Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

Wargame & CTF/SegFault

[SegFault] (Authentication Bypass) - Login Bypass 3

Gearvirus(junyup2) 2023. 12. 6. 04:01

[SegFault] Authentication Bypass (Login)

Login Bypass 3. 

normaltic3 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž!

 

๋ฌธ์ œ ํŒŒ์•…

  • ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ด
  • ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • :  [ID/PW] : doldol / dol1234

  • Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค.
    • 302 Found 
    • 200 OK

  • ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค.

  • ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค.
    • 302 Found - Params ํ™•์ธ
    • 200 OK
  • ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž !

  • /login3/login.php ๊ฒฝ๋กœ์— post ๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserId=doldol&Password=dol1234&Submit=Login๊ฐ€ ๋“ค์–ด๊ฐ€๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.
  • ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜์—ฌ index.php๋กœ ๋ฆฌ๋””๋ ‰์…˜๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

์ƒ๊ฐ ๊ณผ์ •

1. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes
-> doldol'and'1'='1 / dol1234๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต
2. ์–ด๋–ค ๋กœ์ง์œผ๋กœ ์ด๋ฃจ์–ด์ ธ ์žˆ์„๊นŒ?
  2-1. ์‹๋ณ„/์ธ์ฆ ๋™์‹œ
    normaltic3'or'1'='1 ์‹œ๋„ : ์‹คํŒจ(Fail)
  2-2. or ํ•„ํ„ฐ๋ง
    normaltic'# / dol1234 ์‹œ๋„ : ์‹คํŒจ
  2-3 ์‹๋ณ„/์ธ์ฆ ๋ถ„๋ฆฌ
    'union select 'normaltic3','dol1234'# / dol1234

ํ’€์ด ๊ณผ์ • (ํ•ด๊ฒฐ ๋ฐฉ์•ˆ)

 


 

์งˆ๋ฌธ ํ™˜์˜, ์ˆ˜์ • ๋ฐ ๋ณด์™„์— ๋Œ€ํ•œ ์ง€์  ํ™˜์˜