35, 1/2 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   µÎ·ç¹¶¼ú
   [ÄÚµå°ÔÀÌÆ®2011] ÄÚµå°ÔÀÌÆ® ¹®Á¦..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_CTF&no=9 [º¹»ç]


Ãë¾àÁ¡ 100Á¡,200Á¡,300Á¡ ¹®Á¦´Â ²À ¾Ë°í½Í³×¿ä

100Á¡¹®Á¦´Â web mp3 player ·Î mp3 ÆÄÀÏÀ» ¾÷·Îµå ½ÃÅ°¸é À¥¿¡¼­ Àç»ýÇÒ ¼ö ÀÖ´Â ¹®Á¦°í¿ä..
200Á¡Àº.. À½.. ·Î±×ÀÎÇؼ­ µé¾î°¡¸é ±ÛÀÌ 6°³ Á¤µµ ÀÖ´Â ¹®Á¦¿´´Âµ¥ sql ÀÎÁ§¼Ç °°±ä Çѵ¥ °¥ÇǸ¦ ¸øÀâÀº ¹®Á¦¿´°í¿ä..
300Á¡Àº ½Ã½ºÅÛ¹®Á¦.. vuln1 µð·ºÅ丮¿¡ ÀÖ´Â vuln300À̶ó´Â ÆÄÀÏ·Î ¹¹ ¾î¶»°Ô Çؼ­ flag ÆÄÀÏ ÀÐÀ¸¸é µÉ°Å °°¾Ò´Âµ¥..
±×Àú ¾Ë¾Æ³½°Å¶ó°ï Àüü ¿É¼ÇÀ» ´Ù ³Ö¾îÁàºÁ¾ßÁö¸¸ Á¦´ë·Î ÀÛµ¿µÈ´Ù´Â°ÍÀÏ»Ó ¾Ë¾Æ³½°Ô ¾ø³×¿ä..


Àüü ¹®Á¦ Ç®ÀÌ°°Àº°Å ÀÖÀ¸¸é ¾Ë·ÁÁÖ¼¼¿ä ¤¾

  Hit : 5422     Date : 2011/03/06 10:10



    
¸Û¸Û 100, 200Àº ´Ù¸¥ ºÐµéÀÌ ¼³¸íÇØÁÖ½Ç °Í °°°í
300Àº bof ¹®Á¦Àε¥, ¿ìºÐÅõ 10.4¶ó random stack, heap, library + non-exec stack, heap
Ç®À̹ýÀº random libraryÀ̱äÇÏÁö¸¸ lld ./test ¿Í °°ÀÌ °è¼Ó ½ÇÇàÇغ¸¸é 00110000 ÁÖ¼Ò°¡
³ôÀº ºóµµ¼ö·Î ¹Ýº¹ ÃâÇöÇϰŵç. ±×°Éº¸°í 00110000 ±âÁØÀ¸·Î brute forceÇϰųª
ȤÀº Á» ´õ ³ôÀº È®·ü·Î Ç®·Á¸é fprintf °°Àº ÇÔ¼öÀÇ GOT¸¦ execl·Î µ¤´Â RTLÀ» ÇϸéµÇ»ï
¹®Á¦Ç®ÀÌ ¼¼¹Ì³ª ¶Ç ÇÒÅ×´Ï±î ¿À¼À ¤»
2011/03/07  
indra vuln100¹øÀº.. mp3 tag Á¤º¸ÂÊ¿¡ php code¸¦ »ðÀÔÇؼ­ ½ÇÇàÇÏ´Â ¹®Á¦¿´½À´Ï´Ù. phpcode ½ÇÇàÇÏ°í dbconn.php¸¦ º¸¸é root ºñ¹øÀÌ ³ª¿É´Ï´Ù.. ±×°É·Î mysqldump¸¦ ¶ß¸é ±× ¾È¿¡ vul100pw ´ø°¡.. Å×À̺íÀÌ Àִµ¥ ±× Å×À̺í¾È¿¡ Æнº¿öµå°¡ ÀÖ¾ú½À´Ï´Ù.

