728x90

[๋ฌธ์ œ]

https://dreamhack.io/wargame/challenges/938

 

Broken Buffalo Wings

Description Buffalo wings, also known as hot wings or chicken wings... Notice You can solve this problem with the intended solution, but there's also an easier way to do it! Take a look at the diff between the patched version and the original challenge. FY

dreamhack.io


[๋ฌธ์ œ ํ’€์ด]

  • ๋จผ์ € ๋ฌธ์ œ ์„ค๋ช… ๋ถ€๋ถ„์— Notice ๋ถ€๋ถ„์„ ๋ณด๋ฉด original๊ณผ ํŒจ์น˜๋œ ๋ฒ„์ „์˜ ์ฐจ์ด์ ์„ ์ด์šฉํ•˜๋ผ๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ๋ ค์ฃผ๊ณ  ์žˆ๋‹ค.
  • ๊ทธ๋ž˜์„œ, ๋ฆฌ๋ˆ…์Šค์˜ diff ๋ช…๋ น์–ด๋ฅผ ํ™œ์šฉํ•ด์„œ broken buffalo wings์™€ buffalo wings์˜ ํŒŒ์ผ์„ ๋น„๊ตํ•ด ๋ดค์Šต๋‹ˆ๋‹ค.

  • ๊ทธ ๊ฒฐ๊ณผ, ์ฐจ์ด์ ์œผ๋กœ flag.txt๋ฅผ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

  • flag.txt๋ฅผ ์ž…๋ ฅ์ฐฝ์— ์ž…๋ ฅํ•˜๋‹ˆ ๋ฐ”๋กœ flag๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-18 write-up  (0) 2025.01.05
[Webhacking.kr] old-26 write-up  (0) 2025.01.05
[Webhacking.kr] old-16 write-up  (0) 2024.12.29
[Webhacking.kr] old-15 write-up  (0) 2024.12.29
[Webhacking.kr] old-17 write-up  (0) 2024.12.22
728x90

[๋ฌธ์ œ]

https://webhacking.kr/challenge/js-3/

 

Challenge 16

 

webhacking.kr

 


[๋ฌธ์ œ ํ’€์ด]

<script> 
document.body.innerHTML+="<font color=yellow id=aa style=position:relative;left:0;top:0>*</font>";
function mv(cd){
  kk(star.style.left-50,star.style.top-50);
  if(cd==100) star.style.left=parseInt(star.style.left+0,10)+50+"px";
  if(cd==97) star.style.left=parseInt(star.style.left+0,10)-50+"px";
  if(cd==119) star.style.top=parseInt(star.style.top+0,10)-50+"px";
  if(cd==115) star.style.top=parseInt(star.style.top+0,10)+50+"px";
  if(cd==124) location.href=String.fromCharCode(cd)+".php"; // do it!
}
function kk(x,y){
  rndc=Math.floor(Math.random()*9000000);
  document.body.innerHTML+="<font color=#"+rndc+" id=aa style=position:relative;left:"+x+";top:"+y+" onmouseover=this.innerHTML=''>*</font>";
}
</script>
  • ๋จผ์ € ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด๋ฉด mvํ•จ์ˆ˜๋Š” ํ‚ค ์ž…๋ ฅ์— ๋”ฐ๋ผ ์›€์ง์ž„์„ ์ฒ˜๋ฆฌํ•˜๋Š” ํ•จ์ˆ˜์ž…๋‹ˆ๋‹ค.
  • cd๋Š” ASCII์ฝ”๋“œ๋กœ ์ „๋‹ฌ๋˜๋Š” ์ž…๋ ฅ ๊ฐ’์ž…๋‹ˆ๋‹ค.
    • d(100): ์˜ค๋ฅธ์ชฝ์œผ๋กœ 50px ์ด๋™
    • a(97): ์™ผ์ชฝ์œผ๋กœ 50px ์ด๋™
    • w(119): ์œ„๋กœ 50px ์ด๋™
    • s(115): ์•„๋ž˜๋กœ 50px ์ด๋™
  • ASCII ์ฝ”๋“œ๋กœ 124๋Š” |(ํŒŒ์ดํ”„)์ด๋‹ค.
    • | ํ‚ค๋ฅผ ๋ˆ„๋ฅด๋ฉด ์ƒˆ ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•œ๋‹ค.

