Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

Wargame & CTF/SegFault

[SegFault] (Authentication Bypass) - Secret Login

Gearvirus(junyup2) 2023. 12. 6. 04:02

[SegFault] Authentication Bypass (Login)

Secret Login.

๊ด€๋ฆฌ์ž ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๊ทธ๋Ÿฐ๋ฐ... ๊ด€๋ฆฌ์ž ๊ณ„์ •์ด ๋ญ”์ง€ ๋ชจ๋ฅธ๋‹ค..!?

๋ฌธ์ œ ํŒŒ์•…

์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค.

  • ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • :  [ID/PW] : doldol / dol1234

 

๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค.


์ƒ๊ฐ ๊ณผ์ •

1. ๋กœ๊ทธ์ธ ํ•˜์˜€์„ ๋•Œ ํŠน๋ณ„ํ•œ ์ ์ด ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค.
2. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes
-> doldol'and'1'='1 / dol1234 ๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต
3. 'or'1'='1 ๋กœ ์‹œ๋„
 ๊ด€๋ฆฌ์ž ๊ณ„์ •์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ์ „์ฒด ๋ฐ์ดํ„ฐ๋ฅผ ์กฐํšŒํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•˜์ž.
  3-1. doldol'or'1'='1'#
   ์ „์ฒด ๋กœ๊ทธ์ธ ์œ ์ € ๋ฐ์ดํ„ฐ๊ฐ€ ์กฐํšŒ !
4. ์›ํ•˜๋Š” ๊ณ„์ •์œผ๋กœ ๋“ค์–ด๊ฐ€๊ธฐ ์œ„ํ•ด ์ตœ์ƒ๋‹จ์˜ ๊ณ„์ •๋ถ€ํ„ฐ ํ•˜๋‚˜์”ฉ ์ด๋™ํ•ด๋ณธ๋‹ค.
  4-1. doldol'or'1'='1' limit 1,1 #


ํ’€์ด ๊ณผ์ • (ํ•ด๊ฒฐ ๋ฐฉ์•ˆ)


 

์งˆ๋ฌธ ํ™˜์˜, ์ˆ˜์ • ๋ฐ ๋ณด์™„์— ๋Œ€ํ•œ ์ง€์  ํ™˜์˜