vuln200Àº ÀϹݰèÁ¤¿¡¼­ÀÇ SQL injectionÀº ³¬½Ã¿´°í¿ä.. Administrator °èÁ¤À¸·Î µé¾î°¡¾ß ÇÕ´Ï´Ù.. ·Î±×ÀÎ ½Ã¿¡ trim()À» ½ÇÇàÇϴ°ſ´³ª.. ±×·¡¼­ °ø¹éó¸® Çϸé ÀÎÁõ¿ìȸ°¡ µÆ°í¿ä.. Administrator °èÁ¤À¸·Î ·Î±×ÀÎÇؼ­ º¸¸é ±× ¾È¿¡ raw_data Å×À̺íÀÌ ÀÖ½À´Ï´Ù.. ±×°Ô base64 encodeµ¥ÀÌÅÍ ¿´´ø°É·Î ±â¾ïÇÏ°í.. ±×°É Ç®¸é png Å×ÀÌÅÍ°¡ ³ª¿À¸é¼­ Æнº¿öµå°¡ ³ª¿É´Ï´Ù..

¹®Á¦ Ǫ´À¶ó °í»ýÇϼ̽À´Ï´Ù..
2011/03/07  
supershop indra // ºó ÆÄÀÏ¿¡ TAG~~~ ÀÌ·¸°Ô ¾²°í mp3 ÆÄÀÏ·Î ÀúÀåÇÏ¸é ¿Ã¶ó°¡°Åµç¿ä?
°Å±â¿¡ <?php ~~ ?> ÀÌ·¸°Ô ÄÚµå ¾²°í ¿Ã·È´Âµ¥ ½ÇÇàÀº ¾È µÇ´øµ¥¿ä;;;

phpÄڵ带 ¾î¶²½ÄÀ¸·Î »ðÀÔÀ» ÇؾßÇϳª¿ä?
2011/03/07  
ÇÁ¶óÀ̵å indra´ÔÀÌ ÇϽŴë·Î Ä÷³¿À¹öÇ÷ο쳪 trim¶§¹®¿¡ ¹ß»ýÇÏ´Â Ãë¾àÁ¡ÀÌ¿ëÇؼ­ °¡ÀÔÇصµµÇ±äÇÏÁö¸¸ E-mailÆû¿¡¼­ insert sql injectionÀÌ ¹ß»ýÇÕ´Ï´Ù. ÀÌ°É·Î °¡ÀÔÇصµµÇ±¸¿ä ¤»¤µ¤»

±×¸®°í Áß¿äÇÑ°ÍÀº Administrator·Î ·Î±×ÀÎÇÑÈÄ¿¡, ÄíÅ°º¯¼öÀÎ lang¿¡¼­ sqlÀÎÁ§¼ÇÃë¾àÁ¡ÀÌ Á¸ÀçÇÕ´Ï´Ù.
lang¿¡¼­ Äõ¸®ÀÎÁ§¼ÇÀ» Çغ¸¸é ¼Ò½ºÆäÀÌÁö¿¡¼­ Äõ¸®½ÇÇà°á°ú¸¦ º¼¼öÀÖ½À´Ï´Ù. ÀÌ°ÍÀ» ÀÌ¿ëÇؼ­ µ¥ÀÌÅͺ£À̽ºÁ¤º¸¸¦ ¾ò°í , ¾òÀº Á¤º¸Áß raw_data¶ó´Â Å×À̺íÀÌÀִµ¥, 101°³ÀÇ ·¹Äڵ尡ÀÖ½À´Ï´Ù.(Àú´Â ¿©±â¼­ºÎÅÍ raw_dataÅ×À̺í À粸µÎ°í µý°ÅÇß½À´Ï´Ù.¤Ì¤Ì µÚºÎÅʹ Ǫ½ÅºÐ ¼³¸í)
´Ù base64ÀÎÄÚµùµÈ ½ºÆ®¸µÀε¥ ÀÌ Á¤º¸µéÀ» sql ÀÎÁ§¼ÇÀ» ÅëÇؼ­ ¾ò¾î¿Í¼­ ´Ù µðÄÚµùÇغ¸¸é pngÆÄÀÏ ½Ã±×´ÏÃÄ°¡ ³ª¿À´Âµ¥ Á»´õ µðÄÚµùÇÏ´Ùº¸¸é "flag : ~~~~" ÀÌ·±½ÄÀ¸·Î Ç÷¡±×¸¦ ¾òÀ»¼öÀÖ½À´Ï´Ù.

