214, 1/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bigshott
   ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ Áú¹® ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=11 [º¹»ç]


À¥ÇØÅ· °ü·Ã °øºÎ ÇÏ´ÂÁßÀä~

¶Ç ¾î·Á¿î ºÎºÐÀÌ »ý°Ü¼­ Áú¹® µå¸³´Ï´Ù. ^^

php ¼Ò½º±¸¿ä~

¾Æ·¡ ó·³ ÆÄÀÏ ¾÷·Îµå¸¦ ÇÒ ¼ö ÀÖ½À´Ï´Ù.


<form method=post enctype="multipart/form-data" action=index.php>
<input type=file name=upfile><input type=submit>

ÆÄÀÏ ¾÷·Îµå¸¦ Çؼ­ ¶Ç ´Ù¸¥ phpÆÄÀÏ ¼Ò½º¸¦ ÀÐÀ» ¼ö°¡ ÀÖÀ»±î¿ä?

°ü·Ã Ãë¾àÁ¡À» ¾Æ¹«¸® ã¾ÆºÁµµ ¾ø³×¿ä~

aaa;../../test/index.php ¿ä·±½ÄÀ¸·Îµµ Çغôµ¥ Ãâ·ÂÀÌ µÇÁö ¾Ê½À´Ï´Ù.

aaa;cp ./test/index.php ./test/index.txt ¿ä·±°Íµµ Çغ¸±¸¿ä ¤Ì¤Ð

°í¼ö´Ôµé Á¶¾ð Á» ºÎŹµå¸³´Ï´Ù.

¼ö°íÇϼ¼¿ä~

  Hit : 5015     Date : 2010/12/25 12:44



    
º°ºûÀ»´ã¾Æ À¥ ÇØÅ·À̳ª httpd¸¦ Àß ¾Æ´Â °ÍÀº ¾Æ´ÏÁö¸¸... ÀÏ´Ü Á¦ »ý°¢À» ¸»¾¸µå·Áº¼°Ô¿ä.
¸ÕÀú ÆÄÀÏÀÌ ¾÷·ÎµåµÈ °÷ÀÌ /home/httpuser/public_html/test.php·Î ¿Ã¶ó°¬Áö¸¸ index´Â ÀüÇô ´Ù¸¥ °÷¿¡ ÀÖ´Ù´Â °¡Á¤ÇսôÙ. °èÁ¤Àº httpuserÀ̱¸¿ä.

±×·¸´Ù¸é index.php¿¡¼­ test.php·Î Á¢±ÙÀ» ÇÑ´Ù°í ÇÏ¸é °æ·Î ÀÚü°¡ Ʋ·Á¼­ ./¿Í °°Àº ÀÚ±â ÀÚ½ÅÀÇ À§Ä¡¿¡¼­ Á¢±ÙÀº Èûµé°Ì´Ï´Ù.

ÀÌ ¶§ Àú °÷¿¡ Á¢±ÙÇÏ½Ç ¶§´Â Á¦ »ý°¢¿¡´Â ÁÖ¼ÒâÀ» ÀÌ¿ëÇÑ Á¢±Ùµµ Çѹø »ý°¢ÇØ º¸½Ç¸¸ ÇÏ´Ù°í »ý°¢ÇÕ´Ï´Ù.
<a href=http://www.domain.com/../../../../../../../../../../../../../../../../../home/httpuser/public_html/test.php target=_blank>http://www.domain.com/../../../../../../../../../../../../../../../../../home/httpuser/public_html/test.php</a>
2010/12/25  
bigshott ¾Æ~ ±×·¸±º¿ä.
´äº¯ Á¤¸» °¨»çµå¸³´Ï´Ù. µµ¿ò ¸¹ÀÌ µÇ¾ú½À´Ï´Ù.
Áñ°Å¿î ¼ºÅºÀý º¸³»¼¼¿ä ^^
2010/12/25  
214   CloudFlare ¾²´Â »çÀÌÆ®´Â ÇØÅ·Çϱâ Èûµé±î¿ä?[3]     sogreat
03/21 202
213   À¥ÇØÅ· °ü·ÃÇÏ¿© Áú¹®µå¸³´Ï´Ù[5]     solo20
05/21 2354
212   À¥ÇØÅ· ÀÔ¹® Ã¥ÃßõÇØÁÖ¼¼¿ä     kjwp1
02/24 2503
211   À̹ÌÁö¾È¿¡ ¸®´ÙÀÌ·ºÆ® ¼Ò½º(¾Ç¿ë¸ñÀûX)[2]     tjdgus1515
12/06 4628
210   ¾ÆÆÄÄ¡ php mysql ¿¬µ¿°ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     Ä¿¼¼¾î
10/19 3588
209   sql injection ¹æ¾î ÄÚµå[2]     europa8340
10/04 2811
208   À¥ sqlmap Áß¿¡[1]     europa8340
07/26 2257
207   À¥ ÇØ Å· °¡´ÉÇÏ´Â[1]     custom890
12/31 2886
206   À¥ ÇØÅ· ÀÚ½ÅÀÖÀ¸½Å ºÐµé ²À ºÁÁÖ¼¼¿ä     bird999
12/05 2965
205   À¥ ÇØÅ· Çϴµ¥ À¥ °³¹ßµµ ÇÒ ÁÙ ¾Ë¾Æ¾ß Çϳª¿ä?[1]     unmask
10/25 2788
204   ÇØÅ·¸Àº¸±â(¼­Àû) ¾ÆÆÄÄ¡ÇÁ·Î±×·¥ Áú¹®ÀÔ´Ï´Ù[1]     Ä¿¼¼¾î
09/29 2646
203   À¥ÇØÅ· ÀÔ¹®ÇÒ·Á°íÇÕ´Ï´Ù. Á¶¾ð¹×°ú¿ÜÇØÁֽǽº½Â´Ô ±¸ÇÕ´Ï´õ[3]     edustars
09/26 2871
202   417 error     wiwiwi79
08/15 2520
201   ȨÆäÀÌÁö µðµµ½º ¿ø¸®?[1]     tbxmaos
02/12 2655
200   ¾ÆÆÄÄ¡ ¼³Á¤Áß ¿À·ù[2]     eunjong147
02/06 8389
199   Ä®¸®¸®´ª½º dvwa ¼³Ä¡°úÁ¤Áß ¿À·ù[2]     wnsdud5534
01/23 3415
198   À¥ ÇØÅ· Áú¹®ÀÔ´Ï´Ù.     dsgoidsog
11/26 2763
197   XSS <> ġȯ ¿ìȸ°¡ °¡´ÉÇÑ°¡¿ä?[2]     drrobot333
11/19 3608
196   PHP¿¡¼­ À̸ÞÀÏ Àü¼ÛÇÒ¶§ °¡·Îç ¼ö ÀÖ³ª¿ä?[9]     drrobot333
11/16 2577
195   À¥ÇØÅ· Áú¹®[1]     ericseo16
10/14 2824
1 [2][3][4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org