Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

Bypass 9

[๊ธฐ๋ก์ผ์ง€] ๐Ÿ“š 11์ฃผ์ฐจ (XSS ๊ณต๊ฒฉ Script / ๋Œ€์‘ ๋ฐฉ์•ˆ / Client Script ํ™œ์šฉ ๋ฐฉ์•ˆ)

XSS Bypass Trick XSS ์šฐํšŒ ์ „๋žต์„ ํ†ตํ•œ ๊ณต๊ฒฉ ์Šคํฌ๋ฆฝํŠธ ์‚ฝ์ž… ๋ฐฉ๋ฒ• Script Tag (๊ธธ์ด ์ œํ•œ) ์ผ๋ฐ˜์ ์œผ๋กœ ์‚ฝ์ž…๋˜๋Š” ์Šคํฌ๋ฆฝํŠธ ๊ณต๊ฒฉ์€ ์–ด๋Š์ •๋„ ๊ธธ์ด๊ฐ€ ์žˆ๊ฒŒ ๋œ๋‹ค. ๊ทธ๋ž˜์„œ ์ด๋ฅผ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด script ํƒœ๊ทธ์— ๋Œ€ํ•˜์—ฌ ์Šคํฌ๋ฆฝํŠธ ํƒœ๊ทธ ๋‚ด๋ถ€์— ๋“ค์–ด๊ฐ€๋Š” ๊ธธ์ด ์ œํ•œ์„ ๋‘๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. $script = $_GET['script']; $script = substr($script,0,40); alert(1)๊ณผ ๊ฐ™์ด ์งง์€ ๊ฒƒ์œผ๋กœ ํ…Œ์ŠคํŠธ ํ•ด๋ณด๋Š” ๊ฒฝ์šฐ์—๋Š” ์‚ฝ์ž…์ด ๋˜์ง€๋งŒ, ๊ธธ์ด๊ฐ€ ๊ธธ์–ด์ง€๋Š” ๊ฒฝ์šฐ์— ๊ธธ์ด ์ œํ•œ์— ๊ฑธ๋ ค์„œ ์งค๋ฆฌ๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค. ์ด๋Ÿฐ ๊ฒฝ์šฐ์—๋Š” ๊ธด ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฝ์ž…ํ•  ์ˆ˜ ์—†๋Š” ๊ฒƒ์ผ๊นŒ? ๊ทธ๋ ‡์ง€ ์•Š๋‹ค. ์œ„์™€ ๊ฐ™์ด xss.js ๋ผ๋Š” ์‚ฝ์ž…์„ ์œ„ํ•œ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋”ฐ๋กœ ๋งŒ๋“ค์–ด๋‘๊ณ  ํ•ด๋‹น js ํŒŒ์ผ์— ์ ‘๊ทผํ•˜๋„๋ก ํ•˜๋ฉด..

[SegFault] (Authentication Bypass) - Secret Login

[SegFault] Authentication Bypass (Login) Secret Login. ๊ด€๋ฆฌ์ž ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๊ทธ๋Ÿฐ๋ฐ... ๊ด€๋ฆฌ์ž ๊ณ„์ •์ด ๋ญ”์ง€ ๋ชจ๋ฅธ๋‹ค..!? ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • 1. ๋กœ๊ทธ์ธ ํ•˜์˜€์„ ๋•Œ ํŠน๋ณ„ํ•œ ์ ์ด ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. 2. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes -> doldol'and'1'='1 / dol1234 ๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต 3. 'or'1'='1 ๋กœ ์‹œ๋„ ๊ด€๋ฆฌ์ž ๊ณ„์ •์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ์ „์ฒด ๋ฐ์ดํ„ฐ๋ฅผ ์กฐํšŒํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•˜์ž. 3-1. doldol'or'1'..

[SegFault] (Authentication Bypass) - Login Bypass 5

[SegFault] Authentication Bypass (Login) Login Bypass 5. normaltic5 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ํ›„์˜ index ํŽ˜์ด์ง€์˜ ์š”์ฒญ์„ ํ™•์ธํ•ด๋ณธ๋‹ค. ์œ„์˜ ์š”์ฒญ์„ ํ™•์ธํ•ด๋ณด๋ฉด ์ฟ ํ‚ค(Cookie)์— loginUser๋ผ๊ณ  ํ•˜๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ(Params)๊ฐ€ ์กด์žฌํ•œ๋‹ค. ํ•ด๋‹น ํŒŒ๋ผ๋ฏธํ„ฐ์˜ ์ž…๋ ฅ๊ฐ’์€ doldol, ์ฆ‰ ๋กœ๊ทธ์ธํ•œ ์œ ์ €๋ช…๊ณผ ๊ฐ™๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • ์ฟ ํ‚ค์— loginUser = doldol ์ด๋ผ๊ณ  ํ•˜๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ๊ฐ€ ๋กœ๊ทธ์ธ ํ›„์— ํ™•์ธ๋œ๋‹ค. ์ฟ ํ‚ค๋Š” ์‰ฝ๊ฒŒ ๋ณ€์กฐ๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ธฐ ๋•Œ..

[SegFault] (Authentication Bypass) - Login Bypass 4

[SegFault] Authentication Bypass (Login) Login Bypass 4. normaltic4 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ํ•ด๋‹น ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ ํ™•์ธํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ƒ๊ฐ๊ณผ์ • 1. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes -> doldol'and'1'='1 / dol1234๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต 2. ์–ด๋–ค ๋กœ์ง์œผ๋กœ ์ด๋ฃจ์–ด์ ธ ์žˆ์„๊นŒ? 2-1. ์‹๋ณ„/์ธ์ฆ ๋™์‹œ normaltic3'or'1'='1 ์‹œ๋„ : ์‹คํŒจ(Fail) 2-2. or ํ•„ํ„ฐ๋ง normaltic'# / dol1234 ์‹œ๋„ : ์‹คํŒจ 2-3..

