1581, 11/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   »ç¿ëÁß
   http://www.cyworld.com/csy_lovely
   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (8)

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1835 [º¹»ç]


1) È®ÀåÀÚ ÇÊÅ͸µ web.php(À¥ ¼¿)ÆÄÀÏÀ» ¾÷·Îµå ÇÒ ¼ö ¾ø´Ù.
2) htaccess, web.zip À¥¼¿ ¾÷·Îµå ¼º°ø
3) À¥ ½© ½ÇÇà(web.zip Ŭ¸¯ÇÏ¸é ¹Ù·Î ½ÇÇà)

ÁÖ¿ä ½ÇÇà ¸í·É¾î (À¥ ½© ¸¶´Ù ±â´ÉÀÌ ´Ù¸§)

¸ñ·Ïº¸±â :ls
»óÀ§ ¸ñ·Ï º¸±â : ls ../ ../
ÆÄÀÏ »èÁ¦ : rm -rf[Áö¿ï ÆÄÀϸí]
À¥ ÆäÀÌÁö ´Ù¿î : tar -cvf c.tar

2.File download Vulnerability
´Ù¿î·Îµå ÆÄÀÏÀÇ À§Ä¡¿¡ Á¦ÇÑ Á¶°ÇÀ¸ ¤©ºÎ¿©ÇÏÁö ¾Ê¾Æ ÁöÁ¤µÈ ÆÄÀÏ ÀÌ¿ÜÀÇ À§Ä¡¿¡ ÀÖ´Â ÆÄÀϵ鿡 Á¢±ÙÇϰųª ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡À» ¸»ÇÑ´Ù. °Ô½ÃÆÇ µî¿¡ ÀúÀåµÈ ÀÚ·á¿¡ ´ëÇØ ´Ù¿î·Îµå ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ¿© ´Ù¿î·Îµå ±â´ÉÀ» Á¦°øÇϸ鼭, ´ë»ó ÀÚ·á ÆÄÀÏÀÇ À§Ä¡ ÁöÁ¤¿¡ Á¦ÇÑ Á¶°ÇÀ» ºÎ¿©ÇÏÁö ¾Ê¾ÒÀ» °æ¿ì URL°£ÀÇ ´Ù¿î·Îµå ½ºÅ©¸³Æ®ÀÇ Àμö°ª¿¡ '../' ¹®ÀÚ¿­ µîÀ» ÀÔ·ÂÇÏ¿© ½Ã½ºÅÛ µð·ºÅ丮 µî¿¡ ÀÖ´Â /etc/passwd ¿Í °°Àº ºñ°ø°³ ÀÚ·áµéÀÌ À¯ÃâµÉ ¼ö ÀÖ´Ù.
ƯÈ÷, ¸®´ª½º ¹× À¯´Ð½º °è¿­ÀÇ À¥ ¼­¹ö¿¡ °¢º°È÷ ÁÖÀÇ°¡ ÇÊ¿äÇÏ´Ù. ¿¹¸¦ µé¾î ÆÄÀÏ ´Ù¿î·Îµå ½Ã ÁÖ¼Ò Ã¢¿¡ ¡é¿Í °°ÀÌ ÀÔ·Â
http://servername.com/data/download.php?path=upfiles&filename=½Åû¼­.doc
Æнº¿öµå(password) ÆÄÀÏÀÇ ÇØÅ·À» ½ÃµµÇÑ´Ù.
http://servername.com/date/download.php?path../../../../../../../../../../../etc&filename=passwd
(download.php cgiÀÇ path º¯¼ö¿¡ À§Ä¡¸¦ ÁöÁ¤ÇÏ°í filename º¯¼ö¸¦ ÀÌ¿ëÇØ passwd ÆÄÀÏ ´Ù¿î·Îµå)
http://servername.com/data/download.php?path=upfiles&filename=../../../../../../../../../../../etc/passwd
(download.php cgi ÀÇ filenameº¯¼ö¿¡¼­ °æ·Î¸¦ µû¶ó µé¾î°¡ passwd ÆÄÀÏÀ» ´Ù¿î·Îµå ¹ÞÀ½)

  Hit : 8186     Date : 2011/08/03 02:12



    
ghj4890 ÁÁ³×¿©
À¯ÀÍÇÔ
2011/08/04  
»ç¿ëÁß °¨»çÇÕ´Ï´Ù~ 2011/08/06  
salis °¨»çÇÕ´Ï´Ù. 2011/08/18  
1381   Áö±Ý±îÁö ÇØÅ·´çÇÑ »çÀÌÆ® ¸ðÀ½[9]     Nuker
12/28 9933
1380   ÃÖ´ëÈ­[1]     goldcsj
08/13 6697
1379   ÁÖ¼Ò¤»(³×Æ®¿öÅ©)[5]     sdc04303
05/13 6271
1378   Á¤´ä ¤¾¤¾¤¾¤¾[9]     chenkim4
08/28 7578
1377   Á¤¸».....Áö¹æÀº[11]     intmain1202
10/25 6106
1376   Á¤º¸Ã³¸®±â´É»ç ¼ÒÇÁÆ®¿þ¾î °øÇÐ ¸ðÀ½Áý ÀÔ´Ï´Ù.[1]     Ä«¸£ÆäÀÌ
05/08 8110
1375   Á¤º¸Åë½Å ÀÎÅÍ³Ý ¿ë¾î..(¸ð¸£½Ã´Â ºÐµé¸¸..+Âü°í..)[19]     H.R.T
12/29 16882
1374   Á¤º¸°øÀ¯ÇÏ´Â ´ÜÅå¹æÀÕÀ¸¸é ºÎŹÁ»¿ä     lcd7132
04/26 5242
1373   Á¤º¸°øÀ¯ÇÏ´Â ´ÜÅå¹æÀÕÀ¸¸é ºÎŹÁ»¿ä     lcd7132
04/26 5276
1372   Á¤º¸º¸¾È Àü¹®°¡(?)¿¡ ´ëÇؼ­..;;[5]     H.R.T
12/15 7840
1371   Á¤º¸º¸¾ÈÀü¹®°¡ µÇ´Âµ¥ ¼ø¼­[1]     phan_tom2
10/01 7623
1370   Á¤º¸º¸¾ÈÀü¹®°¡(ÇØÄ¿)ÀÇ Á¾·ù..;;[15]     H.R.T
12/29 11471
1369   Á¤º¸º¸¾È¾÷üÀÚ µÉ·Á¸é¾î¶»°Ô ÇؾßÇϳª¿ä[1]     hacs98
04/21 7378
1368   À¥ ÇØÅ·[9]     phan_tom0
12/02 9695
1367   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (1)[7]     »ç¿ëÁß
08/03 8677
1366   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (2)[1]     »ç¿ëÁß
08/03 8720
1365   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (3)[1]     »ç¿ëÁß
08/03 7758
1364   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (6)[1]     »ç¿ëÁß
08/03 7792
1363   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (7)[1]     »ç¿ëÁß
08/03 8721
  À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (8)[3]     »ç¿ëÁß
08/03 8185
[1].. 11 [12][13][14][15][16][17][18][19][20]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org