140003020[*(unsigned __int8 *)(a1 + i)] != byte_140003000[i] ์ด ์ฝ”๋“œ๋ฅผ ๊ฐ„.. 2022. 5. 31.
[ dreamhack ] - [ reversing | rev-basic-5 ] https://dreamhack.io/wargame/challenges/19/ rev-basic-5 Reversing Basic Challenge #5 ์ด ๋ฌธ์ œ๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฌธ์ž์—ด ์ž…๋ ฅ์„ ๋ฐ›์•„ ์ •ํ•ด์ง„ ๋ฐฉ๋ฒ•์œผ๋กœ ์ž…๋ ฅ๊ฐ’์„ ๊ฒ€์ฆํ•˜์—ฌ correct ๋˜๋Š” wrong์„ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ correct๋ฅผ ์ถœ dreamhack.io rev-basic-5 ๋ฌธ์ œ๋„ ์ด์ „๊นŒ์ง€์˜ rev-basic ๋ฌธ์ œ๋“ค๊ณผ ๋น„์Šทํ•œ ์œ ํ˜•์ด๋‹ค. if ์ ˆ์˜ ์กฐ๊ฑด๋ฌธ์„ ํ™•์ธํ•ด๋ณด๋ฉด, *(unsigned __int8 *)(a1 + i + 1) + *(unsigned __int8 *)(a1 + i) != byte_140003000[i] ๋ผ๊ณ  ๋˜์–ด ์žˆ๋Š”๋ฐ, ์ด๋ฅผ ๋ณด๊ธฐ ํŽธํ•˜๊ฒŒ ์ •๋ฆฌํ•˜์ž๋ฉด, a1[i+1] + a1[i] != .. 2022. 5. 31.
[ dreamhack ] - [ reversing | rev-basic-4 ] https://dreamhack.io/wargame/challenges/18/ rev-basic-4 Reversing Basic Challenge #4 ์ด ๋ฌธ์ œ๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฌธ์ž์—ด ์ž…๋ ฅ์„ ๋ฐ›์•„ ์ •ํ•ด์ง„ ๋ฐฉ๋ฒ•์œผ๋กœ ์ž…๋ ฅ๊ฐ’์„ ๊ฒ€์ฆํ•˜์—ฌ correct ๋˜๋Š” wrong์„ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ correct๋ฅผ ์ถœ dreamhack.io ์ด์ „ rev-basic ๋ฌธ์ œ๋“ค๊ณผ ๋น„์Šทํ•˜๋‹ค. ๋””์ปดํŒŒ์ผ๋œ main์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. sub_140001000 ํ•จ์ˆ˜๊ฐ€ ์ฐธ์ด๋˜๋ฉด Correct๊ฐ€ ์ถœ๋ ฅ๋˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ํ™•์ธํ•ด๋ณด๊ฒ ๋‹ค. for ๋ฌธ์„ 0x1C ๋ฒˆ, ์ฆ‰, 28๋ฒˆ ๋Œ๋ฆฌ๋Š”๋ฐ, ์กฐ๊ฑด๋ฌธ์€ ((unsigned __int8)(16 * *(_BYTE *)(a1 + i)) | ((int)*(unsigned __i.. 2022. 5. 30.
