Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

File Inclusion 1

[DVWA] File Inclusion

Vulnerability: File Inclusion File Inclusion(ํŒŒ์ผ ์‹คํ–‰) ์ทจ์•ฝ์ ์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ง€์ •ํ•œ ํŒŒ์ผ ๋‚ด์— ํฌํ•จ๋œ Server Side Script ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๋„๋ก ํ•˜๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ๊ณต๊ฒฉ์ž์˜ ํŒŒ์ผ์ด ์›น ์„œ๋ฒ„ ๋‚ด๋ถ€์— ์žˆ์œผ๋ฉด ๋‚ด๋ถ€ํŒŒ์ผ์‹คํ–‰(LFI, Local File Inclusion), ๋‹ค๋ฅธ ์„œ๋ฒ„์— ์œ„์น˜ํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” ์™ธ๋ถ€ํŒŒ์ผ์‹คํ–‰(RFI, Remote File Inclusion)์ด๋ผ๊ณ  ํ•œ๋‹ค. ์ตœ๊ทผ์—๋Š” PHP๊ฐ€ ์™ธ๋ถ€ํŒŒ์ผ์— ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ์ด ๊ธฐ๋ณธ์ ์œผ๋กœ ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ ์‹ค์ œ ์„œ๋น„์Šค์—์„œ RFI ์ทจ์•ฝ์ ์€ ๊ฑฐ์˜ ๋ฐœ์ƒํ•˜์ง€ ์•Š๋Š”๋‹ค. ๊ฐœ๋ฐœ์ž๋“ค์˜ ์ธ์‹์ด ํ™•์‚ฐ๋˜๋ฉด์„œ LFI์˜ ๊ฒฝ์šฐ์—๋„ ํ”ํ•˜์ง€๋Š” ์•Š์€ ์ทจ์•ฝ์ ์ด ๋˜์–ด๊ฐ€๊ณ  ์žˆ๋‹ค. LFI ์ทจ์•ฝ์ ์€ ํŒŒ์ผ์—…๋กœ๋“œ(์›น์‰˜์—…๋กœ๋“œ) ์ทจ์•ฝ์ ์— ๋น„ํ•ด์„œ๋Š” ๋งค์šฐ ๋“œ๋ฌผ๊ฒŒ ๋ฐœ๊ฒฌ๋œ๋‹ค๊ณ  ํ•œ๋‹ค..

Practice/DVWA 2024.04.09