  • |(ํŒŒ์ดํ”„) ํ‚ค๋ฅผ ๋ˆŒ๋ €๋”๋‹ˆ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-26 write-up  (0) 2025.01.05
[์›นํ•ดํ‚น] | [๋“œ๋ฆผํ•ต]-Broken Buffalo Wings  (0) 2025.01.01
[Webhacking.kr] old-15 write-up  (0) 2024.12.29
[Webhacking.kr] old-17 write-up  (0) 2024.12.22
[Webhacking.kr] old-01 write-up  (0) 2024.12.22
728x90

[๋ฌธ์ œ]

https://webhacking.kr/challenge/web-06/

 

https://webhacking.kr/challenge/web-06/

 

webhacking.kr

 


[๋ฌธ์ œ ํ’€์ด]

<?php
include "../../config.php";
if($_GET['view_source']) view_source();
if(!$_COOKIE['user']){
  $val_id="guest";
  $val_pw="123qwe";
  for($i=0;$i<20;$i++){
    $val_id=base64_encode($val_id);
    $val_pw=base64_encode($val_pw);
  }
  $val_id=str_replace("1","!",$val_id);
  $val_id=str_replace("2","@",$val_id);
  $val_id=str_replace("3","$",$val_id);
  $val_id=str_replace("4","^",$val_id);
  $val_id=str_replace("5","&",$val_id);
  $val_id=str_replace("6","*",$val_id);
  $val_id=str_replace("7","(",$val_id);
  $val_id=str_replace("8",")",$val_id);

  $val_pw=str_replace("1","!",$val_pw);
  $val_pw=str_replace("2","@",$val_pw);
  $val_pw=str_replace("3","$",$val_pw);
  $val_pw=str_replace("4","^",$val_pw);
  $val_pw=str_replace("5","&",$val_pw);
  $val_pw=str_replace("6","*",$val_pw);
  $val_pw=str_replace("7","(",$val_pw);
  $val_pw=str_replace("8",")",$val_pw);

  Setcookie("user",$val_id,time()+86400,"/challenge/web-06/");
  Setcookie("password",$val_pw,time()+86400,"/challenge/web-06/");
  echo("<meta http-equiv=refresh content=0>");
  exit;
}
?>
  • ๋จผ์ € ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด๋ฉด ํฌ๊ฒŒ 2๊ฐ€์ง€๋กœ ๋‚˜๋‰˜์–ด ์žˆ๋Š”๋ฐ ์ฒซ ๋ฒˆ์งธ ๋ถ€๋ถ„์€ ์ฟ ํ‚ค๋ฅผ ์„ค์ •ํ•˜๋Š” ๋ถ€๋ถ„์ด๋‹ค.
  • ์ฟ ํ‚ค user์™€ password๊ฐ€ ์„ค์ •๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๊ธฐ๋ณธ์ ์œผ๋กœ guest์™€ 123qwe๋ฅผ ์„ค์ •ํ•œ๋‹ค.
  • base64_encode()๋ฅผ 20ํšŒ ๋ฐ˜๋ณตํ•˜์—ฌ ๊ฐ’์„ ์ธ์ฝ”๋”ฉํ•˜๊ณ  str_replace()๋ฅผ ํ†ตํ•ด ์ผ๋ถ€ ๋ฌธ์ž๋ฅผ ํŠน์ˆ˜ ๋ฌธ์ž๋กœ ๋ณ€๊ฒฝํ•˜์—ฌ ๋ณ€์กฐํ•œ๋‹ค.
<?php
$decode_id=$_COOKIE['user'];
$decode_pw=$_COOKIE['password'];

$decode_id=str_replace("!","1",$decode_id);
$decode_id=str_replace("@","2",$decode_id);
$decode_id=str_replace("$","3",$decode_id);
$decode_id=str_replace("^","4",$decode_id);
$decode_id=str_replace("&","5",$decode_id);
$decode_id=str_replace("*","6",$decode_id);
$decode_id=str_replace("(","7",$decode_id);
$decode_id=str_replace(")","8",$decode_id);

$decode_pw=str_replace("!","1",$decode_pw);
$decode_pw=str_replace("@","2",$decode_pw);
$decode_pw=str_replace("$","3",$decode_pw);
$decode_pw=str_replace("^","4",$decode_pw);
$decode_pw=str_replace("&","5",$decode_pw);
$decode_pw=str_replace("*","6",$decode_pw);
$decode_pw=str_replace("(","7",$decode_pw);
$decode_pw=str_replace(")","8",$decode_pw);

for($i=0;$i<20;$i++){
  $decode_id=base64_decode($decode_id);
  $decode_pw=base64_decode($decode_pw);
}
  • ๋‘ ๋ฒˆ์งธ ๋ถ€๋ถ„์€ ์ฟ ํ‚ค ๋””์ฝ”๋”ฉ ๋ถ€๋ถ„์œผ๋กœ ์ฟ ํ‚ค user์™€ password ๊ฐ’์„ ์ฝ์–ด์˜ค๊ณ  ์ด์ „์— ์ธ์ฝ”๋”ฉ ์‹œ ๋ณ€ํ™˜ํ–ˆ๋˜ ํŠน์ˆ˜ ๋ฌธ์ž๋ฅผ ์›๋ž˜ ๋ฌธ์ž๋กœ ๋˜๋Œ๋ฆฐ๋‹ค.
  • ๊ทธ๋‹ค์Œ. base64_decode()๋ฅผ 20ํšŒ ๋ฐ˜๋ณตํ•˜์—ฌ ์›๋ž˜ ๊ฐ’์„ ๋ณต๊ตฌํ•œ๋‹ค.
echo("<hr><a href=./?view_source=1 style=color:yellow;>view-source</a><br><br>");
echo("ID : $decode_id<br>PW : $decode_pw<hr>");

