1581, 4/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   »ç¿ëÁß
   http://www.cyworld.com/csy_lovely
   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (8)

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1835 [º¹»ç]


1) È®ÀåÀÚ ÇÊÅ͸µ web.php(À¥ ¼¿)ÆÄÀÏÀ» ¾÷·Îµå ÇÒ ¼ö ¾ø´Ù.
2) htaccess, web.zip À¥¼¿ ¾÷·Îµå ¼º°ø
3) À¥ ½© ½ÇÇà(web.zip Ŭ¸¯ÇÏ¸é ¹Ù·Î ½ÇÇà)

ÁÖ¿ä ½ÇÇà ¸í·É¾î (À¥ ½© ¸¶´Ù ±â´ÉÀÌ ´Ù¸§)

¸ñ·Ïº¸±â :ls
»óÀ§ ¸ñ·Ï º¸±â : ls ../ ../
ÆÄÀÏ »èÁ¦ : rm -rf[Áö¿ï ÆÄÀϸí]
À¥ ÆäÀÌÁö ´Ù¿î : tar -cvf c.tar

2.File download Vulnerability
´Ù¿î·Îµå ÆÄÀÏÀÇ À§Ä¡¿¡ Á¦ÇÑ Á¶°ÇÀ¸ ¤©ºÎ¿©ÇÏÁö ¾Ê¾Æ ÁöÁ¤µÈ ÆÄÀÏ ÀÌ¿ÜÀÇ À§Ä¡¿¡ ÀÖ´Â ÆÄÀϵ鿡 Á¢±ÙÇϰųª ´Ù¿î·Îµå ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡À» ¸»ÇÑ´Ù. °Ô½ÃÆÇ µî¿¡ ÀúÀåµÈ ÀÚ·á¿¡ ´ëÇØ ´Ù¿î·Îµå ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ¿© ´Ù¿î·Îµå ±â´ÉÀ» Á¦°øÇϸ鼭, ´ë»ó ÀÚ·á ÆÄÀÏÀÇ À§Ä¡ ÁöÁ¤¿¡ Á¦ÇÑ Á¶°ÇÀ» ºÎ¿©ÇÏÁö ¾Ê¾ÒÀ» °æ¿ì URL°£ÀÇ ´Ù¿î·Îµå ½ºÅ©¸³Æ®ÀÇ Àμö°ª¿¡ '../' ¹®ÀÚ¿­ µîÀ» ÀÔ·ÂÇÏ¿© ½Ã½ºÅÛ µð·ºÅ丮 µî¿¡ ÀÖ´Â /etc/passwd ¿Í °°Àº ºñ°ø°³ ÀÚ·áµéÀÌ À¯ÃâµÉ ¼ö ÀÖ´Ù.
ƯÈ÷, ¸®´ª½º ¹× À¯´Ð½º °è¿­ÀÇ À¥ ¼­¹ö¿¡ °¢º°È÷ ÁÖÀÇ°¡ ÇÊ¿äÇÏ´Ù. ¿¹¸¦ µé¾î ÆÄÀÏ ´Ù¿î·Îµå ½Ã ÁÖ¼Ò Ã¢¿¡ ¡é¿Í °°ÀÌ ÀÔ·Â
http://servername.com/data/download.php?path=upfiles&filename=½Åû¼­.doc
Æнº¿öµå(password) ÆÄÀÏÀÇ ÇØÅ·À» ½ÃµµÇÑ´Ù.
http://servername.com/date/download.php?path../../../../../../../../../../../etc&filename=passwd
(download.php cgiÀÇ path º¯¼ö¿¡ À§Ä¡¸¦ ÁöÁ¤ÇÏ°í filename º¯¼ö¸¦ ÀÌ¿ëÇØ passwd ÆÄÀÏ ´Ù¿î·Îµå)
http://servername.com/data/download.php?path=upfiles&filename=../../../../../../../../../../../etc/passwd
(download.php cgi ÀÇ filenameº¯¼ö¿¡¼­ °æ·Î¸¦ µû¶ó µé¾î°¡ passwd ÆÄÀÏÀ» ´Ù¿î·Îµå ¹ÞÀ½)

  Hit : 8101     Date : 2011/08/03 02:12



    
ghj4890 ÁÁ³×¿©
À¯ÀÍÇÔ
2011/08/04  
»ç¿ëÁß °¨»çÇÕ´Ï´Ù~ 2011/08/06  
salis °¨»çÇÕ´Ï´Ù. 2011/08/18  
1521   ¸®´ª½º ¸í·É¾î ¸¶½ºÅÍ 4[13]     ¼ÒÀ¯
09/05 16493
1520   ³×Æ®¿öÅ© °³³ä ÈÖ¾îÀâ±â 7[8]     ¼ÒÀ¯
09/16 12102
1519   ÁÁÀº ºñ¹Ð¹øÈ£¶õ???[24]     ¼ÒÀ¯
09/04 19370
1518   ¸®´ª½º ¸í·É¾î ¸¶½ºÅÍ 3[13]     ¼ÒÀ¯
09/04 16880
1517   À¯Ä¡¿ø ¸¸È­ Å©°Ôº¸±â[11]     ¼ÒÀ¯
09/03 18391
1516   ¸®´ª½º ¸í·É¾î ¸¶½ºÅÍ 1[77]     ¼ÒÀ¯
09/02 34780
1515   ¸®´ª½º ¸í·É¾î ¸¶½ºÅÍ 2[26]     ¼ÒÀ¯
09/03 21413
1514   ¹öÆÛ ¿À¹ö Ç÷ο쿡 °üÇؼ­(¼ÓĪ BOF)[1]     »ç¿ù
09/11 9027
  À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (8)[3]     »ç¿ëÁß
08/03 8100
1512   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (7)[1]     »ç¿ëÁß
08/03 8634
1511   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (6)[1]     »ç¿ëÁß
08/03 7730
1510   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (5)[2]     »ç¿ëÁß
08/03 8909
1509   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (4)      »ç¿ëÁß
08/03 8165
1508   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (3)[1]     »ç¿ëÁß
08/03 7696
1507   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (2)[1]     »ç¿ëÁß
08/03 8652
1506   À¥ ÇØÅ·¿¡´ëÇؼ­ ¾Ë¾Æº¸ÀÚ (1)[7]     »ç¿ëÁß
08/03 8595
1505   ¸®´ª½º(9) ¸®´ª½º ¸í·É¾î 1~8     »ç¿ëÁß
08/02 8527
1504   < ¸®´ª½º ÂüÁ¶ °¡À̵å > 4     »ç¿ëÁß
08/02 7575
1503   < ¸®´ª½º ÂüÁ¶ °¡À̵å > 3      »ç¿ëÁß
08/02 7541
1502   < ¸®´ª½º ÂüÁ¶ °¡À̵å > 2     »ç¿ëÁß
08/02 7356
[1][2][3] 4 [5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org