๋ฐ˜์‘ํ˜•

๐Ÿ”’ Cyber Security 27

[DreamHack] ๋“œ๋ฆผํ•ต ์›นํ•ดํ‚น: csrf-1

https://dreamhack.io/wargame/challenges/26/ csrf-1 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. CSRF ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. Reference Client-side Basic dreamhack.io ๋ฌธ์ œ์ •๋ณด ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. CSRF ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ๋”๋ณด๊ธฐ #!/usr/bin/python3 from flask import Flask, request, render_template from selenium import webdriver import urllib import os app = Flask(__name__) app.secret_key = os.urand..

[HackerSchool] ํ•ด์ปค์Šค์ฟจ FTZ: level3

$ cat hint [level3@ftz level3]$ cat hint ๋‹ค์Œ ์ฝ”๋“œ๋Š” autodig์˜ ์†Œ์Šค์ด๋‹ค. #include #include #include int main(int argc, char **argv){ char cmd[100]; if( argc!=2 ){ printf( "Auto Digger Version 0.9\n" ); printf( "Usage : %s host\n", argv[0] ); exit(0); } strcpy( cmd, "dig @" ); strcat( cmd, argv[1] ); strcat( cmd, " version.bind chaos txt"); system( cmd ); } ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ level4์˜ ๊ถŒํ•œ์„ ์–ป์–ด๋ผ. more hints. - ๋™์‹œ์— ์—ฌ๋Ÿฌ ๋ช…๋ น์–ด..

[HackerSchool] ํ•ด์ปค์Šค์ฟจ FTZ: level2

$ cat hint [level2@ftz level2]$ cat hint ํ…์ŠคํŠธ ํŒŒ์ผ ํŽธ์ง‘ ์ค‘ ์‰˜์˜ ๋ช…๋ น์„ ์‹คํ–‰์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค๋Š”๋ฐ... ์ด๋ฒˆ ๋ฌธ์ œ๋Š” ํŒŒ์ผ์„ ํŽธ์ง‘ํ• ๋•Œ ์–ป์€ ๊ถŒํ•œ์œผ๋กœ ๋ฐ”๋กœ ์‰˜ ๋ช…๋ น, ์ฆ‰ my-pass๋ฅผ ์‹คํ–‰์‹œ์ผœ์„œ ํŒจ์Šค์›Œ๋“œ๋ฅผ ์–ป์–ด๋‚ด๋Š” ๋ฌธ์ œ๋‹ค. ์ผ๋‹จ level3 ๊ถŒํ•œ์„ ์ค„ ์ˆ˜ ์žˆ์œผ๋ฉด์„œ ํŽธ์ง‘ํ•  ์ˆ˜ ์žˆ๋Š” ํŒŒ์ผ์„ ์ฐพ์•„๋ณด์ž $ find / -user level3 [level2@ftz level2]$ find / -user level3 find: /lost+found: Permission denied find: /boot/lost+found: Permission denied find: /proc/1/fd: Permission denied ... /usr/bin/editor ... find: /home/tr..

[HackerSchool] ํ•ด์ปค์Šค์ฟจ FTZ: Level1

FTZ Level ๋ฌธ์ œ๋“ค์—์„œ ์ตœ์ข… ๋ชฉํ‘œ๋Š” my-pass ๋ช…๋ น์–ด๋กœ ๋‹ค์Œ ๋ ˆ๋ฒจ์— ํ•ด๋‹นํ•˜๋Š” ๋น„๋ฒˆ์„ ์ฐพ์•„๋‚ด๋Š” ๊ฒƒ์ด๋‹ค. ๊ทธ๋ฆฌ๊ณ  my-pass ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋ ค๋ฉด ๊ทธ ๋ ˆ๋ฒจ์— ํ•ด๋‹นํ•˜๋Š” ๊ถŒํ•œ์„ ์–ป์–ด์•ผํ•œ๋‹ค level1 (๋น„๋ฒˆ๋„ level1) ์œผ๋กœ ๋กœ๊ทธ์ธํ•˜๊ณ  ์„ฑ๊ณตํ•˜๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ์ฐฝ์ด ๋œฌ๋‹ค ์•ˆ๋–ด๋‹ค๋ฉด ์„ธํŒ…์ด ์ž˜ ๋˜์–ด์žˆ๋Š”์ง€ ํ™•์ธํ•˜์ž Xshell 7 (Build 0113) Copyright (c) 2020 NetSarang Computer, Inc. All rights reserved. Type `help' to learn how to use Xshell prompt. [C:\~]$ Connecting to 192.168.176.128:22... Connection established. To escape to local sh..

[DreamHack] ๋“œ๋ฆผํ•ต ์›นํ•ดํ‚น: simple-sqli

https://dreamhack.io/wargame/challenges/24/ simple_sqli ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. SQL INJECTION ์ทจ์•ฝ์ ์„ ํ†ตํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Server-side Basic dreamhack.io ๋ฌธ์ œ์ •๋ณด ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. SQL INJECTION ์ทจ์•ฝ์ ์„ ํ†ตํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. ๋”๋ณด๊ธฐ #!/usr/bin/python3 from flask import Flask, request, render_template, g import sqlite3 import os import binascii app = Flask(__name__) app.s..

[DreamHack] ๋“œ๋ฆผํ•ต ์›นํ•ดํ‚น: Session-basic

https://dreamhack.io/wargame/challenges/6/ cookie ์ฟ ํ‚ค๋กœ ์ธ์ฆ ์ƒํƒœ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io ๋ฌธ์ œ์ •๋ณด ์ฟ ํ‚ค์™€ ์„ธ์…˜์œผ๋กœ ์ธ์ฆ ์ƒํƒœ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œํŒŒ์ผ ๋”๋ณด๊ธฐ #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for app = Flask(__name__) try: FLAG = op..

[DreamHack] ๋“œ๋ฆผํ•ต ์›นํ•ดํ‚น: Cookie

https://dreamhack.io/wargame/challenges/6/ cookie ์ฟ ํ‚ค๋กœ ์ธ์ฆ ์ƒํƒœ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io ๋ฌธ์ œ์ •๋ณด ์ฟ ํ‚ค๋กœ ์ธ์ฆ ์ƒํƒœ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œํŒŒ์ผ ๋”๋ณด๊ธฐ #!/usr/bin/python3 from flask import Flask, request, render_template, make_response, redirect, url_for app = Flask(__name__) try: FLAG = open('...

๋ฐ˜์‘ํ˜•