reversing | [CodeEngn] Malware L07 https://dreamhack.io/wargame/challenges/374/ [CodeEngn] Malware L07 ๋‹ค์Œ์€ ์•…์„ฑ์ฝ”๋“œ Flow์˜ ์ผ๋ถ€๋ถ„์ด๋‹ค. ๋ถ„์„๊ฒฐ๊ณผ ์ด ์•…์„ฑ์ฝ”๋“œ๋Š” ํŠน์ • ์‚ฌ์ดํŠธ์— ์ ‘์†์„ ์‹œ๋„ ํ•˜๊ณ  ์žˆ๋Š”๋ฐ ์ ‘์†์ด ์•ˆ๋ ๊ฒฝ์šฐ ๋ช‡์ดˆ ๋‹จ์œ„๋กœ ์žฌ์ ‘์†์„ ํ•œ๋‹ค. ๋ช‡ms ๋‹จ์œ„๋กœ ์žฌ์ ‘์†์„ ํ•˜๋Š”๊ฐ€ dreamhack.io ๋‹ค์Œ์€ ์•…์„ฑ์ฝ”๋“œ Flow์˜ ์ผ๋ถ€๋ถ„์ด๋‹ค. ๋ถ„์„๊ฒฐ๊ณผ ์ด ์•…์„ฑ์ฝ”๋“œ๋Š” ํŠน์ • ์‚ฌ์ดํŠธ์— ์ ‘์†์„ ์‹œ๋„ ํ•˜๊ณ  ์žˆ๋Š”๋ฐ ์ ‘์†์ด ์•ˆ๋ ๊ฒฝ์šฐ ๋ช‡์ดˆ ๋‹จ์œ„๋กœ ์žฌ์ ‘์†์„ ํ•œ๋‹ค. ๋ช‡ms ๋‹จ์œ„๋กœ ์žฌ์ ‘์†์„ ํ•˜๋Š”๊ฐ€ ๋ฌธ์ œ๋Š” ์œ„์™€ ๊ฐ™๋‹ค. ์ ‘์†์ด ์•ˆ๋  ๊ฒฝ์šฐ -> false๋กœ ์ด์–ด์ง€๋Š” ๋ถ€๋ถ„์„ ์ฐพ์•„๋ณผ ์ƒ๊ฐ์ธ๋ฐ ๋˜ํ•œ, ์žฌ์ ‘์† ์‚ฌ์ด์— ์‹œ๊ฐ„์„ ๋‘๋Š” ๊ฒƒ์„ ๋ณด๋‹ˆ sleep์„ ํ†ตํ•ด ๋ฉˆ์ท„๋‹ค๊ฐ€ ์ด์–ด์ง€๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ด๊ธฐ๋„ ํ•œ๋‹ค. ์ฝ”๋“œ๋“ค์„ ์‚ดํŽด๋ณด๋‹ค ๋ณด๋‹ˆ.. 2022. 5. 30.
[dreamhack] - [reversing | rev-basic-2] https://dreamhack.io/wargame/challenges/16/ rev-basic-2 Reversing Basic Challenge #2 ์ด ๋ฌธ์ œ๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฌธ์ž์—ด ์ž…๋ ฅ์„ ๋ฐ›์•„ ์ •ํ•ด์ง„ ๋ฐฉ๋ฒ•์œผ๋กœ ์ž…๋ ฅ๊ฐ’์„ ๊ฒ€์ฆํ•˜์—ฌ correct ๋˜๋Š” wrong์„ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ด ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ•ด๋‹น ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ correct๋ฅผ ์ถœ dreamhack.io ์‚ฌ์šฉ์ž๊ฐ€ ์–ด๋–ค ๊ฐ’์„ ์ž…๋ ฅํ–ˆ์„ ๋•Œ, ํ•ด๋‹น ์ž…๋ ฅ๊ฐ’์— ๋”ฐ๋ผ correct ํ˜น์€ wrong ์ด ์ถœ๋ ฅ๋˜๋Š” ํ”„๋กœ๊ทธ๋žจ์„ ๋ฆฌ๋ฒ„์‹ฑํ•˜์—ฌ correct๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ๊ฐ’์„ ์ฐพ์•„๋‚ด๋Š” ๋ฌธ์ œ์ด๋‹ค. Corect , Wrong ๋“ฑ์˜ ๋ฌธ์ž๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋•Œ, IDA์—์„œ ๋ฆฌ๋ฒ„์Šค๋””๋ฒ„๊น…ํ•œ c์ฝ”๋“œ์—์„œ printf ์™€ scanf ๋กœ ๋ณด์ด๋Š” ํ•จ์ˆ˜๋ฅผ ๋‹จ์ถ•ํ‚คN์„ ํ†ตํ•ด ์ด๋ฆ„์„ ๋ฐ”๊ฟ”์ฃผ์—ˆ๋‹ค. ๋˜ํ•œ.. 2022. 5. 30.
[ dreamhack ] - [ web | login-1 ] https://dreamhack.io/wargame/challenges/47/ login-1 python์œผ๋กœ ์ž‘์„ฑ๋œ ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์„ ๊ฐ€์ง„ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. "admin" ๊ถŒํ•œ์„ ๊ฐ€์ง„ ์‚ฌ์šฉ์ž๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. Reference Server-side Basic dreamhack.io #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for, session, g import sqlite3 import hashlib import os import time, random app = Flask(__name__) app.secret_key = os.urandom(32) DATABA.. 2022. 4. 25.