if($decode_id=="admin" && $decode_pw=="nimda"){
  solve(6);
}
  • ๋งˆ์ง€๋ง‰์œผ๋กœ ๋””์ฝ”๋”ฉ๋œ ID์™€ PW๋ฅผ ์ถœ๋ ฅํ•˜์—ฌ ํ™”๋ฉด์— ํ‘œ์‹œํ•˜๊ณ  ๋””์ฝ”๋”ฉ๋œ ๊ฐ’์ด ID๊ฐ€ admin, PW๊ฐ€ nimda์ผ ๊ฒฝ์šฐ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ์šฐ์„  ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•œ ๊ฒฐ๊ณผ admin๊ณผ nimda๋ฅผ 20๋ฒˆ ์ธ์ฝ”๋”ฉํ•œ ํ›„ ์ˆซ์ž๋ฅผ ํŠน์ˆ˜๋ฌธ์ž๋กœ ์น˜ํ™˜ํ•ด์„œ ๊ฐ๊ฐ์˜ ๊ฐ’์„ ์ฟ ํ‚ค๋กœ ์„ค์ •ํ•˜๋ฉด ๋œ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
import base64

def encode_and_replace(value, iterations=20):
    # Base64 Encoding 20๋ฒˆ ๋ฐ˜๋ณต
    for _ in range(iterations):
        value = base64.b64encode(value.encode()).decode()

    # ํŠน์ • ๋ฌธ์ž ์น˜ํ™˜
    replacements = {
        "1": "!",
        "2": "@",
        "3": "$",
        "4": "^",
        "5": "&",
        "6": "*",
        "7": "(",
        "8": ")"
    }
    for original, replacement in replacements.items():
        value = value.replace(original, replacement)
    
    return value

# ์ดˆ๊ธฐ ๊ฐ’
id_value = "admin"
pw_value = "nimda"

# ์ธ์ฝ”๋”ฉ ๋ฐ ์น˜ํ™˜ ์ˆ˜ํ–‰
encoded_id = encode_and_replace(id_value)
encoded_pw = encode_and_replace(pw_value)

# ๊ฒฐ๊ณผ ์ถœ๋ ฅ
print("Encoded and Replaced ID:", encoded_id)
print("Encoded and Replaced Password:", encoded_pw)
  • ๋จผ์ €, ์ž…๋ ฅ ๋ฌธ์ž์—ด์„ 20๋ฒˆ Base64๋กœ ์ธ์ฝ”๋”ฉํ•˜๊ณ , ๋ฌธ์ž ์น˜ํ™˜๊นŒ์ง€ ์ˆ˜ํ–‰ํ•˜๋Š” ํŒŒ์ด์ฌ ์ฝ”๋“œ๋ฅผ ์ง  ๋‹ค์Œ ๋‚˜์˜จ ๊ฒฐ๊ณผ๋ฅผ ๊ฐ๊ฐ ์ฟ ํ‚ค ๊ฐ’์ด ์ž…๋ ฅํ•ด ์ฃผ์—ˆ์Šต๋‹ˆ๋‹ค.

  • ๊ฐ’์„ ์„ค์ •ํ•ด ์ฃผ๊ณ  ์ƒˆ๋กœ๊ณ ์นจ์„ ํ•˜๋‹ˆ ID๋ž‘ PW๊ฐ€ ์ œ ์˜๋„๋Œ€๋กœ ๋ฐ”๋€Œ์—ˆ๊ณ  ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

 

728x90

[๋ฌธ์ œ]

  • ๋ฌธ์ œ๋ฅผ ํด๋ฆญํ•˜๋ฉด Access_Denied ๋ฉ”์‹œ์ง€์™€ ํ•จ๊ป˜ alert ๊ฒฝ๊ณ ์ฐฝ์ด ๋‚˜์˜จ๋‹ค.

https://webhacking.kr/chall.php

 

Webhacking.kr

 

webhacking.kr


[๋ฌธ์ œ ํ’€์ด]

  • ๋ฌธ์ œ๋ฅผ ํด๋ฆญํ•˜๋ฉด ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ†ตํ•ด alert() ๊ฒฝ๊ณ ์ฐฝ๋ฅผ ๋„์šฐ๋Š” ์ฝ”๋“œ๊ฐ€ ์ž‘๋™๋˜๊ณ  ์žˆ์Œ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
  • ์šฐ์„  ํฌ๋กฌ ์„ค์ •์— ๋“ค์–ด๊ฐ€ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ ์‚ฌ์šฉ์„ ํ—ˆ์šฉํ•˜์ง€ ์•Š์Œ์œผ๋กœ ์„ค์ •ํ•ด ์ฃผ์—ˆ์Šต๋‹ˆ๋‹ค.
    • ์„ค์ • -> ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฐ ๋ณด์•ˆ -> ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ

