ÇÁ·Î±×·¡¹Ö

 3198, 1/160 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   U_SoRang
   http://root@root]# rm -rf /
   [PHP] <¼¼¼Ç À¯Áö> ¿¡ ´ëÇÑ Áú¹®ÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=2986 [º¹»ç]


Á¦°¡ Áö±Ý php¸¦ °øºÎÇϰí Àִµ¥¿ä..
(¾îÇÃÁ¦ÀÛ °ü·ÃÀÔ´Ï´Ù.)

¼¼¼Ç¿¡¼­ ¸·Èü´Ï´Ù..

¼¼¼ÇÀ» µî·ÏÇϰųª ÇÏ¸é ÆäÀÌÁö°¡ ³Ñ¾î°¥ ¶§¸¶´Ù °è¼Ó À̾îÁ®¾ß Çϴµ¥, ±×·¯Áú ¸øÇÕ´Ï´Ù.

session_register·Î µî·ÏÀ» ÇØÁ൵, ±×³É $_SESSION['INPUT'] ÀÌ·±½ÄÀ¸·Î Á൵,
½º¸¶Æ®Æù¿¡¼± ¾ÈµÇ´õ±º¿ä..


ºê¶ó¿ìÁ® »óÀÇ ¹®Á¦Àΰǰ¡ ½Í¾î¼­ PC¿¡¼± ÆÄÆøÀ» ±ò°í ÇØº¸¾Ò°í, (PC¿¡¼± Å©·ÒÀÌ ±âº»)
½º¸¶Æ®Æù¿¡¼± ÆÄÆø(±âº»), ¿ÀÆä¶ó, µ¹ÇÉ µîµî ¿©·¯ ºê¶ó¿ìÁ®¸¦ ±ò°í ½ÃÇèÇØ º¸¾Ò½À´Ï´Ù.

ÇÏÁö¸¸ ¼¼¼ÇÀÌ À¯Áö°¡ µÇ´Â °ÍÀº PCÀÇ Å©·Ò »ÓÀÌ´õ±º¿ä..

ÀÎÅͳÝÀ¸·Î µÚÁö¸é ³ª¿À´Â ¹æ¹ýÀ̶õ ¹æ¹ýÀº ´Ù ½áº¸¾Ò½À´Ï´Ù¸¸, ¿ª½Ã³ª... ´õ±º¿ä...
(php.ini ¼³Á¤µµ ÇØº¸¾Ò½À´Ï´Ù. ¿ÀÅä¼¼¼Çµµ ÇØº¸¾Ò±¸¿ä..)

ÀÌ·¸°Ô º¸¸é, °á±¹ ºê¶ó¿ìÁ® ¹®Á¦¶ó°í »ý°¢ÇÒ ¼öµµ Àִµ¥... ´Ù¸¥ ¹®Á¦°¡ ÀÖÀ»·±Áö¿ä?

Å©·Ò¸¸ µÇ°í, ³ª¸ÓÁö´Â ¾ÈµÇ´Â °æ¿ì´Â ¹¹¶ó°í ¼³¸íÀ» ÇØ¾ß Çϳª¿ä?
(¾Èµå·ÎÀ̵å¿ë Å©·ÒÀÌ Ã£¾Æº¸´Ï ¾ø´Â°Í °°¾Æ¼­ ´ä´äÇϱ⸸ ÇÕ´Ï´Ù...)



[1.php]
<html>
<head>
<title>1</title>
</head>

<body>
<form name="FORM_1" method="POST" action="2.php">
<input type="text" class="Input_TEXT1" tabindex="1" name="ID" value="asdfg"/>
<input type="submit" value="OK"/>
</form>
</body>
</html>

[2.php]
<?
$INPUT = $_POST['ID'];
session_register("INPUT");
//$_SESSION['INPUT'] = $_POST['ID'];
//print $_SESSION['INPUT'];
print $INPUT;
?>
<form name="FORM_1" method="POST" action="3.php">
<input type="hidden" name="ID" value="<?=$INPUT?>">
<input type="submit" value="OK"/>
</form>

[3.php]
<?
print $INPUT;
?>
<form name="FORM_1" method="POST" action="1.php">
<input type="submit" value="return 1.php"/>
</form>


Á¤¸» °£´ÜÇÑ ¼Ò½ºÀÔ´Ï´Ù.

ÀÌ°Ô µÇ¾ßÁö ·Î±×ÀÎ ¼¼¼Çµµ µÇ´Â°Çµ¥, °è¼Ó ¸·Çô¹ö¸®´Ï Á¤¸» ¿ï°í ½Í½À´Ï´Ù.

È¥ÀÚ¼­ ²þ²þ°Å¸®´Ù ÀÌ·¸°Ô ±Û ³²±é´Ï´Ù...

Á¶¾ð ºÎʵ右´Ï´Ù..