[ dreamhack ] - [ web | csrf-2 ] ์œ„์™€ ๊ฐ™์€ ๋ฌธ์ œ์ด๋‹ค. ์ฃผ์–ด์ง„ UR์— ์ ‘์†ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜จ๋‹ค. vuln, flag, login ํŽ˜์ด์ง€๊ฐ€ ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ํƒœ๊ทธ๊ฐ€ ํ•„ํ„ฐ๋ง ๋˜๊ณ  ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ๋‹ค๋ฅธ ํƒœ๊ทธ๋„ ํ•„ํ„ฐ๋ง ๋˜๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ํƒœ๊ทธ๋ฅผ ํ™•์ธํ•ด๋ณด์•˜๋‹ค. ํ•„ํ„ฐ๋ง์ด ๋˜์ง€ ์•Š์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. vulnํŽ˜์ด์ง€๋กœ ์ž…๋ ฅํ•œ ๊ฐ’์„ ์ธ์ž๊ฐ’์œผ๋กœ ๋„˜๊ธฐ๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. username ๊ณผ password ๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ๋กœ๊ทธ์ธํ•˜๋Š” ํŽ˜์ด์ง€์ด๋‹ค. guest / guest ๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„. guest ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์€ ์„ฑ๊ณตํ•˜์˜€์œผ๋‚˜ admin์€ ์•„๋‹ˆ๋ผ๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ๋“œ๋ฆผํ•ต์—์„œ ์ค€ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•˜์—ฌ ๋ณด๋ฉด, ์›น์‚ฌ์ดํŠธ ์ƒ์—์„œ๋Š” ํ™•์ธํ•  ์ˆ˜ ์—†์œผ๋‚˜, /change_password ๋ผ๋Š” ํŽ˜์ด์ง€๊ฐ€ ์กด์žฌํ•จ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ๋˜ํ•œ, /change_passw.. 2022. 4. 5.
[ dreamhack ] - [ web | csrf -1 ] ๋ฌธ์ œ๋Š” ์ด๋ ‡๋‹ค. csrf ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ flag๋ฅผ ์–ป์–ด๋‚ด๋Š” ๊ฒƒ์ด ๋ฌธ์ œ์ด๋‹ค. ์ฃผ์–ด์ง„ ๋งํฌ์— ์ ‘์†ํ•˜๋ฉด ์œ„ ๊ทธ๋ฆผ์ฒ˜๋Ÿผ 4๊ฐœ์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฉ”์ธ ํŽ˜์ด์ง€๊ฐ€ ๋œฌ๋‹ค. :: vuln(csrf) page :: ์œ„ ์‚ฌ์ง„์—์„œ ๋ณด๋ฉด, url์— get์œผ๋กœ ๋ณด๋‚ธ ๊ฐ€ ์ถœ๋ ฅ๋˜์—ˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋Š”๋ฐ, script ๋ผ๋Š” ๋ฌธ์ž์—ด์ด ํ•„ํ„ฐ๋ง๋˜๊ณ  ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. :: memo :: ์ด๋•Œ, hello๋ผ๋Š” ๋ฌธ์ž๊ฐ€ ์ถœ๋ ฅ๋˜๋Š”๋ฐ, ํ•œ๋ฒˆ ๋” ๋‹ค์‹œ ์ ‘์†ํ•˜๋ฉด, ์ด๋ ‡๊ฒŒ hello๊ฐ€ ๋‘๋ฒˆ ์ถœ๋ ฅ๋˜๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. :: notice_flag :: ์ ‘์† ๊ถŒํ•œ์ด ์—†์–ด์„œ Acees Denied ๊ฐ€ ๋ฐœ์ƒ์ค‘์ž„์„ ํ™•์ธ๊ฐ€๋Šฅํ•˜๋‹ค. notice_flag์ธ ๊ฑฐ๋กœ ๋ด์„œ๋Š” ์ด ํŽ˜์ด์ง€์— flag๊ฐ€ ์žˆ์ง€ ์•Š์„๊นŒ๋ผ๊ณ  ์ƒ๊ฐ๋œ๋‹ค. :: flag :: ์ด ํŽ˜์ด์ง€์— ๋ณด์ด๋Š” .. 2022. 3. 29.