 

  • ๊ทธ๋‹ค์Œ, ๋ฌธ์ œ ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐˆ ์ˆ˜ ์žˆ๊ฒŒ ๋์ง€๋งŒ ์•„๋ฌด๊ฒƒ๋„ ์•ˆ ๋– ์„œ F12๋ฅผ ๋ˆŒ๋Ÿฌ ์ฝ”๋“œ๋ฅผ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด๋‹ˆ url ๋’ค์— ?getFlag๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ๋ฉด Flag๋ฅผ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ๋‹ค๋Š” ์‚ฌ์‹ค์„ ์•Œ์•„๋ƒˆ์Šต๋‹ˆ๋‹ค.

  • ๊ทธ ๊ฒฐ๊ณผ, ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
  • ์ด์™ธ์—๋„ ๋‹ค๋ฅธ ์‚ฌ์ดํŠธ๋ฅผ ์ฐธ๊ณ ํ•ด ๋ณด๋‹ˆ Burpsuite๋ฅผ ํ†ตํ•ด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[์›นํ•ดํ‚น] | [๋“œ๋ฆผํ•ต]-Broken Buffalo Wings  (0) 2025.01.01
[Webhacking.kr] old-16 write-up  (0) 2024.12.29
[Webhacking.kr] old-17 write-up  (0) 2024.12.22
[Webhacking.kr] old-01 write-up  (0) 2024.12.22
[์›นํ•ดํ‚น] | [LOS] Gremlin write up  (0) 2024.12.01
728x90

[๋ฌธ์ œ]

https://webhacking.kr/challenge/js-4/

 

Challenge 17

 

webhacking.kr

 


[๋ฌธ์ œ ํ’€์ด]

  • ๋จผ์ € ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด๋‹ˆ unlock์˜ ๊ฐ’๊ณผ ์ž…๋ ฅ๊ฐ’์ด ๊ฐ™์œผ๋ฉด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ์•˜๋‹ค.
  • ๊ทธ๋Ÿฌ๋ฉด ๋จผ์ € unlock์˜ ๊ฐ’์„ ์•Œ์•„๋‚ด์•ผ ํ•˜๋Š”๋ฐ ๋”ฑ ๋ด๋„ ๋„ˆ๋ฌด ๋ณต์žกํ•˜๊ณ  ๊ณ„์‚ฐ์ด ๊ธธ๊ธฐ ๋•Œ๋ฌธ์— unlock๊ฐ’์„ ๊ณ„์‚ฐํ•˜๊ธฐ ์œ„ํ•ด ๊ฐœ๋ฐœ์ž ๋„๊ตฌ์˜ ์ฝ˜์†”์„ ์ด์šฉํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ์ฝ˜์†”์„ ์ด์šฉํ•ด์„œ ์‰ฝ๊ฒŒ ๊ฐ’ 7809297.1์„ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ์—ˆ๊ณ  ์ด๋ฅผ ์ž…๋ ฅ๊ฐ’์œผ๋กœ ๋„ฃ์–ด ๋งž๋Š”์ง€ ํ™•์ธํ•ด ๋ดค์Šต๋‹ˆ๋‹ค.
  • ๊ทธ ๊ฒฐ๊ณผ, ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค!

 

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-16 write-up  (0) 2024.12.29
[Webhacking.kr] old-15 write-up  (0) 2024.12.29
[Webhacking.kr] old-01 write-up  (0) 2024.12.22
[์›นํ•ดํ‚น] | [LOS] Gremlin write up  (0) 2024.12.01
[์›นํ•ดํ‚น] | [LOS] Goblin write up  (0) 2024.12.01
728x90

[๋ฌธ์ œ]

https://webhacking.kr/challenge/js-1/

 

Challenge 14

 

webhacking.kr


[๋ฌธ์ œ ํ’€์ด]

function ck(){
  var ul=document.URL;
  ul=ul.indexOf(".kr");
  ul=ul*30;
  if(ul==pw.input_pwd.value) { location.href="?"+ul*pw.input_pwd.value; }
  else { alert("Wrong"); }
  return false;
}
  • ๋จผ์ € ๊ฐœ๋ฐœ์ž ๋„๊ตฌ๋ฅผ ์—ด์–ด ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•˜๋ ค๊ณ  ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด๋ฉด ํ˜„์žฌ ํŽ˜์ด์ง€์˜ url์—์„œ .kr์ด ๋‚˜ํƒ€๋‚˜๋Š” ์œ„์น˜๋ฅผ ul์— ์ €์žฅํ•˜๊ณ 
  • ์ด ์œ„์น˜ ๊ฐ’์— 30์„ ๊ณฑํ•ฉ๋‹ˆ๋‹ค.
  • ๊ทธ ๋‹ค์Œ, ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ๊ณ„์‚ฐ๋œ ๊ฐ’๊ณผ ๋™์ผํ•œ์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
    • ๋™์ผํ•˜๋‹ค๋ฉด ํŽ˜์ด์ง€๋ฅผ ํŠน์ • ๊ฐ’์œผ๋กœ ๋ฆฌ๋‹ค์ด๋ ‰ํŠธ ํ•ฉ๋‹ˆ๋‹ค.
    • ๋™์ผํ•˜์ง€ ์•Š๋‹ค๋ฉด ๊ฒฝ๊ณ ์ฐฝ์„ ๋„์›๋‹ˆ๋‹ค.

→ ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•œ ๊ฒฐ๊ณผ ๋จผ์ € url์—์„œ .kr์˜ ์œ„์น˜๋ฅผ ์•Œ์•„๋‚ด๊ณ  ๊ทธ ๊ฐ’์— 30์„ ๊ณฑํ•ด์„œ ๊ทธ ๊ฐ’์„ ์ž…๋ ฅํ•˜๋ฉด ๋œ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

 

  • url์—์„œ .kr์€ 0๋ถ€ํ„ฐ ์‹œ์ž‘ํ•ด์„œ 18๋ฒˆ์งธ ์œ„์น˜ํ•ด ์žˆ๊ณ  ul=18์ด๊ณ  ๊ทธ ๊ฐ’์— 30์„ ๊ณฑํ•˜๋ฉด 540์ด๋ฏ€๋กœ 540์„ ์ž…๋ ฅํ•ด ๋ณด์•˜์Šต๋‹ˆ๋‹ค.
  • ๊ทธ ๊ฒฐ๊ณผ, ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

728x90

[๋ฌธ์ œ]

https://webhacking.kr/chall.php

 

Webhacking.kr

 

webhacking.kr


[๋ฌธ์ œ ํ’€์ด]

<?php
  include "../../config.php";
  if($_GET['view-source'] == 1){ view_source(); }
  if(!$_COOKIE['user_lv']){
    SetCookie("user_lv","1",time()+86400*30,"/challenge/web-01/");
    echo("<meta http-equiv=refresh content=0>");
  }
?>
<html>
<head>
<title>Challenge 1</title>
</head>
<body bgcolor=black>
<center>
<br><br><br><br><br>
<font color=white>
---------------------<br>
<?php
  if(!is_numeric($_COOKIE['user_lv'])) $_COOKIE['user_lv']=1;
  if($_COOKIE['user_lv']>=4) $_COOKIE['user_lv']=1;
  if($_COOKIE['user_lv']>3) solve(1);
  echo "<br>level : {$_COOKIE['user_lv']}";
?>
<br>
<a href=./?view-source=1>view-source</a>
</body>
</html>
  • ๋จผ์ € ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด์ž
<?php
  if(!is_numeric($_COOKIE['user_lv'])) $_COOKIE['user_lv']=1;
  if($_COOKIE['user_lv']>=4) $_COOKIE['user_lv']=1;
  if($_COOKIE['user_lv']>3) solve(1);
  echo "<br>level : {$_COOKIE['user_lv']}";
?>
  • user_lv ์ฟ ํ‚ค ๊ฐ’์ด ์ˆซ์ž๊ฐ€ ์•„๋‹ˆ๋ฉด, 1๋กœ ์ดˆ๊ธฐํ™”๋œ๋‹ค.
  • user_lv ๊ฐ’์ด 4 ์ด์ƒ์ด๋ฉด 1๋กœ ์ดˆ๊ธฐํ™”๋œ๋‹ค.
  • user_lv ๊ฐ’์ด 3๋ณด๋‹ค ํฌ๋ฉด solve(1) ํ•จ์ˆ˜๊ฐ€ ์‹คํ–‰๋œ๋‹ค.
  • solve(1) ํ•จ์ˆ˜๋Š” ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ฑฐ๋‚˜ ์ƒํƒœ๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ํ•จ์ˆ˜์ผ ๊ฐ€๋Šฅ์„ฑ์ด ํด ๊ฒƒ์ด๋‹ค.

→ user_lv ๊ฐ’์€ 3๋ณด๋‹ค ํฌ๊ณ  4๋ณด๋‹ค ์ž‘์€ ์ˆซ์ž๊ฐ€ ๋“ค์–ด๊ฐ€์•ผ ํ•œ๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ์Šต๋‹ˆ๋‹ค.

  • ๊ทธ๋ž˜์„œ, ์ฟ ํ‚ค ๊ฐ’์„ 3๊ณผ 4 ์‚ฌ์ด์— ๊ฐ’์„ ์ž…๋ ฅํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ๊ทธ ๊ฒฐ๊ณผ, ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค!

