Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

CTF 14

[SegFault] (Authentication Bypass) - Secret Login

[SegFault] Authentication Bypass (Login) Secret Login. ๊ด€๋ฆฌ์ž ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๊ทธ๋Ÿฐ๋ฐ... ๊ด€๋ฆฌ์ž ๊ณ„์ •์ด ๋ญ”์ง€ ๋ชจ๋ฅธ๋‹ค..!? ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • 1. ๋กœ๊ทธ์ธ ํ•˜์˜€์„ ๋•Œ ํŠน๋ณ„ํ•œ ์ ์ด ๋ณด์ด์ง€ ์•Š๋Š”๋‹ค. 2. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes -> doldol'and'1'='1 / dol1234 ๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต 3. 'or'1'='1 ๋กœ ์‹œ๋„ ๊ด€๋ฆฌ์ž ๊ณ„์ •์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ์—†๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ์ „์ฒด ๋ฐ์ดํ„ฐ๋ฅผ ์กฐํšŒํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•˜์ž. 3-1. doldol'or'1'..

[SegFault] (Authentication Bypass) - Login Bypass 5

[SegFault] Authentication Bypass (Login) Login Bypass 5. normaltic5 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ํ›„์˜ index ํŽ˜์ด์ง€์˜ ์š”์ฒญ์„ ํ™•์ธํ•ด๋ณธ๋‹ค. ์œ„์˜ ์š”์ฒญ์„ ํ™•์ธํ•ด๋ณด๋ฉด ์ฟ ํ‚ค(Cookie)์— loginUser๋ผ๊ณ  ํ•˜๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ(Params)๊ฐ€ ์กด์žฌํ•œ๋‹ค. ํ•ด๋‹น ํŒŒ๋ผ๋ฏธํ„ฐ์˜ ์ž…๋ ฅ๊ฐ’์€ doldol, ์ฆ‰ ๋กœ๊ทธ์ธํ•œ ์œ ์ €๋ช…๊ณผ ๊ฐ™๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์ƒ๊ฐ ๊ณผ์ • ์ฟ ํ‚ค์— loginUser = doldol ์ด๋ผ๊ณ  ํ•˜๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ๊ฐ€ ๋กœ๊ทธ์ธ ํ›„์— ํ™•์ธ๋œ๋‹ค. ์ฟ ํ‚ค๋Š” ์‰ฝ๊ฒŒ ๋ณ€์กฐ๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ธฐ ๋•Œ..

[SegFault] (Authentication Bypass) - Login Bypass 4

[SegFault] Authentication Bypass (Login) Login Bypass 4. normaltic4 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 ํ•ด๋‹น ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์—ฌ ํ™•์ธํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ƒ๊ฐ๊ณผ์ • 1. SQL Injection์ด ๊ฐ€๋Šฅํ•œ๊ฐ€? Yes -> doldol'and'1'='1 / dol1234๋กœ ๋กœ๊ทธ์ธ ์‹œ๋„ : ์„ฑ๊ณต 2. ์–ด๋–ค ๋กœ์ง์œผ๋กœ ์ด๋ฃจ์–ด์ ธ ์žˆ์„๊นŒ? 2-1. ์‹๋ณ„/์ธ์ฆ ๋™์‹œ normaltic3'or'1'='1 ์‹œ๋„ : ์‹คํŒจ(Fail) 2-2. or ํ•„ํ„ฐ๋ง normaltic'# / dol1234 ์‹œ๋„ : ์‹คํŒจ 2-3..

[SegFault] (Authentication Bypass) - Login Bypass 3

[SegFault] Authentication Bypass (Login) Login Bypass 3. normaltic3 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜ด ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found - Params ํ™•์ธ 200 OK ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! /login3/login.php ๊ฒฝ๋กœ์— post ๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserI..

[SegFault] (Authentication Bypass) - Login Bypass 2

[SegFault] Authentication Bypass (Login) Login Bypass 2. normaltic2 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์šฐ์„  ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history), ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! /login2/login.php ๊ฒฝ๋กœ์— post๋ฉ”์„œ๋“œ๋กœ ํŒŒ๋ผ๋ฏธํ„ฐ UserId=doldol&Password=..

[SegFault] (Authentication Bypass) - Login Bypass 1

[SegFault] Authentication Bypass (Login) Login Bypass 1. normaltic1 ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ์„ ์‹œ๋„ ํ•ด๋ณธ๋‹ค. 302 Found 200 OK ์œ„์˜ ๋‘ history์— ๋Œ€ํ•œ ์š”์ฒญ(Request)์„ ์‚ดํŽด๋ณด์ž ! ์š”์ฒญ(Requset)์—์„œ POST ๋ฉ”์„œ๋“œ๋ฅผ ์ด์šฉํ•˜์—ฌ /login1/login.php ๊ฒฝ๋กœ์— ํŒŒ๋ผ๋ฏธํ„ฐUserId=doldol&Password=dol12..

