Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

reflected 1

[DVWA] XSS (Reflected)

Vulnerability: XSS (Reflected)XSS ์ทจ์•ฝ์ ์€ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ ๊ฐ’์„ HTML์—์„œ ์ถœ๋ ฅํ•˜๋Š” ๋ถ€๋ถ„์—์„œ ๋ฐœ์ƒํ•œ๋‹ค. ๋ณธ ์‹ค์Šต์—์„œ๋Š” ์ž…๋ ฅ ๊ฐ’์ด ๋ฐ˜์‚ฌ๋˜์–ด ์ถœ๋ ฅ๋˜๋Š” ๊ฒฝ์šฐ์— ๋Œ€ํ•˜์—ฌ XSS๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•œ๋‹ค.DVWA XSS(Reflected) ์‹ค์Šต์‹ค์Šต ํ™˜๊ฒฝ- Windows Docker๋ฅผ ์ด์šฉํ•œ DVWA- Windows ํ™˜๊ฒฝ์˜ Burp SuiteLow, Medium, High, Impossible ๋ ˆ๋ฒจ์— ์ƒ๊ด€์—†์ด ์œ„์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๊ฐ€ ๋‚˜์˜ค๊ณ , ์ž…๋ ฅ์ฐฝ์— ์ž…๋ ฅํ•˜๋Š” ๊ฐ’์„ ํ•ด๋‹น ํŽ˜์ด์ง€์— ๊ทธ๋Œ€๋กœ ๋ฐ˜์‚ฌ์‹œ์ผœ ์ถœ๋ ฅํ•ด์ฃผ๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด๋‹ค.alert(document.cookie);์œ„์™€ ๊ฐ™์ด ์ฟ ํ‚ค๋ฅผ ์ถœ๋ ฅํ•ด์ฃผ๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•  ๊ฒƒ์ด๋‹ค. Security Level: Low ํ™•์ธํ•˜๊ธฐ์šฐ์„  XSS ๊ฐ€๋Šฅ..

Practice/DVWA 2024.04.14