Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ 113

[๊ธฐ๋ก์ผ์ง€] ๐Ÿ“š 07์ฃผ์ฐจ (๐Ÿ’‰SQL Injection - Error Based/Blind)

Error Based Sqli SQL ์งˆ์˜ ๊ฒฐ๊ณผ๊ฐ€ ํ™”๋ฉด์— ์ถœ๋ ฅ๋˜๋Š” ๊ฒฝ์šฐ์— UNION SQLi๋ฅผ ์‚ฌ์šฉํ–ˆ๋‹ค. ๊ทธ๋ ‡๋‹ค๋ฉด ๊ฒฐ๊ณผ๊ฐ€ ์•„๋‹Œ ์—๋Ÿฌ(Error) ๋ฉ”์‹œ์ง€๊ฐ€ ์ถœ๋ ฅ๋˜๋Š” ๊ฒฝ์šฐ์—๋Š” ์–ด๋–ป๊ฒŒ ํ•ด์•ผํ• ๊นŒ? ์ด๋•Œ ์šฐ๋ฆฌ๋Š” Error Based SQLi๋ฅผ ์ƒ๊ฐํ•ด ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ์ฟผ๋ฆฌ์˜ ์‹ค์งˆ์ ์ธ ๊ฒฐ๊ณผ๋Š” ์ถœ๋ ฅ๋˜๊ณ  ์žˆ์ง€ ์•Š์ง€๋งŒ ์˜ค๋ฅ˜๊ฐ€ ๋‚ฌ์„ ๊ฒฝ์šฐ์— ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€๊ฐ€ ๋…ธ์ถœ๋˜๊ณ  ์žˆ๋‹ค๋ฉด, ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฅผ ์ถ”์ถœํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค. ๊ทธ๋Ÿผ ์–ด๋–ค ๊ฒฝ์šฐ์— Error Based SQLi๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ์ƒ๊ฐํ•ด๋ณด์ž! ๋‹น์—ฐํ•˜๊ฒŒ๋„ ์—๋Ÿฌ ๋ฉ”์‹œ์ง€๋ฅผ ํ™œ์šฉํ•ด์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ๋ฐฉ๋ฒ•์ด๊ธฐ ๋•Œ๋ฌธ์—, ์šฐ์„  ์—๋Ÿฌ ๋ฉ”์‹œ์ง€๊ฐ€ ํ™”๋ฉด์— ์ถœ๋ ฅ๋˜๋Š” ๊ณณ์ด์—ฌ์•ผ ํ•œ๋‹ค. Error ?! ์—๋Ÿฌ(Error) ... ์—๋Ÿฌ์˜ ์ข…๋ฅ˜๋Š” ๋‹ค์–‘ํ•˜๋‹ค. ๊ทธ๋Ÿผ Error Based๋Š” ๋ชจ๋“  ์—๋Ÿฌ์— ..

[SegFault] (SQLi) - SQL Injection 2

[SegFault] (SQLi) SQL Injection 2. ์ง„์งœ! ๋ฐ์ดํ„ฐ๋ฅผ ์ฐพ์•„๋ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ฐฝ์ด ๋‚˜์˜จ๋‹ค. ์šฐ์„  ๊ฒ€์ƒ‰์ฐฝ์— ๋Œ€ํ•˜์—ฌ ์ž…๋ ฅ ํ…Œ์ŠคํŠธ๋ฅผ ์ง„ํ–‰ํ•ด๋ณธ๋‹ค. SQL ๊ตฌ์กฐ ํ™•์ธ ์šฐ์„  placeholder๋กœ ์กด์žฌํ•˜๋Š” normaltic์„ ์ž…๋ ฅํ•ด๋ณธ๋‹ค. ์œ„์™€ ๊ฐ™์€ ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์˜ค๋Š” ๊ฒƒ์„ ํ™•์ธํ–ˆ๋Š”๋ฐ ์—ฌ๊ธฐ์„œ ๋ถ€๋ถ„์ ์œผ๋กœ ์ž…๋ ฅํ–ˆ์„ ๋•Œ๋„ ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์˜ค๋Š”์ง€ ํ™•์ธํ•ด๋ณธ๋‹ค. ๊ฒฐ๊ณผ๊ฐ€ ์™„์ „ํžˆ ๋™์ผํ•˜์ง€๋Š” ์•Š์ง€๋งŒ ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์˜ค๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. SQLi ๊ฐ€๋Šฅ ์—ฌ๋ถ€ ํ™•์ธ normaltic%' and '1%'='1 SQL Injection์ด ๊ฐ€๋Šฅํ•œ ๊ฒƒ์„ ํ™•์ธ ํ–ˆ์œผ๋ฏ€๋กœ UNION SQLi ์˜ ์ง„ํ–‰ ์ ˆ์ฐจ์— ๋”ฐ๋ผ ์ง„ํ–‰ํ•œ๋‹ค. ํ’€์ด ๊ณผ์ • (ํ•ด๊ฒฐ ๋ฐฉ์•ˆ) 1. SQL Injection ๊ฐ€๋Šฅ ์—ฌ๋ถ€ ํŒ๋‹จ ์œ„์—์„œ ํ™•์ธ..