[SegFault] (Authentication Bypass) - Admin is Mine

[SegFault] Authentication Bypass (Admin) Admin is Mine. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธ 200 OK : ์ •์ƒ์ ์ธ ์‘๋‹ต ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ๋จผ์ € ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ œ๊ณต๋œ ID/PW๋ฅผ ์ž…๋ ฅํ–ˆ์Œ์—๋„ ํ•ด๋‹น ์ฐฝ์—์„œ ๋„˜์–ด๊ฐ€์ง€ ์•Š์Œ์„ ํ™•์ธ, ๋กœ๊ทธ์ธ์ด ์ง„ํ–‰๋˜์ง€ ์•Š๋Š”๋‹ค?! ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history) ํ™•์ธ ํ•ด๋ณด์ž ! ID์™€ PW๋ฅผ ์ž…๋ ฅํ–ˆ์Œ์—๋„ ํŒŒ๋ผ๋ฏธํ„ฐ(Params)๊ฐ€ ๋“ค์–ด๊ฐ€์ง€ ์•Š๊ณ ์žˆ์Œ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์š”์ฒญ(R..

[SegFault] (Authentication Bypass) - PIN Code Bypass

[SegFault] Authentication Bypass (Code) PIN CODE Bypass. ํ•ต๋ฏธ์‚ฌ์ผ ์‹œ์Šคํ…œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ํš๋“ํ–ˆ๋‹ค! ๋ฐœ์‚ฌ๋งŒ ๋‚จ์•˜๋‹ค! ๊ฐ€์ž!!! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 200 OK (์ ‘์†) 200 OK (Fire) 200 OK (ํ™•์ธ) 200 OK (์ธ์ฆ) ์ƒ๊ฐ ๊ณผ์ • ์ƒ๊ฐ ๊ณผ์ • 1. ํŒŒ๋ผ๋ฏธํ„ฐ admin_pass๊ฐ€ ๋„˜์–ด๊ฐ€์ง€๋งŒ, ์•Œ์•„๋‚ผ ๋ฐฉ๋ฒ•์ด ์•ˆ๋ณด์ธ๋‹ค. 2. ๊ทธ๋Ÿฐ๋ฐ? URL์„ ๋ณด๋ฉด Step์œผ๋กœ ๋‹จ๊ณ„๊ฐ€ ๋„˜์–ด๊ฐ€๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. 3. ์ง์ ‘ ์ ‘๊ทผ ์‹œ๋„ ํ•ด๋ณด์ž!! 4. Step1.php ์—์„œ Step2.php๋กœ ๋„˜์–ด๊ฐ€๋‹ˆ๊นŒ? 5. ๋‹ค์Œ์€ Step3.php๊ฐ€ ์•„๋‹๊นŒ? ํ’€์ด ๊ณผ์ •..

[SegFault] (Authentication Bypass) - Get Admin

[SegFault] Authentication Bypass (Admin) Get Admin. admin ๊ณ„์ •์œผ๋กœ ์ ‘์†ํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found 200 OK ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ๋จผ์ € ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found : Cookie๋ฅผ ๋ฐ›์•„์˜ด 200 OK : ์ •์ƒ์ ์ธ ์‘๋‹ต ์š”์ฒญ(Request)๊ณผ ์‘๋‹ต(Response)๋ฅผ ์‚ดํŽด๋ณด์ž ! ์š”์ฒญ(Requset)์—์„œ POST ๋ฉ”์„œ๋“œ๋ฅผ ์ด์šฉํ•˜์—ฌ /2/login.p..

[SegFault] (Burp) - Burp Suite Prac 4.

[SegFault] Burp Suite Prac. Prac 4. Flag๋ฅผ ์ฐพ์œผ์‹œ์˜ค! ๋””์ฝ”๋”(Decoder) ํ™œ์šฉ ๋ฌธ์ œ ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. You are Not Admin์ด๋ผ๋Š” ๋ฌธ๊ตฌ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๊ฒƒ์„ ๋ณด๋ฉด Admin์œผ๋กœ ๊ถŒํ•œ์„ ์ƒ์Šนํ•ด์ค˜์•ผ ํ•จ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธํ•œ๋‹ค. 302 Found : ์š”์ฒญํ•œ ๋ฆฌ์†Œ์Šค๋ฅผ ๋‹ค๋ฅธ URL์—์„œ ์ฐพ์•˜๋‹ค. 200 OK : ์ •์ƒ์ ์ธ ์‘๋‹ต ์š”์ฒญํ•œ ๋ฆฌ์†Œ์Šค๋ฅผ ๋‹ค๋ฅธ URL์—์„œ ์ฐพ์Œ : ์ฟ ํ‚ค(Cookie)์—์„œ level ์ •๋ณด๋ฅผ ๋ฐ›์•„์˜จ ๊ฒƒ์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ๋‹ค. Admin ๊ถŒํ•œ์„ ์œ„ํ•ด์„œ level์„ ์˜ฌ๋ ค์ค˜์•ผ ํ•จ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์š”์ฒญ(Request)๊ณผ ์‘๋‹ต(Response)๋ฅผ ์‚ดํŽด๋ณด์ž..