Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

html entity 2

[DVWA] XSS (Stored)

Vulnerability:XSS (Stored)XSS ์ทจ์•ฝ์ ์€ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ ๊ฐ’์„ HTML์—์„œ ์ถœ๋ ฅํ•˜๋Š” ๋ถ€๋ถ„์—์„œ ๋ฐœ์ƒํ•œ๋‹ค. ๋ณธ ์‹ค์Šต์—์„œ๋Š” ์•ž์—์„œ ๋‹ค๋ฃฌ DVWA Reflected XSS ์ทจ์•ฝ์ (์ž…๋ ฅ ๊ฐ’์ด ๋ฐ˜์‚ฌ๋˜์–ด ์ถœ๋ ฅ๋˜๋Š” ๊ฒฝ์šฐ์— ๋Œ€ํ•œ XSS)์™€ ๋‹ฌ๋ฆฌ ๊ณต๊ฒฉ์˜ ๊ฒฐ๊ณผ๊ฐ€ ์„œ๋ฒ„์— ๋‚จ๊ธฐ ๋•Œ๋ฌธ์— ํ›จ์”ฌ ์œ„ํ—˜ํ•œ ๊ณต๊ฒฉ์ธ Stored XSS์— ๋Œ€ํ•˜์—ฌ ๋‹ค๋ฃฌ๋‹ค. ์ฆ‰, ์ €์žฅ ๊ฐ€๋Šฅํ•œ XSS๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•œ๋‹ค.DVWA XSS(Stored) ์‹ค์Šต์‹ค์Šต ํ™˜๊ฒฝ- Windows Docker๋ฅผ ์ด์šฉํ•œ DVWA- Windows ํ™˜๊ฒฝ์˜ Burp Suiteํ•ด๋‹น ์‹ค์Šต ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.Name๊ณผ Message๋ฅผ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ์ž…๋ ฅ์ฐฝ์ด ์กด์žฌํ•˜๊ณ , ์ž…๋ ฅ์ฐฝ ์•„๋ž˜์˜ ์˜ˆ์‹œ๋ฅผ ๋ณด๋ฉด Name๊ณผ Message์˜ ์ •๋ณด๊ฐ€ ์ถœ๋ ฅ๋˜๊ณ  ์žˆ๋‹ค..

Practice/DVWA 2024.04.17

[DVWA] XSS (Reflected)

Vulnerability: XSS (Reflected)XSS ์ทจ์•ฝ์ ์€ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ ๊ฐ’์„ HTML์—์„œ ์ถœ๋ ฅํ•˜๋Š” ๋ถ€๋ถ„์—์„œ ๋ฐœ์ƒํ•œ๋‹ค. ๋ณธ ์‹ค์Šต์—์„œ๋Š” ์ž…๋ ฅ ๊ฐ’์ด ๋ฐ˜์‚ฌ๋˜์–ด ์ถœ๋ ฅ๋˜๋Š” ๊ฒฝ์šฐ์— ๋Œ€ํ•˜์—ฌ XSS๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•œ๋‹ค.DVWA XSS(Reflected) ์‹ค์Šต์‹ค์Šต ํ™˜๊ฒฝ- Windows Docker๋ฅผ ์ด์šฉํ•œ DVWA- Windows ํ™˜๊ฒฝ์˜ Burp SuiteLow, Medium, High, Impossible ๋ ˆ๋ฒจ์— ์ƒ๊ด€์—†์ด ์œ„์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜ค๊ณ , ์ž…๋ ฅ์ฐฝ์— ์ž…๋ ฅํ•˜๋Š” ๊ฐ’์„ ํ•ด๋‹น ํŽ˜์ด์ง€์— ๊ทธ๋Œ€๋กœ ๋ฐ˜์‚ฌ์‹œ์ผœ ์ถœ๋ ฅํ•ด์ฃผ๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด๋‹ค.alert(document.cookie);์œ„์™€ ๊ฐ™์ด ์ฟ ํ‚ค๋ฅผ ์ถœ๋ ฅํ•ด์ฃผ๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•  ๊ฒƒ์ด๋‹ค. Security Level: Low ํ™•์ธํ•˜๊ธฐ์šฐ์„  XSS ๊ฐ€๋Šฅ..

Practice/DVWA 2024.04.14