[ dreamhack ] - [ web | image-storage ] ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์ ์— ๋Œ€ํ•œ ๋ฌธ์ œ๋กœ ๋ณด์ธ๋‹ค. ์ฃผ์–ด์ง„ ํŽ˜์ด์ง€๋กœ ์ ‘์†ํ•œ ํ›„, Upload ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ฉด ์œ„ ๊ทธ๋ฆผ์ฒ˜๋Ÿผ ํŒŒ์ผ์„ ์˜ฌ๋ฆด ์ˆ˜ ๊ฐ€ ์žˆ๋‹ค. ์ฃผ์–ด์ง„ php ์ฝ”๋“œ๋ฅด ๋ณด๋‹ˆ, ์—…๋กœ๋“œ ํŒŒ์ผ์— ๋Œ€ํ•œ ํ™•์žฅ์ž ํ•„ํ„ฐ๋ง์€ ์กด์žฌํ•˜์ง€ ์•Š๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ๊ทธ๋ž˜์„œ, php ์ฝ”๋“œ ํŒŒ์ผ์„ ๋งŒ๋“ค์–ด์„œ ์„œ๋ฒ„์˜ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋Š” ๋ช…๋ น์„ ์‹คํ–‰ํ•ด๋ณด๋„๋ก ํ•˜์ž. ๋จผ์ €, ๋ผ๊ณ  ์ฝ”๋“œ๋ฅผ ๋งŒ๋“ค์–ด์„œ ํ˜„์žฌ์œ„์น˜์—์„œ์˜ ํŒŒ์ผ๋“ค์„ ๋จผ์ € ์ถœ๋ ฅํ•ด๋ณด์ž. (ํŒŒ์ผ๋ช… : get_flag4.php) ์—…๋กœ๋“œ ์™„๋ฃŒ. list ํŽ˜์ด์ง€๋กœ ๊ฐ€์„œ ์—…๋กœ๋“œ๋œ get_flag4.php ๋ฅผ ํด๋ฆญ. !! ํŒŒ์ผ ๋ชฉ๋ก์ด ์ถœ๋ ฅ๋˜์—ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์•„์‰ฝ๊ฒŒ๋„ list์œ„์น˜์—๋Š” flag.txt๋Š” ์—†๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. flag.txt ๊ฐ€ ์–ด๋Š ์œ„์น˜์— ์žˆ๋Š”์ง€ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•ด ์ตœ์ƒ์œ„ ํด๋”๋ถ€ํ„ฐ ๋ฆฌ์ŠคํŠธ๋ฅผ ์ถœ๋ ฅํ•˜๋Š” .. 2022. 3. 17.
[ dreamhack ] - [ web | proxy-1 ] ์œ„์™€ ๊ฐ™์€ ๋ฌธ์ œ์ด๋‹ค. ์ ‘์†ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋œฌ๋‹ค. Raw Socket Sender ๋ฅผ ํด๋ฆญํ•˜์—ฌ ๋“ค์–ด๊ฐ€๋ฉด ์œ„์™€ ๊ฐ™์ด host, port, Data๋ฅผ ์ž…๋ ฅํ•˜์—ฌ Send ํ•  ์ˆ˜ ์žˆ๋Š”๋ฐ ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ flag๋ฅผ ์–ป์–ด๋‚ด์•ผ ํ•˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ๋จผ์ €, ํ…Œ์ŠคํŠธ์šฉ์œผ๋กœ 127.0.0.1 80 apple ์ด๋ผ๊ณ  ์ž…๋ ฅํ•˜๊ณ  Send ํ•ด๋ณด๊ฒ ๋‹ค. ์ด๋ฅผ ๋ฐ”๋กœ ๋ณด๋‚ด์ง€ ์•Š๊ณ  Burp Suite๋กœ ์žก์•„๋ณด๋ฉด ์œ„์ฒ˜๋Ÿผ http ํ—ค๋”์™€ ๋ฐ”๋””๊ฐ€ ๋ณด์ด๊ธดํ•˜๋Š”๋ฐ ์–ด๋Š ๋ถ€๋ถ„์—์„œ ํžŒํŠธ๋ฅผ ์–ป์–ด์•ผํ• ์ง€ ๋ชจ๋ฅด๊ฒ ์–ด์„œ ์ฃผ์–ด์ง„ ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด๋ด์•ผ๊ฒ ๋‹ค. ์ฝ”๋“œ๋ฅผ ์ž˜ ๋ณด๋‹ค๋ณด๋ฉด /admin ์œ„์น˜์— POST method ๋กœ ์œ„ if๋ฌธ๋“ค์„ ๋ชจ๋‘ ํ”ผํ•ด๊ฐ€๋ฉด ๋งˆ์ง€๋ง‰์— FLAG๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ์ด์ œ httpํ—ค๋”๋ฅผ ๋ณ€์กฐํ•˜์—ฌ ์œ„ ์กฐ๊ฑด์— ๋งž๊ฒŒ ๋ณด๋‚ด๋ฉด ๋  ๊ฒƒ ๊ฐ™๋‹ค. ์œ„์ฒ˜๋Ÿผ .. 2022. 3. 17.