  Hit : 6673     Date : 2011/05/07 01:09



    
pwn3r session_register ÇÔ¼ö´Â php¹öÁ¯ ¿Ã¶ó°¡¸é¼­ »ç¿ëÇÏÁö ¾Ê±¸¿ä ¤¾

óÀ½¿¡ session_start() ÇÔ¼ö¸¦ ½ÇÇàÇØ ÁÖ¾î¾ß ±×ÆäÀÌÁö¿¡¼­ ¼¼¼ÇÆÄÀÏÀ» ¸¸Áú¼öÀÖ½À´Ï´Ù.
(session_start() ÇÔ¼ö ¾Õ¿¡´Â @¸¦ ºÙ¿©ÁÖ½Ã´Â°Ô ÁÁ½À´Ï´Ù.)

±×´ÙÀ½ ¼¼¼Ç º¯¼ö¸¦ »ç¿ëÇϽǶ§´Â ±×³É SESSION ½´ÆÛ±Û·Î¹ú ¹è¿­À» »ç¿ëÇÏ½Ã¸é µË´Ï´Ù.
$_SESSION['id'] = "pwn3r";
ó·³ »ç¿ëÇÏ½Ã¸é ¼¼¼ÇÆÄÀÏ¿¡ ÀúÀåÀ̵Ǽ­ »ç¿ëÇϽǼöÀÖ½À´Ï´Ù.
2011/05/07  
asdwho session_start() ÇÔ¼ö ¾øÀÌ ±Û¾²½Å ºÐ ó·³ Å©·ÒÀº ¿Ö µÇ´Â°É±î¿ä? 2011/05/08  
U_SoRang ´äº¯ÇØÁֽŠµÎ ºÐ.. Áø½ÉÀ¸·Î °¨»çµå¸³´Ï´Ù..

Á¶¾ðÀ» Âü°íÇÏ¿© ´õ¿í ¿¬±¸ÇØ º¸µµ·Ï ÇϰڽÀ´Ï´Ù.
2011/05/08  
prosper ¿ì¼± À¥»ó¿¡¼­ À§ÀÇ phpÄڵ尡 Á¤»óÀûÀ¸·Î µÇ´ÂÁö È®ÀÎÇØº¸½Ã°í..

ie/ff µîÀ¸·Î POSTµ¥ÀÌÅͰ¡ ¼¼¼ÇÀ¸·Î À¯ÁöµÇ´ÂÁö (Á¤È®È÷´Â ¼¼¼ÇÄíŰ) Ŭ¶óÀÌ¾ðÆ®¿¡¼­
¼¼¼ÇŰÀÇ Äí۰¡ ¹Þ¾ÆÁö´ÂÁö...

¾Èµå·ÎÀÌµå ¾Û¿¡ÀÇ ¼¼¼Ç 󸮹æ¹ýÀº Á¶±Ý Ʋ¸³´Ï´Ù.

http ÇÏÀ§ Ŭ·¡½º¿Í android ÇÏÀ§ Ŭ·¡½º°¡ Ʋ¸³´Ï´Ù.

°¡±ÞÀû http.response, hppt.request, http.cookie µîÀÇ ¾Èµå·ÎÀÌµå °³¹ßÀÚ »çÀÌÆ®¿¡ ¸®ÆÛ·±½º Âü°íÇÏ´Â°Ô ÁÁ½À´Ï´Ù.

=> http °´Ã¼´Â Àü¿ªÀ¸·Î »ý¼ºÇؼ­ connect°¡ ÀϾ ½ÃÁ¡ ÀÌÈÄ responce¿¡¼­ ÇØ´õ Áß Äí۸¦ cookiestore ¿¡ ÀúÀåÇÏ°í ±×°ÍÀ» °è¼Ó ¹Ýº¹ÀûÀ¸·Î request ½Ã Çì´õ¿¡ Æ÷ÇÔÇÏ´Â ½ÄÀ¸·Î ¼¼¼ÇÀ» À¯Áö ÇÏ¿©¾ß ÇÕ´Ï´Ù.
=> http°´Ã¼ »ý¼ºÀÌÈÄ ¼Ò¸ê½ÃŰÁö ¾Ê°í ¾Û Á¾·á±îÁö ÇϳªÀÇ °´Ã¼·Î ¿¬°áÀ¯Áö ½ÃÄÑ¾ß Çϴ°̴ϴÙ.

¼³¸íÀ» À߸øÇؼ­ ÀÌÇØ°¡ ‰ç´ÂÁö ¸ð¸£°Ú³×¿ä.
2011/05/09  
U_SoRang >> prosper ´Ô


ÀúÇÑÅ× ±Û Àû¾îÁֽŠ°Í¸¸À¸·Îµµ Å« µµ¿òÀÌ µÇ¾ú½À´Ï´Ù.

´öºÐ¿¡ Àß ÇØ°áÀÌ µÈ °Í °°³×¿ä.. °¨»çÇÕ´Ï´Ù.
2011/05/14