[SegFault] (SQLi) - SQL Injection 1

[SegFault] (SQLi) SQL Injection 1. ๋น„๋ฐ€ ๋ฐ์ดํ„ฐ๋ฅผ ์ฐพ์•„๋‚ด๋ผ! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ์ฐฝ์ด ๋‚˜์˜จ๋‹ค. ์šฐ์„  ๊ฒ€์ƒ‰์ฐฝ์— ๋Œ€ํ•˜์—ฌ ์ž…๋ ฅ ํ…Œ์ŠคํŠธ๋ฅผ ์ง„ํ–‰ํ•ด๋ณธ๋‹ค. SQL ๊ตฌ์กฐ ํ™•์ธ ์šฐ์„  r ์„ ์ž…๋ ฅํ•ด๋ณธ ๊ฒฐ๊ณผ r ์ด๋ผ๋Š” ๋ฌธ์ž๊ฐ€ ๋“ค์–ด๊ฐ€๋Š” 3๊ฐœ์˜ ID๊ฐ€ ๊ฒ€์ƒ‰์˜ ๋Œ€์ƒ์ด ๋˜๋Š” ๊ฒƒ์„ ๋ณด๊ณ  ๋ถ€๋ถ„๋งŒ ์ž…๋ ฅํ•ด๋„ ๋‚˜์˜จ๋‹ค๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ทธ๋ ‡๋‹ค๋ฉด ๊ฒ€์ƒ‰์ฐฝ์˜ ๊ตฌ์กฐ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์„ ๊ฒƒ์ด๋ผ๊ณ  ์˜ˆ์ƒ์ด ๊ฐ€๋Šฅํ•˜๋‹ค. select * from ~~ where name like '%_____%'; ๊ทธ๋Ÿผ ์šฐ์„  SQL Injection์ด ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•ด ๋ณด๊ธฐ ์œ„ํ•ด and๋ฅผ ์ด์šฉํ•˜์—ฌ ์ฐธ์ธ ๊ฒฐ๊ณผ๋ฅผ ํ•จ๊ป˜ ๋„ฃ์–ด ํ™•์ธํ•ด๋ณธ๋‹ค. SQLi ๊ฐ€๋Šฅ์—ฌ๋ถ€ ํ™•์ธ select * from ~~ where name like '%(r..

[SegFault] (Authentication Bypass) - Secret Login

[SegFault] Authentication Bypass (Login) Secret Login. ๊ด€๋ฆฌ์ž ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๊ทธ๋Ÿฐ๋ฐ... ๊ด€๋ฆฌ์ž ๊ณ„์ •์ด ๋ญ”์ง€ ๋ชจ๋ฅธ๋‹ค..!? ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • 1. ๋กœ๊ทธ์ธ ํ•˜์˜€์„ ๋•Œ ํŠน๋ณ„ํ•œ ์ ์ด ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. 2. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes -> doldol'and'1'='1 / dol1234 ๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต 3. 'or'1'='1 ๋กœ ์‹œ๋„ ๊ด€๋ฆฌ์ž ๊ณ„์ •์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ์ „์ฒด ๋ฐ์ดํ„ฐ๋ฅผ ์กฐํšŒํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•˜์ž. 3-1. doldol'or'1'..