Administartor·Î ·Î±×ÀÎÇØ¾ß ÇÑ´Ù´ÂÁ¡°ú, blind sql injectionÀ» ÇÏÁö¾Ê¾Æµµ µÈ´Ù´Â Á¡À» Á¦¿ÜÇϸé Àú¾î¹ø¿¡ ÄÚµå°ÔÀÌÆ®¹®Á¦·Î ³ª¿Ô´ø webhacking.kr 2¹ø ¹®Á¦¶û °ÅÀÇ À¯»çÇÏ´Ù°í»ý°¢ÇÕ´Ï´Ù =)
2011/03/07  
ÇÁ¶óÀ̵å p.s vuln200¹®Á¦¼­¹ö »ýÁ¸È®ÀÎ =)

<a href=http://221.141.3.112/index.php target=_blank>http://221.141.3.112/index.php</a>
2011/03/07  
35   ÇØÅ·´ëȸ[2]     ¿­Á¤
05/14 3963
     [Çʵ¶] ÇØÅ· ´ëȸ Á¾·á ÈÄ¿¡¸¸ Áú¹®À» ¿Ã·ÁÁÖ¼¼¿ä. [1] ¸Û¸Û 11/28 4240
33   [ÆĵµÄÜ2011] fc4 ÀÌÈķκÎÅÍ bof ±â¹ý..[2]     µÎ·ç¹¶¼ú
01/17 5224
  [ÄÚµå°ÔÀÌÆ®2011] ÄÚµå°ÔÀÌÆ® ¹®Á¦..[5]     µÎ·ç¹¶¼ú
03/06 5421
31   ÇØÅ·´ëȸ ³ª°¥·Á°í ÇÕ´Ï´Ù.[2]     yj6393
11/05 4104
30   [ÄÚµå°ÔÀÌÆ®2011] crypto 300[2]     xzvsda
03/07 4034
29   ÇØÄ¿½ºÄð ¸ÞÀο¡ ¿Ã¶ó¿ÍÀÕ´Â ÄÚµå°ÔÀÌÆ® 2012 ¹æ¾î±â¼ú¾ÆÀ̵ð¾î ÄÁÅ×½ºÆ®¿¡ ´ëÇؼ­..Áú¹®[1]     windowhan
03/11 3734
28   [ÄÚµå°ÔÀÌÆ®2011] Æ÷·»½Ä100 Áú¹®[5]     W.H.
03/06 4477
27   [ÆĵµÄÜ2011] karma200 Áú¹® ¹× ³ÌµÎ¸®[5]     trynerr
01/20 3917
26   [ÄÚµå°ÔÀÌÆ®2011] vuln 100 ¹¹ÁÒ;;;[1]     supershop
03/07 3864
25   ÀÏ¹Ý ¼ºÀÎÀÌ Âü°¡ °¡´ÉÇÑ ÇØÅ· ´ëȸ ¸ñ·ÏÀ» À϶÷ÇÒ¼ö ÀÖ´Â »çÀÌÆ®°¡ ÀÖ³ª¿ë?[2]     sungwoodat
08/08 4094
24   ºñ¹Ð¹øÈ£¸¦ hash°ªÀ¸·Î ÀúÀåÇÏ¸é ¾ÈµÇ³ª¿ä?[3]     securityjeong
03/03 3472
23   ÇØÅ·´ëȸ...[5]     rudwo4685
06/17 4705
22   Àß ¸ð¸£´Âµ¥ ÇØÅ·´ëȸ Âü¿©Çصµ µÇ·Á³ª¿ä?[1]     leorld
07/19 3920
21   ÇØÅ·´ëȸ ¹®Á¦[1]     ks610126
07/17 3894
20   [ÆĵµÄÜ2011] karma100 °ú goe200 Áú¹®ÀÔ´Ï´Ù.[6]     I'm Not GoN
01/17 4544
19   ÇØÅ·´ëȸ µ¶ÇÐ °¡´ÉÇÑ°¡¿ä?[2]     herjun9903
01/19 3007
18   û¼Ò³â ÇØÅ·´ëȸ     h@cking2013
12/24 3788
17   Á¤º¸¿Ã¸²ÇǾƵå&¾Ë°í¸®Áò¿¡ ´ëÇØ Áú¹®Çմϴ٤ФФÐ[4]     h@cking2013
03/08 4546
16   ¼øõÇâ´ë ÇØÅ·´ëȸ (Áß,°í±³»ý)[1]     dnem142
07/15 4052
1 [2]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org