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-15 write-up  (0) 2024.12.29
[Webhacking.kr] old-17 write-up  (0) 2024.12.22
[์›นํ•ดํ‚น] | [LOS] Gremlin write up  (0) 2024.12.01
[์›นํ•ดํ‚น] | [LOS] Goblin write up  (0) 2024.12.01
[์›นํ•ดํ‚น] | [LOS] Cobolt write up  (0) 2024.12.01
728x90

[๋ฌธ์ œ]

https://tryhackme.com/r/room/windowsforensics1

 

Windows Forensics 1

Introduction to Windows Registry Forensics

tryhackme.com


[๋ฌธ์ œ ํ’€์ด]

Task 1) Introduction to Computer Forensics for Windows

 

What is the most used Desktop Operationg System right now?

๋‹ต) Microsoft Windows


Task 2) Windows Registry and Forensics

What is the short form for HKEY_LOCAL_MACHINE?

๋‹ต) HKLM


Task3) Accessing registry hives offline

What is the path for the five main registry hives, DEFAULT, SAM, SECURITY, SOFTWARE, and SYSTEM?

๋‹ต) C:\Windows\System32\Config

 

What is the path for the AmCache hive?

๋‹ต) C:\Windows\AppCompat\Programs\Amcache.hve


Task 6) System Information and System Accounts

What is the Current Build Number of the machine whose data is being investigated?

๋‹ต: 19044

 

 

Which ControlSet contains the last known good configuration?

๋‹ต: 1

 

What is the Computer Name of the computer?

๋‹ต: THM-4N6

 

What is the value of the TimeZoneKeyName?

๋‹ต: Pakistan Standard Time

 

What is the DHCP IP address

๋‹ต: 192.168.100.58

What is the RID of the Guest User account?

๋‹ต: 501


Task 7) Usage or knowledge of files/folders

When was EZtools opened?

๋‹ต: 2021-15-01 13:00:34

At what time was My Computer last interacted with?

๋‹ต: 2021-12-01 13:06:47

What is the Absolute Path of the file opened using notepad.exe?

๋‹ต: C:\Program Files\Amazon\Ec2ConfigService\Settings

 

When was this file opened?

๋‹ต: 2021-11-30 10:56:19


Task 8) Evidence of Execution

How many times was the File Explorer launched?

๋‹ต: 26

 

What is another name for ShimCache?

๋‹ต: AppCompatCache

 

Which of the artifacts also saves SHA1 hashes of the executed programs?

๋‹ต: AmCache

 

Which of the artifacts saves the full path of the executed programs?

๋‹ต: BAM/DAM


Task 9) External Devices/USB device forensics

What is the serial number of the device from the manufacturer 'Kingston'?

๋‹ต: 1C6f654E59A3B0C179D366AE&0

 

What is the name of this device?

๋‹ต: Kingston Data Traveler 2.0 USB Device

 

 

What is the friendly name of the device from the manufacturer 'Kingston'?

๋‹ต: USB


Task 10) Hands-on Challenge

  • ๋จผ์ € RegistryExplorer์„ run as administrator๋กœ ํ•ด์„œ ์‹คํ–‰ํ•œ๋‹ค.
  • ๊ทธ๋‹ค์Œ C:\Windows\System32\Config ๋””๋ ‰ํ„ฐ๋ฆฌ์—์„œ SAM, SOFTWARE, SYSTEM์„ ๋กœ๋“œํ•ด์•ผ ํ•œ๋‹ค.
  • SOFTWARE๋ž‘ SYSTEM์„ ๋กœ๋“œ๋ฅผ ํ•˜๋ผ๊ณ  ํ•˜๋ฉด "Dirty hive detected" ํŒ์—…์ด ๋œจ๋ฉด "no"๋ฅผ ์„ ํƒํ•˜๊ณ  "replay transaction logs against this hive" ํŒ์—…์ด ๋œจ๋ฉด "yes"๋ฅผ ์„ ํƒํ•œ๋‹ค.

  • ๊ทธ๋‹ค์Œ 1~3๋ฒˆ ๋ฌธ์ œ๋ฅผ ํ’€๊ธฐ ์œ„ํ•ด SAM์—์„œ Users ๊ฒฝ๋กœ๋ฅผ ํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.

How many user create accounts are present on the system?

๋‹ต: 3

 

What is the username of the account that has never been logged in?

๋‹ต:  thm-user2

 

What's the password hint for the user THM-4n6?

๋‹ต: count

 

์•„๋ž˜ ๋ฌธ์ œ๋“ค์€ ๋‹ค์Œ์— ์ด์–ด์„œ...

When was the file 'Changelog.txt' accessed?

What is the complete path from where the python 3.8.2 installer was run?

When was the USB device with the friendly name 'USB' last connected?

