22018, 1/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   qw3709
   20.jpg (33.1 KB), Download : 68     [¿À¸¥ÂÊ ¹öư ´­·¯ ´Ù¿î ¹Þ±â]
   À¥ÇØÅ·.kr 51¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=35885 [º¹»ç]



if($_POST[id] && $_POST[pw])
{
$input_id=$_POST[id];
$input_pw=md5($_POST[pw],true);

$q=@mysql_fetch_array(mysql_query("select id from challenge_51_admin where id='$input_id' and pw='$input_pw'"));

if($q[id]=="admin")
{
@solve(51,250);
}

if($q[id]!="admin") echo("<center><font color=green><h1>Wrong</h1></font></center>");


}



¹®Á¦ ¼Ò½ºÀÔ´Ï´Ù.

¹®Á¦´Â
id:admin
pw:******
ÀÌ·±½ÄÀÔ´Ï´Ù.

¹ÙÀ̳ʸ®ÇüÅ·Πmd5¸¦ ÀÌ¿ëÇØ ÀÎÄÚµùÇÑÈÄ¿¡
Äõ¸®¸¦ º¸³» adminÀǰª°ú °°À¸¸é Á¤´äÀ̶ó´Â°Í±îÁö´Â ¾Ë°Ù´Âµ¥.
md5¸¦ ¾î¶»°Ô ó¸®ÇؾßÇÒÁö ¸ô¶ó¼­ ±¸±Û¸µÀ» ÇØº¸´Ï...

´äÀ» ã´Â Äڵ尡 ÀúÄڵ尡 ³ª¿À´õ±º¿ä..
ÇØ¼®Àº °¡´ÉÇѵ¥

¹®Á¦´Â ¿Ö ¼ýÀÚºÎÅÍ Ã£´ÂÁö À߸𸣰ٳ׿ä...
ºñ¹Ð¹øÈ£°¡ ¹®ÀÚ°¡µé¾î°¥¼öµµÀÖÁö¾Ê³ª¿ä

±×¸®°í ¿¹¸¦ µé¾î
sql¿¡¼­ idÄ®·³¿¡ aaa,bbb,ccc °¡ÀÖ´Ù°íÄ¡¸é
select id from table where id='aaa'=(°ÅÁþ°ª) À»Çϸé
aaa¸¦ Á¦¿ÜÇÑ °ªÀÌ ³ª¿Â´Ù´Â°ÍÀÌ ÀÌÇØ°¡µÇ´Âµ¥

´äÀ» ã´ÂÄڵ忡¼­ ¿Ö '='ÀÌ Æ÷ÇÔµÇÀÖ´Â ´äÀ» ã´ÂÁö ÀÌÇØµµÁ»¾ÈµÇ±¸¿ä...
±×³É ÃÑüÀû³­±¹ÀÔ´Ï´Ù..

  Hit : 9010     Date : 2018/01/18 11:45



    
ReverseLookUp ¹®Á¦¸¦ ¹«ÀÛÁ¤ Ç®±âÀü¿¡ ,
¹®Á¦ÀÇ Àǵµ¸¦ º¸¸é md5 Ãë¾àÁ¡ÀÓÀ» ¾Ë ¼ö Àֳ׿ä.
°ü·Ã Ãë¾àÁ¡ °øºÎ¸¦ ¸ÕÀú ÇÏ½Ã´Â°Ô ¸Â´Â °Í °°½À´Ï´Ù.
2018/01/19  
yelang123 ÇØ´ç ¹®Á¦´Â phpÀÇ md5ÇÔ¼öÀÇ µÎ¹øÂ° ÀÎÀÚÀÎ raw_output ÀÇ °ªÀÌ true·Î ¼ÂÆÃµÇ¾î md5 ÇÔ¼öÀÇ return°ªÀÌ binary ÇüÅ·ΠÃâ·ÂÇÒ ¶§ ¹ß»ýÇÏ´Â Ãë¾àÁ¡ ÀÔ´Ï´Ù. ÀÌÇØÇϱ⠾î·Á¿ì½Ã´Ù¸é php¿¡¼­ md5('aa'); ¿Í md5('aa',true)ÀÇ °ªÀ» Ãâ·ÂÇÏ¿© ºñ±³Çغ¸½Ã¸é µÉ °Í °°½À´Ï´Ù ^^
¶Ç mysql¿¡¼­ °ªÀÌ ÂüÀ̵Ǵ ÀÌÀ¯´Â select id from challenge_51_admin where id='admin' and pw=''='' ·Î Äõ¸®°¡ ½ÇÇàµÇ±â ¶§¹®¿¡ ÇØ´ç SQLÀÌ ÂüÀÌµÇ¾î ·Î±×ÀÎÀÌ µÇ´Â°ÍÀ» ¾Ë ¼ö ÀÖ½À´Ï´Ù. ±×¸®°í ¸¶Áö¸·À¸·Î ¿Ö ¼ýÀÚ·Î brute force Áú¹®Àº php¸¦ Á» ´õ °øºÎÇÏ½Ã¸é ¾Ë µí ÇÕ´Ï´Ù ¤¾¤¾
2018/01/19  
qw3709 ´äº¯°¨»çÇÕ´Ï´ç 2018/01/24