Archive for Dev. (junyup2)

์ง€์‹์„ ์ฑ„์›Œ๊ฐ€๋Š” ใ€Ž๊ฐœ๋ฐœ์ž/ํ™”์ดํŠธํ•ด์ปคใ€๋ฅผ ๋ชฉํ‘œ๋กœ ์ •๋ฆฌํ•˜๋Š” ๋ธ”๋กœ๊ทธ

stored 1

[DVWA] XSS (Stored)

Vulnerability:XSS (Stored)XSS ์ทจ์•ฝ์ ์€ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ ๊ฐ’์„ HTML์—์„œ ์ถœ๋ ฅํ•˜๋Š” ๋ถ€๋ถ„์—์„œ ๋ฐœ์ƒํ•œ๋‹ค. ๋ณธ ์‹ค์Šต์—์„œ๋Š” ์•ž์—์„œ ๋‹ค๋ฃฌ DVWA Reflected XSS ์ทจ์•ฝ์ (์ž…๋ ฅ ๊ฐ’์ด ๋ฐ˜์‚ฌ๋˜์–ด ์ถœ๋ ฅ๋˜๋Š” ๊ฒฝ์šฐ์— ๋Œ€ํ•œ XSS)์™€ ๋‹ฌ๋ฆฌ ๊ณต๊ฒฉ์˜ ๊ฒฐ๊ณผ๊ฐ€ ์„œ๋ฒ„์— ๋‚จ๊ธฐ ๋•Œ๋ฌธ์— ํ›จ์”ฌ ์œ„ํ—˜ํ•œ ๊ณต๊ฒฉ์ธ Stored XSS์— ๋Œ€ํ•˜์—ฌ ๋‹ค๋ฃฌ๋‹ค. ์ฆ‰, ์ €์žฅ ๊ฐ€๋Šฅํ•œ XSS๊ฐ€ ๊ฐ€๋Šฅํ•œ์ง€ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•œ๋‹ค.DVWA XSS(Stored) ์‹ค์Šต์‹ค์Šต ํ™˜๊ฒฝ- Windows Docker๋ฅผ ์ด์šฉํ•œ DVWA- Windows ํ™˜๊ฒฝ์˜ Burp Suiteํ•ด๋‹น ์‹ค์Šต ํŽ˜์ด์ง€์— ์ ‘์†ํ•˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.Name๊ณผ Message๋ฅผ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ์ž…๋ ฅ์ฐฝ์ด ์กด์žฌํ•˜๊ณ , ์ž…๋ ฅ์ฐฝ ์•„๋ž˜์˜ ์˜ˆ์‹œ๋ฅผ ๋ณด๋ฉด Name๊ณผ Message์˜ ์ •๋ณด๊ฐ€ ์ถœ๋ ฅ๋˜๊ณ  ์žˆ๋‹ค..

Practice/DVWA 2024.04.17