214, 1/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bigshott
   php ¿ìȸ Áú¹® µå¸³´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=3 [º¹»ç]


¾È³çÇϼ¼¿ä~

sql ÀÎÁ§¼Ç °øºÎÇÏ´Ù°¡ ±Ã±ÝÇÑ ºÎºÐÀÌ À־ ÀÌ·¸°Ô Áú¹®µå¸³´Ï´Ù. ^^

¿äÁò °øºÎ ÇÏ´Ù º¸´Ï ¿ö³« ÇãÁ¢Çؼ­ ÀÚÁÖ Áú¹®µå¸®°Ô µÇ³×¿ä ^^

phpÇÔ¼ö¿¡ º¸¸é eregi ÇÔ¼ö·Î ÇÊÅ͸µÀ» °É´øµ¥¿ä~

if(eregi("--|2|50|\+|substring|from|infor|mation|lv|%20|=|!|<>|sysM|and|or|table|column",$ck)) exit("Access Denied!");

À§¿Í °°ÀÌ ÇÊÅ͸µÀÌ °É·Á ÀÖ½À´Ï´Ù.

?val=1 union select 2  

¿ä·¸°Ô ÀÔ·ÂÇؼ­ °ªÀ» ³Ö¾î¾ß µÇ´Âµ¥¿ä~

2°¡ eregi ÇÔ¼ö¿¡ °É·Á¼­ ³Ñ¾î°¡Áú ¾Ê½À´Ï´Ù.

url encode, hex µîµî ´Ù ÇغÁµµ °É¸®³×¿ä~

¿ìȸ ÇÒ¼ö ÀÖ´Â ÁÁÀº ¹æ¹ý ¾øÀ»±î¿ä?

°í¼ö´Ôµé Á¶¾ð Á» ºÎŹµå¸³´Ï´Ù. ^^

¼ö°íÇϼ¼¿ä~



* ¸Û¸Û´Ô¿¡ ÀÇÇؼ­ °Ô½Ã¹° À̵¿µÇ¾ú½À´Ï´Ù (2010-11-28 12:14)

  Hit : 7795     Date : 2010/11/10 04:37



    
lMaxl04 2°¡ %32 ·Î µÇÁö¾ÊÀ»±î¿ä?
Àü À¥À» ¸ô¶ó¼­... ¾ÆÇÏÇÏÇÏÇÏ
2010/11/10  
ÇÁ¶óÀ̵å 3-1 µµ 2 ÀÌ°í 5-3µµ 2ÀÔ´Ï´Ù ¤»¤»
select¹®À¸·Î °¡Á®¿Ã¶§ ¼ö½ÄÀ»°è»êÇÑ °á°úµµ °¡Á®¿Ã¼öÀÖ½À´Ï´Ù :D
2010/11/10  
zzguswhd ³ªµµ ¾ð³Õ PHPÇÏ°í½Í´ç ¤Ð¤Ð¤Ð¤Ð 2010/11/14  
bigshott ´Ùµé ´äº¯ Á¤¸» °¨»çÇÕ´Ï´Ù. ^^
ÇÁ¶óÀ̵å´Ô ±×·¸°Ôµµ µÇ´Â±º¿ä ^^. °¨»çÇÕ´Ï´Ù.
´Ùµé Áñ°Å¿î ÇÏ·çµÇ¼¼¿ä~
2010/11/17  
214   googlebig.com/hackgame ¿¡¼­ ³ª¿À´Â XSS¹®Á¦ Áú¹®µå¸³´Ï´Ù.[2]     Ilios
11/23 5751
  php ¿ìȸ Áú¹® µå¸³´Ï´Ù.[4]     bigshott
11/10 7794
212   Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.     cjy559510
12/02 4521
211     [re] Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.[2]     cjy559510
12/02 4592
210   À¥ÇØÅ· °ü·Ã Áú¹® Á» µå¸³´Ï´Ù.[2]     bigshott
12/16 5011
209   ÇØÄ¿µéÀÇÇØÅ·¹æ½Ä[2]     jhm2882
12/17 5553
208   ÆäÀ̽ººÏ[1]     smile_mut
12/22 4101
207   ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ Áú¹® ÀÔ´Ï´Ù.[2]     bigshott
12/25 4973
206   À¥½© »ç¿ë¹ýÁ»[3]     À¥ÇØÅ·
12/30 15020
205   À¥ÇØÅ·,º¸¾È/ÇØÅ· À» ¹è¿ì·Á¸é...[1]     kn0ck
01/14 4339
204   ´©³ª »çÀÌÆ® Çã¶ô¸º°í ÇØÅ·¿¬½À Çϴ´ë ......[2]     lsykoh2
01/16 6536
203   htmlÄڵ带 Çí½º·Î º¯È¯ÇØ ½ÇÇàÇÒ¼ö ÀÖ³ª¿ä?[2]     kangms0801
01/16 4257
202   ±Ã±ÝÇÑ°ÔÀִµ¥¿ä~...[1]     ÇØÅ·study
01/17 4029
201   webhacking.kr °¡ÀÔ¹®Á¦ ¹Ù²¸¼­ Àß ¸ð¸£°Ú½À´Ï´Ù[1]     ¤»z¤Ól¤²q¤Çh¤§e¤Ñm
01/18 5798
200   À¥ÇØÅ· ¹æ¹ý? Áú¹®ÇÕ´Ï´Ù.[1]     wilmamom
01/23 4870
199   [À¥(mysql)Áú¹®ÀÌ ÀÖ½À´Ï´Ù.][3]     BkeMan
01/27 3710
198   À¥°ø°Ý Top3[3]     Pang
02/07 5026
197   Áú¹®µå¸®°Ú½À´Ï´Ù     khl0803
02/07 3639
196   »çÀÌÆ®¿¡ trojan ÀÌ ¹«´õ±â·Î ±ò·È½À´Ï´Ù, ¾î¶»°Ô Áö¿ö¾ß Çϳª¿ä?[1]     someone3
02/09 3999
195   À¥ÇØÅ·À» ¾î¶»°Ô ÇÏ´ÂÁö ¸ð¸£°Ú½À´Ï´Ù[4]     rappit
02/14 4464
1 [2][3][4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org