[SegFault] (Authentication Bypass) - Login Bypass 5

[SegFault] Authentication Bypass (Login) Login Bypass 5. normaltic5 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ํ›„์˜ index ํŽ˜์ด์ง€์˜ ์š”์ฒญ์„ ํ™•์ธํ•ด๋ณธ๋‹ค. ์œ„์˜ ์š”์ฒญ์„ ํ™•์ธํ•ด๋ณด๋ฉด ์ฟ ํ‚ค(Cookie)์— loginUser๋ผ๊ณ  ํ•˜๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ(Params)๊ฐ€ ์กด์žฌํ•œ๋‹ค. ํ•ด๋‹น ํŒŒ๋ผ๋ฏธํ„ฐ์˜ ์ž…๋ ฅ๊ฐ’์€ doldol, ์ฆ‰ ๋กœ๊ทธ์ธํ•œ ์œ ์ €๋ช…๊ณผ ๊ฐ™๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • ์ฟ ํ‚ค์— loginUser = doldol ์ด๋ผ๊ณ  ํ•˜๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ๊ฐ€ ๋กœ๊ทธ์ธ ํ›„์— ํ™•์ธ๋œ๋‹ค. ์ฟ ํ‚ค๋Š” ์‰ฝ๊ฒŒ ๋ณ€์กฐ๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ธฐ ๋•Œ..

[SegFault] (Authentication Bypass) - Login Bypass 4

[SegFault] Authentication Bypass (Login) Login Bypass 4. normaltic4 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ํ•ด๋‹น ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ ํ™•์ธํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ƒ๊ฐ๊ณผ์ • 1. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes -> doldol'and'1'='1 / dol1234๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต 2. ์–ด๋–ค ๋กœ์ง์œผ๋กœ ์ด๋ฃจ์–ด์ ธ ์žˆ์„๊นŒ? 2-1. ์‹๋ณ„/์ธ์ฆ ๋™์‹œ normaltic3'or'1'='1 ์‹œ๋„ : ์‹คํŒจ(Fail) 2-2. or ํ•„ํ„ฐ๋ง normaltic'# / dol1234 ์‹œ๋„ : ์‹คํŒจ 2-3..

[SegFault] (Authentication Bypass) - Login Bypass 3

[SegFault] Authentication Bypass (Login) Login Bypass 3. normaltic3 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ด ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found - Params ํ™•์ธ 200 OK ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! /login3/login.php ๊ฒฝ๋กœ์— post ๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserI..

[SegFault] (Authentication Bypass) - Login Bypass 2

[SegFault] Authentication Bypass (Login) Login Bypass 2. normaltic2 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์šฐ์„  ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! /login2/login.php ๊ฒฝ๋กœ์— post๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserId=doldol&Password=..

[SegFault] (Authentication Bypass) - Login Bypass 1

[SegFault] Authentication Bypass (Login) Login Bypass 1. normaltic1 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ์„ ์‹œ๋„ ํ•ด๋ณธ๋‹ค. 302 Found 200 OK ์œ„์˜ ๋‘ history์— ๋Œ€ํ•œ ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! ์š”์ฒญ(Requset)์—์„œ POST ๋ฉ”์„œ๋“œ๋ฅผ ์ด์šฉํ•˜์—ฌ /login1/login.php ๊ฒฝ๋กœ์— ํŒŒ๋ผ๋ฏธํ„ฐUserId=doldol&Password=dol12..

[SegFault] (Authentication Bypass) - Pin Code Crack

[SegFault] Authentication Bypass (Code) Pin Code Crack. ์•„๋ž˜ ์‚ฌ์ดํŠธ์˜ PIN ๋ฒˆํ˜ธ๋ฅผ ํฌ๋ž™ํ•ด๋ณด์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. LOGIN ๋ฒ„ํŠผ์„ ๋ˆ„๋ฅด๋ฉด ํŒ์—… ์ฐฝ์ด ์—ด๋ฆฐ๋‹ค. Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์ ‘์† ๊ณผ์ • ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋ฒ„ํŠผ ๋ˆŒ๋ €์„ ๋•Œ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. (LOGIN) ๊ฐ™์€ ์ฐฝ์˜ ํŒ์—… ์ฐฝ์ด๋ฏ€๋กœ ์•„๋ฌด๋Ÿฐ ๋ณ€ํ™” ์—†์Œ 200 OK (Enter) PIN Code๋ฅผ ๋„ฃ์–ด์ค˜์•ผ ํ•œ๋‹ค. ๋‚ด๋ถ€๋ฅผ ์‚ดํŽด๋ณด๋ฉด checkOTP.js๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • ์ƒ๊ฐ ๊ณผ์ • 1. Enter ๋ฒ„ํŠผ์„ ๋ˆ„๋ฅด๋ฉด SendOTP๋ฅผ ํ•˜๊ณ , checkOTP.php์—์„œ ํ™•์ธํ•˜๋Š” ๊ฒƒ์„..