[ dreamhack ] - [ web | command-injection-1 ] ์ž…๋ ฅํ•œ ip๋กœ ping ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. Host ์— ip๋ฅผ ์ž…๋ ฅํ•˜๊ณ  Ping! ์„ ๋ˆŒ๋Ÿฌ๋ณด์ž. ์ด๋ ‡๊ฒŒ 8.8.8.8 ๋กœ ping ๋ช…๋ น์ด ์‹คํ–‰๋œ ๊ณผ์ •์ด ๊ทธ๋Œ€๋กœ ์ถœ๋ ฅ๋œ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ๋‘๊ฐ€์ง€๋ฅผ ์•Œ ์ˆ˜ ์žˆ๋Š”๋ฐ, 1. ip๋ฅผ ์ž…๋ ฅํ•˜๋Š” ์นธ์ด ์šด์˜์ฒด์ œ๋ฅผ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์นธ์ด๋‹ค. 2. ๋ฆฌ๋ˆ…์Šค๋Š” ping ๋ช…๋ น์„ ์˜ต์…˜์—†์ด ์‹คํ–‰ํ•˜๋ฉด ๋ฌด์ œํ•œ์œผ๋กœ ํŒจํ‚ท์„ ๋ณด๋‚ด๋Š”๋ฐ, 3๊ฐœ์˜ ํŒจํ‚ท๋งŒ ๋ณด๋‚ธ๊ฒƒ์œผ๋กœ ๋ณด์•„, ping -c 3 8.8.8.8 ๋กœ ๋ช…๋ น์ด ์ž…๋ ฅ๋œ ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ์ด๋ฅผ ์ด์šฉํ•ด์„œ ping ๋ช…๋ น์„ ์ž…๋ ฅํ•˜๊ธฐ ์œ„ํ•ด ๋งŒ๋“ค์–ด์ ธ์žˆ๋Š” ์ž…๋ ฅ์นธ์— flag.py ๋ฅผ ์ฝ๊ธฐ ์œ„ํ•œ ์ฝ”๋“œ๋ฅผ ์ž…๋ ฅํ•  ์ƒ๊ฐ์ด๋‹ค. ๋“œ๋ฆผํ•ต์—์„œ ์ œ๊ณตํ•˜๋Š” ์ฝ”๋“œ๋ฅผ ๋ณด๋‹ˆ, ์ž…๋ ฅํ•œ ๊ฐ’์€ cmd = f'ping -c 3 "{host}"' ์ด๋ผ๋Š” ์ฝ”๋“œ๋ฅผ ํ†ตํ•ด ๋”๋ธ”์ฟผํ„ฐ ์‚ฌ.. 2022. 3. 16.