[SegFault] (Authentication Bypass) - Login Bypass 3

[SegFault] Authentication Bypass (Login) Login Bypass 3. normaltic3 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ด ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found - Params ํ™•์ธ 200 OK ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! /login3/login.php ๊ฒฝ๋กœ์— post ๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserI..

[SegFault] (Authentication Bypass) - Login Bypass 2

[SegFault] Authentication Bypass (Login) Login Bypass 2. normaltic2 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์šฐ์„  ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! /login2/login.php ๊ฒฝ๋กœ์— post๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserId=doldol&Password=..

[SegFault] (Authentication Bypass) - Login Bypass 1

[SegFault] Authentication Bypass (Login) Login Bypass 1. normaltic1 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ์„ ์‹œ๋„ ํ•ด๋ณธ๋‹ค. 302 Found 200 OK ์œ„์˜ ๋‘ history์— ๋Œ€ํ•œ ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! ์š”์ฒญ(Requset)์—์„œ POST ๋ฉ”์„œ๋“œ๋ฅผ ์ด์šฉํ•˜์—ฌ /login1/login.php ๊ฒฝ๋กœ์— ํŒŒ๋ผ๋ฏธํ„ฐUserId=doldol&Password=dol12..

[SegFault] (Authentication Bypass) - PIN Code Bypass

[SegFault] Authentication Bypass (Code) PIN CODE Bypass. ํ•ต๋ฏธ์‚ฌ์ผ ์‹œ์Šคํ…œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ํš๋“ํ–ˆ๋‹ค! ๋ฐœ์‚ฌ๋งŒ ๋‚จ์•˜๋‹ค! ๊ฐ€์ž!!! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 200 OK (์ ‘์†) 200 OK (Fire) 200 OK (ํ™•์ธ) 200 OK (์ธ์ฆ) ์ƒ๊ฐ ๊ณผ์ • ์ƒ๊ฐ ๊ณผ์ • 1. ํŒŒ๋ผ๋ฏธํ„ฐ admin_pass๊ฐ€ ๋„˜์–ด๊ฐ€์ง€๋งŒ, ์•Œ์•„๋‚ผ ๋ฐฉ๋ฒ•์ด ์•ˆ๋ณด์ธ๋‹ค. 2. ๊ทธ๋Ÿฐ๋ฐ? URL์„ ๋ณด๋ฉด Step์œผ๋กœ ๋‹จ๊ณ„๊ฐ€ ๋„˜์–ด๊ฐ€๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. 3. ์ง์ ‘ ์ ‘๊ทผ ์‹œ๋„ ํ•ด๋ณด์ž!! 4. Step1.php ์—์„œ Step2.php๋กœ ๋„˜์–ด๊ฐ€๋‹ˆ๊นŒ? 5. ๋‹ค์Œ์€ Step3.php๊ฐ€ ์•„๋‹๊นŒ? ํ’€์ด ๊ณผ์ •..

[๊ธฐ๋ก์ผ์ง€] ๐Ÿ“š 05์ฃผ์ฐจ (๐Ÿ”“Authentication Bypass)

์ธ์ฆ (Authentication) Bypass with SQL Injection SQL Injection SQL Injection์ด๋ž€? ๋ง ๊ทธ๋Œ€๋กœ SQL ์งˆ์˜๋ฌธ์„ ์‚ฝ์ž…ํ•˜์—ฌ ์„œ๋ฒ„ ์ธก์—์„œ ์ค€๋น„๋œ SQL ์งˆ์˜๋ฌธ์„ ๋ณ€์กฐํ•˜๋Š” ๊ณต๊ฒฉ์„ ์˜๋ฏธํ•œ๋‹ค. ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•˜๋Š” ์ž…๋ ฅ๊ฐ’์— ๋Œ€ํ•ด ๊ฒ€์ฆ์„ ์ œ๋Œ€๋กœ ํ•˜์ง€ ์•Š๋Š” ์ทจ์•ฝ์ ์„ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉด SQL๋ฌธ์„ ๋ผ์›Œ ๋„ฃ์„์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค. ๊ณต๊ฒฉ์ž๊ฐ€ ์ž…๋ ฅ์ฐฝ์— ์•…์˜์ ์œผ๋กœ SQL ๋ฌธ์„ ๋ผ์›Œ๋„ฃ์–ด ๊ณต๊ฒฉํ•˜๋Š” ๊ฒƒ์ด ๋ฐ”๋กœ SQL Injection์ด๋‹ค. SQL๋ฌธ์„ ์ž…๋ ฅ์ฐฝ์— ์ ์œผ๋ฉด ๋ฌด์—‡์„ ํ•  ์ˆ˜ ์žˆ๊ธฐ์— ์ด๊ฒƒ์„ ๊ณต๊ฒฉ์ด๋ผ๊ณ  ํ• ๊นŒ? ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•˜๋Š” ๊ณผ์ •์—์„œ ํ•„์š”ํ•œ ๋ฐ์ดํ„ฐ๊ฐ€ ๋ณด๊ด€๋œ DB๊ฐ€ ์กด์žฌํ•˜๊ณ , ์š”์ฒญ์— ๋”ฐ๋ผ ํ•ด๋‹น DB๋ฅผ CRUD(์ €์žฅ,์กฐํšŒ,์ˆ˜์ •,์‚ญ์ œ)ํ•˜๋Š”๋ฐ ํ•„์š”ํ•œ SQL Query๊ฐ€ ์ค€๋น„๋˜์–ด์žˆ๋‹ค. ์ข€ ๋” ์ž์„ธํžˆ..