Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

File Downlaod 1

[SegFault] (File Vuln) - Get Flag File 2

[SegFault] (File Vuln) Get Flag File 2 FLAG ํŒŒ์ผ์„ ๊ตฌํ•ด๋ผ! ๋ฌธ์ œ ํŒŒ์•… ๋ณธ ๋ฌธ์ œ์—๋Š” ๋‹ค์šด๋กœ๋“œ ๊ธฐ๋Šฅ์ด ์กด์žฌํ•œ๋‹ค. download.php ํŒŒ์ผ์˜ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์ด์šฉํ•˜์—ฌ flag๋ฅผ ์ฐพ์•„์•ผ ํ•œ๋‹ค. Vunl Point ๊ฒŒ์‹œํŒ์˜ ๊ธ€์“ฐ๊ธฐ ๊ธฐ๋Šฅ์—์„œ .php ํ™•์žฅ์ž๋ฅผ ํ•„ํ„ฐ๋งํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— png ํ™•์žฅ์ž๋กœ ์˜ฌ๋ฆฌ๊ณ  .htaccess ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜์—ฌ ์‹คํ–‰๊ฐ€๋Šฅํ•œ ํ™•์žฅ๋ช…์„ ์ˆ˜์ •ํ•˜์—ฌ ์šฐํšŒ๋ฅผ ์‹œ๋„ํ•œ ๊ฒฐ๊ณผ ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•œ ๊ฒƒ์„ ํ™•์ธํ•˜์˜€๋‹ค. ๋ฌธ์ œ ํ’€์ด (ํ•ด๊ฒฐ ๋ฐฉ์•ˆ) ํ•œ์ค„ ์›น ์‰˜ ๊ธฐ๋ณธ์ ์ธ ํ•œ ์ค„ ์›น์‰˜์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. ํŒŒ์ผ ์—…๋กœ๋“œ web_shell.php -> web_shell.png ์œ„์™€ ๊ฐ™์ด ํ™•์žฅ์ž๋ฅผ .png๋กœ ์˜ฌ๋ฆฌ๊ณ , .htaccess ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•œ๋‹ค. filename = ".htaccess" Ad..