1581, 1/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   »ç¿ëÁß
   http://www.cyworld.com/csy_lovely
   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (8)

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1835 [º¹»ç]


1) È®ÀåÀÚ ÇÊÅ͸µ web.php(À¥ ¼¿)ÆÄÀÏÀ» ¾÷·Îµå ÇÒ ¼ö ¾ø´Ù.
2) htaccess, web.zip À¥¼¿ ¾÷·Îµå ¼º°ø
3) À¥ ½© ½ÇÇà(web.zip Ŭ¸¯ÇÏ¸é ¹Ù·Î ½ÇÇà)

ÁÖ¿ä ½ÇÇà ¸í·É¾î (À¥ ½© ¸¶´Ù ±â´ÉÀÌ ´Ù¸§)

¸ñ·Ïº¸±â :ls
»óÀ§ ¸ñ·Ï º¸±â : ls ../ ../
ÆÄÀÏ »èÁ¦ : rm -rf[Áö¿ï ÆÄÀϸí]
À¥ ÆäÀÌÁö ´Ù¿î : tar -cvf c.tar

2.File download Vulnerability
´Ù¿î·Îµå ÆÄÀÏÀÇ À§Ä¡¿¡ Á¦ÇÑ Á¶°ÇÀ¸ ¤©ºÎ¿©ÇÏÁö ¾Ê¾Æ ÁöÁ¤µÈ ÆÄÀÏ ÀÌ¿ÜÀÇ À§Ä¡¿¡ ÀÖ´Â ÆÄÀϵ鿡 Á¢±ÙÇϰųª ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡À» ¸»ÇÑ´Ù. °Ô½ÃÆÇ µî¿¡ ÀúÀåµÈ ÀÚ·á¿¡ ´ëÇØ ´Ù¿î·Îµå ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ¿© ´Ù¿î·Îµå ±â´ÉÀ» Á¦°øÇϸ鼭, ´ë»ó ÀÚ·á ÆÄÀÏÀÇ À§Ä¡ ÁöÁ¤¿¡ Á¦ÇÑ Á¶°ÇÀ» ºÎ¿©ÇÏÁö ¾Ê¾ÒÀ» °æ¿ì URL°£ÀÇ ´Ù¿î·Îµå ½ºÅ©¸³Æ®ÀÇ Àμö°ª¿¡ '../' ¹®ÀÚ¿­ µîÀ» ÀÔ·ÂÇÏ¿© ½Ã½ºÅÛ µð·ºÅ丮 µî¿¡ ÀÖ´Â /etc/passwd ¿Í °°Àº ºñ°ø°³ ÀÚ·áµéÀÌ À¯ÃâµÉ ¼ö ÀÖ´Ù.
ƯÈ÷, ¸®´ª½º ¹× À¯´Ð½º °è¿­ÀÇ À¥ ¼­¹ö¿¡ °¢º°È÷ ÁÖÀÇ°¡ ÇÊ¿äÇÏ´Ù. ¿¹¸¦ µé¾î ÆÄÀÏ ´Ù¿î·Îµå ½Ã ÁÖ¼Ò Ã¢¿¡ ¡é¿Í °°ÀÌ ÀÔ·Â
http://servername.com/data/download.php?path=upfiles&filename=½Åû¼­.doc
Æнº¿öµå(password) ÆÄÀÏÀÇ ÇØÅ·À» ½ÃµµÇÑ´Ù.
http://servername.com/date/download.php?path../../../../../../../../../../../etc&filename=passwd
(download.php cgiÀÇ path º¯¼ö¿¡ À§Ä¡¸¦ ÁöÁ¤ÇÏ°í filename º¯¼ö¸¦ ÀÌ¿ëÇØ passwd ÆÄÀÏ ´Ù¿î·Îµå)
http://servername.com/data/download.php?path=upfiles&filename=../../../../../../../../../../../etc/passwd
(download.php cgi ÀÇ filenameº¯¼ö¿¡¼­ °æ·Î¸¦ µû¶ó µé¾î°¡ passwd ÆÄÀÏÀ» ´Ù¿î·Îµå ¹ÞÀ½)

  Hit : 8174     Date : 2011/08/03 02:12



    
ghj4890 ÁÁ³×¿©
À¯ÀÍÇÔ
2011/08/04  
»ç¿ëÁß °¨»çÇÕ´Ï´Ù~ 2011/08/06  
salis °¨»çÇÕ´Ï´Ù. 2011/08/18  
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 18763
1580   °í¼ö´ÔµéÀÇ µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù     vbnm111
02/11 212
1579   ¸®´ª½º Ä¿³Î 2.6 ¹öÀü ÀÌÈÄÀÇ LKM     jdo
07/25 711
1578   ½©ÄÚµå ¸ðÀ½     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 1542
1577   Call by value VS Call by Reference     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 924
1576   (²Ä¼ö) L.O.B Çѹ濡 Ŭ¸®¾îÇϱâ[2]     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 1262
1575   towelroot.c (zip) ÄÚ¸àÆÃ.[1]     scube
08/18 3785
1574   levitator.c (¾Èµå·ÎÀÌµå ·çÆÃ) °ø°Ý ºÐ¼® ¼Ò½º ÄÚµå °øÀ¯.[4]     scube
08/17 3696
1573   ¹«·á Á¤º¸º¸¾È ±â¼úÀÎÀç ¾ç¼º °úÁ¤ ±³À°»ý ¸ðÁý     chanjung111
06/17 4499
1572   K-Shield ÁִϾî 5±â ¸ðÁý     lrtk
06/17 4227
1571   [ÆÁ] ÆÄÀ̽ã 2¼Ò½º¸¦ 3À¸·Î º¯°æÇØÁÖ´Â »çÀÌÆ®[3]     ÇѽÂÀç
05/13 3932
1570   ±¸±Û ¹é¸µÅ© ÀÛ¾÷ Áú¹®¿ä     wkatnxka
03/30 3367
1569   [ÆÁ] ¿ìºÐÅõ ¹Ì·¯¸µ¼­¹ö     ÇѽÂÀç
03/09 4060
1568 ºñ¹Ð±ÛÀÔ´Ï´Ù  °¨À»¸øÀâ°Ú³×¿ä¤Ì¤Ì     À×À×À×
01/15 3
1567   µ¥ºñ¾È °è¿­ ¸®´ª½º ÀÇÁ¸¼º ±úÁ³À»¶§ ÇØ°á¹ý     ÇѽÂÀç
11/27 4542
1566   È«º¸ÇÕ´Ï´Ù. ½Å»ý º¸¾ÈÄ¿¹Â´ÏƼÀÔ´Ï´Ù.     kimwoojin0952
10/26 4272
1565   ½Å±âÇÑ ÇÁ·Î±×·¡¹Ö ¾ð¾î[3]     koreal33t
09/06 4669
1564   À©µµ¿ì,¸®´ª½º¿¡¼­ ³» ip¸¦ È®ÀÎÇØ º¸ÀÚ [1]     koreal33t
09/06 3868
1563   CTF »çÀÌÆ®[1]     koreal33t
09/06 4529
1562   ÀÚ°ÝÁõ (¹®Á¦)»çÀÌÆ® [2]     koreal33t
09/06 4347
1 [2][3][4][5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org