Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

redirect 1

[SegFault] (Authentication Bypass) - Admin is Mine

[SegFault] Authentication Bypass (Admin) Admin is Mine. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜์ž! ๋ฌธ์ œ ํŒŒ์•… ์œ„์˜ ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ํ™”๋ฉด์ด ๋‚˜์˜จ๋‹ค. ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ • : [ID/PW] : doldol / dol1234 Burp Suite์„ ์ด์šฉํ•˜์—ฌ ์‚ฌ์ดํŠธ ์ ‘์† ๊ณผ์ •์˜ ์ƒํƒœ์ฝ”๋“œ(Status code) ํ™•์ธ 200 OK : ์ •์ƒ์ ์ธ ์‘๋‹ต ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ๊ตฌ์กฐ๋ฅผ ์•Œ๊ธฐ ์œ„ํ•ด, ๋จผ์ € ์•Œ๊ณ  ์žˆ๋Š” ์ •๋ณด๋กœ ๋กœ๊ทธ์ธ ํ•ด๋ณธ๋‹ค. ์ œ๊ณต๋œ ID/PW๋ฅผ ์ž…๋ ฅํ–ˆ์Œ์—๋„ ํ•ด๋‹น ์ฐฝ์—์„œ ๋„˜์–ด๊ฐ€์ง€ ์•Š์Œ์„ ํ™•์ธ, ๋กœ๊ทธ์ธ์ด ์ง„ํ–‰๋˜์ง€ ์•Š๋Š”๋‹ค?! ๋กœ๊ทธ์ธ ๊ณผ์ •์˜ ํžˆ์Šคํ† ๋ฆฌ(HTTP history) ํ™•์ธ ํ•ด๋ณด์ž ! ID์™€ PW๋ฅผ ์ž…๋ ฅํ–ˆ์Œ์—๋„ ํŒŒ๋ผ๋ฏธํ„ฐ(Params)๊ฐ€ ๋“ค์–ด๊ฐ€์ง€ ์•Š๊ณ ์žˆ์Œ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์š”์ฒญ(R..