 

์ฐธ๊ณ 

728x90

[๋ฌธ์ œ]

https://los.rubiya.kr/

 

Lord of SQLInjection

 

los.rubiya.kr


[๋ฌธ์ œํ’€์ด]

  • ๋จผ์ € ์ฑ—gpt๋ฅผ ์ด์šฉํ•ด ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•œ ๊ฒฐ๊ณผ ์กฐํšŒํ•œ query์˜ ๊ฒฐ๊ณผ์— id๊ฐ€ ์žˆ๋‹ค๋ฉด ์„ฑ๊ณต์„ ์ถœ๋ ฅํ•˜๋Š” ๊ฒƒ์„ ์•Œ์•˜๊ณ  $_GET['id']์™€ $_GET['pw']๋ฅผ ๊ทธ๋Œ€๋กœ ์ฟผ๋ฆฌ์— ๋„ฃ๊ณ  ์žˆ์œผ๋ฏ€๋กœ, ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ์‚ฌ์‹ค์„ ์•Œ์•˜์Šต๋‹ˆ๋‹ค.



  • ๊ทธ๋ž˜์„œ query๋ฌธ์„ php?id=admin&pw=admin ๋ณ€๊ฒฝํ•˜๋ฉด ๋˜์ง€ ์•Š์„๊นŒ ์ƒ๊ฐํ•˜๊ณ  ๋ณ€๊ฒฝํ•œ ๊ฒฐ๊ณผ ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์ง€ ์•Š์•„ ๋‹ค๋ฅธ ๋ฐฉ๋ฒ•์„ ์ฐพ์•„๋ดค์Šต๋‹ˆ๋‹ค.

 

  • SQL ์‚ฝ์ž… ๊ณต๊ฒฉ ์ค‘ ๊ฐ€์žฅ ์ผ๋ฐ˜์ ์ธ ‘ or ‘1’=’1 ๋ฐฉ๋ฒ•์„ ์‹œ๋„ํ•˜์—ฌ ํ•ญ์ƒ ์ฐธ์ธ ์กฐ๊ฑด์„ ๋งŒ๋“ค์–ด ๋ชจ๋“  ๋ ˆ์ฝ”๋“œ๋ฅผ ๊ฐ€์ ธ์˜ค๊ฒŒ ํ•˜๋ ค๊ณ  ?id=' OR '1'='1&pw=' OR '1'='1๋กœ query๋ฌธ์„ ๋ณ€๊ฒฝํ–ˆ๊ณ  ๊ทธ ๊ฒฐ๊ณผ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค.

 


 

[TIP]

  • Get๋ฐฉ์‹์€ ์ฃผ์†Œ์ฐฝ์— ๊ฐ’์„ ์ž…๋ ฅ, ์ถœ๋ ฅํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ฃผ์†Œ์ฐฝ์˜ ๋ณ€์ˆ˜๊ฐ’์„ ์ˆ˜์ •ํ•œ๋‹ค๋ฉด ๋“ค์–ด๊ฐ€๊ฑฐ๋‚˜ ๋‚˜์˜ค๋Š” ๊ฐ’์— ์˜ํ–ฅ์„ ๋ฏธ์นœ๋‹ค.
  • url์— ๋ณ€์ˆ˜๊ฐ’์„ ์ˆ˜์ •ํ•  ๋•Œ์—๋Š” php๋’ค์— ?(๋ณ€์ˆ˜๋ช…)/๋ณ€์ˆ˜ ์ž…๋ ฅ ๋‹ค๋ฅธ ๋ณ€์ˆ˜๋ฅผ ๋˜ ์ž…๋ ฅํ•˜๊ณ ์ž ํ•  ๋•Œ php?(๋ณ€์ˆ˜๋ช…)&(๋ณ€์ˆ˜๋ช…)
  • ์ฟผ๋ฆฌ ์ „์ฒด๋ฅผ ์ฐธ์œผ๋กœ ๋งŒ๋“ค์–ด์ฃผ๋Š” ๋ฐฉ๋ฒ•: ‘1’ or ‘1’=1

 

[์ฐธ๊ณ ]

https://in-reason.tistory.com/26

 

 

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-17 write-up  (0) 2024.12.22
[Webhacking.kr] old-01 write-up  (0) 2024.12.22
[์›นํ•ดํ‚น] | [LOS] Goblin write up  (0) 2024.12.01
[์›นํ•ดํ‚น] | [LOS] Cobolt write up  (0) 2024.12.01
[Tryhackme] OhSINT  (0) 2024.11.24
728x90

[๋ฌธ์ œ]

https://los.rubiya.kr/chall/goblin_e5afb87a6716708e3af46a849517afdc.php

 

https://los.rubiya.kr/chall/goblin_e5afb87a6716708e3af46a849517afdc.php

 

los.rubiya.kr


[๋ฌธ์ œ ํ’€์ด]