[ dreamhack ] - [web | file download ] ์ ‘์†ํ•˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋œฌ๋‹ค. [ Upload Your own Memo ]๋ฅผ ํด๋ฆญํ•˜๋ฉด ์œ„ ๊ทธ๋ฆผ์ฒ˜๋Ÿผ Filename ๊ณผ Content ๋ฅผ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š”๋ฐ, ์ผ๋‹จ ๋‚˜๋Š” ํ…Œ์ŠคํŠธ๋ฅผ ํ•ด๋ณด๊ธฐ ์œ„ํ•ด test1 / 1111์„ ์ž…๋ ฅํ•˜๊ณ  Upload๋ฅผ ๋ˆŒ๋Ÿฌ๋ณด๊ฒ ๋‹ค. ๋‚ด๊ฐ€ Filename์— ์ž…๋ ฅํ•œ ๊ฐ’์ด ์ œ๋ชฉ์ด ๋˜์–ด ์ €์žฅ๋œ ๊ฒƒ์„ ํ™•์ธ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ๋‚ด์šฉ ๋˜ํ•œ ์ €์žฅ๋˜์–ด์žˆ์Œ์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด ๋ฌธ์ œ๊ฐ€ [ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์  ]์— ๋Œ€ํ•œ ๋ฌธ์ œ์ด๋ฏ€๋กœ ์–ด๋Š ๋ถ€๋ถ„์—์„œ ๋‹ค์šด๋กœ๋“œ๊ฐ€ ์ด๋ฃจ์–ด์งˆ ์ˆ˜ ์žˆ๋Š”์ง€ ์ƒ๊ฐํ•ด๋ณด๋‹ˆ, ์ €์žฅ๋œ test1๊ธ€์„ ํด๋ฆญํ•˜์—ฌ ๋‚ด์šฉ์„ ํ™•์ธํ•  ๋•Œ, ์„œ๋ฒ„์˜ ํŒŒ์ผ ๋ชฉ๋ก์—์„œ ์ด๋ฆ„์ด test1์ธ ํŒŒ์ผ์„ ๋ถˆ๋Ÿฌ์˜ค๋Š” ๊ฒƒ์„ http://host2.dreamhack.games:17409/read?name=test1 ์ด url์˜ ๋’ท .. 2022. 3. 16.
[ dreamhack ] - [ web | pathtraversal ] ์ฒ˜์Œ ์ ‘์†ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋œฌ๋‹ค. geust๋ฅผ ์ž…๋ ฅํ•˜๊ณ  View๋ฅผ ๋ˆŒ๋ €์„ ๋•Œ ํ•ด๋‹น ์ •๋ณด๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. /api/flag ์— flag๊ฐ€ ์žˆ๋‹ค๊ณ  ํ–ˆ์œผ๋‹ˆ ์ƒ์œ„ ํด๋”๋กœ ์ด๋™์„ ์‹œ๋„ํ•˜๊ธฐ ์œ„ํ•ด ../ ๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ์ „์†กํ•ด๋ณด๊ฒ ๋‹ค. ../ ๋ผ๊ณ  ์ž…๋ ฅํ•œ ๊ฐ’์ด undefined ๋กœ ๋ฐ”๋€์ฑ„๋กœ ์ „์†ก๋จ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ../ ๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ์ „์†กํ–ˆ๋”๋‹ˆ ์œ„์™€ ๊ฐ™์€ html ์ฝ”๋“œ๊ฐ€ ์ถœ๋ ฅ๋˜์—ˆ๋‹ค. ../ ๊ฐ€ ์ธ์‹๋œ ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ๊ทธ๋Ÿผ ์ด๋ฒˆ์—๋Š” ../ ํ•œ๋ฒˆ์œผ๋กœ ์ตœ์ƒ์œ„ ํด๋”๊นŒ์ง€ ์ด๋™ํ• ๊ฑฐ ๊ฐ™์ง€ ์•Š์•„์„œ ../../ ๋ผ๊ณ  ์ž…๋ ฅํ•˜์—ฌ ๋‘ ๊ณ„์ธต์œ„์˜ ํด๋”๋กœ ์ด๋™์‹œ์ผœ๋ณด์•˜๋‹ค. ์ถœ๋ ฅ ๊ฐ’์— html ์ฝ”๋“œ๊ฐ€ ์ถœ๋ ฅ๋˜์—ˆ๋‹ค. ../../../ ๋„ ์ž…๋ ฅํ•˜์—ฌ ๋ณด์•˜์ง€๋งŒ ../../๋ฅผ ์ž…๋ ฅํ–ˆ์„ ๋•Œ์™€ ๊ฐ™์€ ์ฝ”๋“œ๊ฐ€ ์ถœ๋ ฅ๋˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์•„ ๋‘๋ฒˆ๋งŒ ์œ„ ๊ณ„์ธต์œผ๋กœ.. 2022. 3. 15.
728x90