728x90

[๋ฌธ์ œ]

https://webhacking.kr/challenge/web-32/

 

Challenge 18

 

webhacking.kr

 


[๋ฌธ์ œ ํ’€์ด]

  • ๋จผ์ € ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด์ž!
    • ๋จผ์ € ์ •๊ทœํ‘œํ˜„์‹์„ ์‚ฌ์šฉํ•ด ์ž…๋ ฅ๊ฐ’์— ํŠน์ • ๋ฌธ์ž์—ด์ด๋‚˜ ํŒจํ„ด์ด ํฌํ•จ๋˜์—ˆ๋Š”์ง€ ๊ฒ€์‚ฌํ•˜๋Š” ๋ฐ ์ฐจ๋‹จ ๋Œ€์ƒ์€ ๊ณต๋ฐฑ, ํŠน์ˆ˜๋ฌธ์ž, select, from ๊ฐ™์€ SQL ํ‚ค์›Œ๋“œ, 16์ง„์ˆ˜ ํ‘œํ˜„๋„ ์ฐจ๋‹จํ•œ๋‹ค.
    • ๊ทธ๋‹ค์Œ, chall18 ํ…Œ์ด๋ธ”์—์„œ id๊ฐ€ 'guest'์ด๊ณ  no๊ฐ€ ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ ๊ฐ’๊ณผ ์ผ์น˜ํ•˜๋Š” ํ–‰์„ ์กฐํšŒํ•œ๋‹ค. ์ด๋•Œ admin์˜ no๋Š” 2์ด๋‹ค.
    • result['id'] ๊ฐ’์ด "admin"์ผ ๊ฒฝ์šฐ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ ๊ฐ™๋‹ค.
  • ์šฐ์„ , id๊ฐ€ guest๋กœ ๊ณ ์ •๋˜์–ด ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด ๊ฐ’์„ ๊ฑฐ์ง“ ๊ฐ’์„ ๋„ฃ์–ด ์ด๋ฅผ ๋ฌดํšจํ™”ํ•˜๊ณ , or๋กœ admin์˜ no๋ฅผ ๋„ฃ์–ด์ฃผ์–ด admin ๊ฐ’์œผ๋กœ ์ ‘๊ทผํ•ด์•ผ ํ•œ๋‹ค.
  • ๊ทธ๋ž˜์„œ, sql๋ฌธ์ด select id from chall18 where id='guest' and no=-1 or no=2๊ฐ€ ๋˜๋ฉด ๋œ๋‹ค. 
  • ํ•˜์ง€๋งŒ, ์œ„์—์„œ ๊ณต๋ฐฑ์€ ํ•„ํ„ฐ๋ง์ด ๋˜๊ธฐ ๋•Œ๋ฌธ์— ๊ณต๋ฐฑ์˜ url encode ํ•œ ๊ฐ’์ธ %09๋ฅผ ๋„ฃ์–ด์„œ sql injection์„ ์‹œ๋„ํ•˜๋ฉด ๋œ๋‹ค.

  • ์ตœ์ข…์ ์œผ๋กœ, ์ด no=-1%09or%09no=2 ๊ฐ’์„ url์— ์ž…๋ ฅํ•ด ์ฃผ๋‹ˆ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-24 write-up  (0) 2025.01.12
[์›นํ•ดํ‚น] | [๋“œ๋ฆผํ•ต]: baby-Case  (0) 2025.01.11
[Webhacking.kr] old-26 write-up  (0) 2025.01.05
[์›นํ•ดํ‚น] | [๋“œ๋ฆผํ•ต]-Broken Buffalo Wings  (0) 2025.01.01
[Webhacking.kr] old-16 write-up  (0) 2024.12.29

+ Recent posts