  $query = "select id from prob_goblin where id='guest' and no={$_GET[no]}";
  • ์šฐ์„  ์ „ ๋ฌธ์ œ๋“ค๊ณผ ๋‹ค๋ฅด๊ฒŒ id๊ฐ€ ๊ณ ์ •๋˜์–ด ์žˆ๊ณ  ์ด๋ฒˆ์—๋Š” no ๋ถ€๋ถ„์„ ์ž…๋ ฅํ•ด์•ผ ํ•˜๋Š” ๊ฑฐ ๊ฐ™์Šต๋‹ˆ๋‹ค.
  • no๋Š” ๊ทธ๋ฆฌ๊ณ  ์ˆซ์ž ํ˜•ํƒœ๋กœ ์ฟผํ„ฐ(', ")๊ฐ€ ํ•„ํ„ฐ๋ง๋˜์–ด ์žˆ์–ด ๋ฌธ์ž์—ด์„ ์ž…๋ ฅํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
if($result['id']) echo "<h2>Hello {$result[id]}</h2>"; 
if($result['id'] == 'admin') solve("goblin");
  • ์œ„ ์ฟผ๋ฆฌ๋ฅผ ํ†ตํ•ด ์กฐํšŒ๊ฐ€ ์„ฑ๊ณตํ•  ๊ฒฝ์šฐ ์กฐํšŒ๋œ id์™€ ํ•จ๊ป˜ Hello ๋ฌธ๊ตฌ๋ฅผ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค.
  • ๊ทธ๋ฆฌ๊ณ  id๊ฐ€ admin์ผ ๊ฒฝ์šฐ์— ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • ๋จผ์ € no ๊ฐ’์— 1์ด๋ž‘ ๋‹ค๋ฅธ ์ˆซ์ž๋“ค์„ ๋„ฃ์—ˆ๋Š”๋ฐ 1์ด ๊ฒŒ์ŠคํŠธ ๊ณ„์ •์ž„์„ ์•Œ ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.
  • ํ˜น์‹œ๋‚˜ admin์— ํ•ด๋‹นํ•˜๋Š” ์ˆซ์ž๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์„๊นŒํ•˜๊ณ  ์—ฌ๋Ÿฌ ์ˆซ์ž๋“ค์„ ์‹œ๋„ํ•ด ๋ณด์•˜์ง€๋งŒ ์•„๋ฌด๊ฒƒ๋„ ์•ˆ ๋–ด์Šต๋‹ˆ๋‹ค.

  • ์šฐ์„  ๋จผ์ € id๋ฅผ admin์œผ๋กœ ๋ฐ”๊ฟ”์•ผ ํ•œ๋‹ค๋Š” ์ƒ๊ฐ์— no๋ฅผ false๊ฐ€ ๋˜๋„๋ก ํ•œ ๋’ค id๋ฅผ admin์œผ๋กœ ํ•˜๋Š” ๊ตฌ๋ฌธ์„ ์ž…๋ ฅํ–ˆ์Šต๋‹ˆ๋‹ค.
  • no=2 or id='admin'
  • ๊ทธ๋žฌ๋”๋‹ˆ No Quotes๋ผ๋Š” ๋ฌธ๊ตฌ๋ฅผ ๋–ด๋Š”๋ฐ ํŠน์ˆ˜๋ฌธ์ž๊ฐ€ ๋ง‰ํ˜€์žˆ๋‹ค๋Š” ๊ฒƒ์„ ๋‹ค์‹œ ๊นจ๋‹ฌ์•˜์Šต๋‹ˆ๋‹ค..

  • ๊ทธ๋ž˜์„œ ์ด๋ฒˆ์—๋Š” id='admin' ๊ฐ’์„ ์•„์Šคํ‚ค์ฝ”๋“œ๋กœ ๋ณ€ํ™˜ํ•ด์„œ ์ˆซ์žํ˜•์‹์œผ๋กœ ์ž…๋ ฅํ–ˆ์Šต๋‹ˆ๋‹ค.
  • no=2 or id=char(97, 100, 109, 105, 110)
  • ๊ทธ๋žฌ๋”๋‹ˆ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค!

์ฐธ๊ณ 

์•„์Šคํ‚ค ์ฝ”๋“œ ๋ณ€ํ™˜ ์‚ฌ์ดํŠธ

  • ์œ„ ์‚ฌ์ดํŠธ๋ฅผ ํ†ตํ•ด ๋ฌธ์ž์—ด์„ ์‰ฝ๊ฒŒ ์•„์Šคํ‚ค์ฝ”๋“œ๋กœ ๋ณ€ํ™˜ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Webhacking.kr] old-01 write-up  (0) 2024.12.22
[์›นํ•ดํ‚น] | [LOS] Gremlin write up  (0) 2024.12.01
[์›นํ•ดํ‚น] | [LOS] Cobolt write up  (0) 2024.12.01
[Tryhackme] OhSINT  (0) 2024.11.24
[ํฌ๋ Œ์‹] | [BTLO] Meta  (0) 2024.11.24

+ Recent posts