Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

command injection 1

[DVWA] Command Injection

Vulnerability: Command Injection์ปค๋งจ๋“œ ์ธ์ ์…˜ (Command Injection)์— ๋Œ€ํ•œ Prcatice ์ด๋‹ค.Command Injection์€ ์›น ์š”์ฒญ ๋ฉ”์‹œ์ง€์— ์ž„์˜์˜ ์‹œ์Šคํ…œ ๋ช…๋ น์–ด๋ฅผ ์‚ฝ์ž…ํ•˜๊ณ  ์ „์†ก, ์›น ์„œ๋ฒ„์—์„œ ํ•ด๋‹น ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋„๋ก ํ•˜๋Š” ๊ณต๊ฒฉ์ด๋‹ค.(์›น์—์„œ ์‹œ์Šคํ…œ ๋ช…๋ น์–ด(command)๋ฅผ ์ž…๋ ฅํ•˜๋Š” ๋ถ€๋ถ„์—์„œ ์ถ”๊ฐ€์ ์ธ ๋ช…๋ น์–ด์˜ ์‹คํ–‰์„ ํ†ตํ•ด ๊ณต๊ฒฉํ•˜๋Š” ๊ฒƒ์ด๋‹ค.)Vuln Point์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋‚ด๋ถ€์—์„œ ์‹œ์Šคํ…œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ƒํ™ฉ์—์„œ ์ž…๋ ฅ๊ฐ’์— ๋Œ€ํ•œ ์ ์ ˆํ•œ ๊ฒ€์‚ฌ ์—†์ด ์‹œ์Šคํ…œ ๋ช…๋ น์–ด์˜ ์ผ๋ถ€๋ถ„์œผ๋กœ ์ „๋‹ฌํ•˜๋Š” ๊ฒฝ์šฐ, ๊ณต๊ฒฉ์ž๊ฐ€ ์ž…๋ ฅ๊ฐ’์„ ์กฐ์ž‘ํ•˜์—ฌ ์ž„์˜์˜ ์‹œ์Šคํ…œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋‹ค.Vuln ExampleDVWA์˜ ์˜ˆ์‹œ์™€ ๊ฐ™์ด ์‚ฌ์šฉ์ž๊ฐ€ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ–ˆ์„ ๋•Œ ์›น ์„œ๋ฒ„์—์„œ pi..

Practice/DVWA 2024.04.07