214, 10/11 ȸ  α  
   bigshott
   ε Դϴ.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=11 []


ŷ ϴε~

κ ܼ 帳ϴ. ^^

php ҽ~

Ʒ ó ε带 ֽϴ.


<form method=post enctype="multipart/form-data" action=index.php>
<input type=file name=upfile><input type=submit>

ε带 ؼ ٸ php ҽ ?

ƹ ãƺ ׿~

aaa;../../test/index.php ䷱ε غôµ ʽϴ.

aaa;cp ./test/index.php ./test/index.txt ䷱͵ غ ̤

Ե Ź帳ϴ.

ϼ~

  Hit : 5028     Date : 2010/12/25 12:44



    
ŷ̳ httpd ƴ ƴ... ϴ Կ.
ε /home/httpuser/public_html/test.php ö index ٸ ִٴ սô. httpuseṟ.

׷ٸ index.php test.php Ѵٰ ϸ ü Ʋ ./ ڱ ڽ ġ ̴ϴ.

Ͻ ּâ ̿ ٵ ѹ Ǹ ϴٰ մϴ.
<a href=http://www.domain.com/../../../../../../../../../../../../../../../../../home/httpuser/public_html/test.php target=_blank>http://www.domain.com/../../../../../../../../../../../../../../../../../home/httpuser/public_html/test.php</a>
2010/12/25  
bigshott ~ ׷.
亯 帳ϴ. Ǿϴ.
ſ ź ^^
2010/12/25  
34   SQL Injection ݱ 帳ϴ.[3]     kmc8724
07/03 4747
33   vbscript Ŭ̾Ʈ ŷ ִ Ʈ ϴ ñմϴ     lekel09
10/10 4767
32   sessionid  ȣ ڵ Ǵ°ǰ?[2]     kangms0801
04/03 4842
31   ȸ 帳ϴ.[1]     tpdbs953
10/17 4880
30   ŷ ? մϴ.[1]     wilmamom
01/23 4911
29   webhacking.kr[1]     ǹ̼
04/28 4950
28   Paros [2]     stalaction
10/21 4964
  ε Դϴ.[2]     bigshott
12/25 5027
26   Top3[3]     Pang
02/07 5067
25   ŷ 帳ϴ.[2]     bigshott
12/16 5075
24   ŷ ؼ մϴ[5]     wqw3
12/16 5079
23   ̹ б OWASP͵ ߴµ 庼 Ƽ...[1]     heizelnet
07/17 5247
22   [] Ʈ ҽ ° ֳ?[2]     helpwizet
03/08 5250
21   ŷ Ҷ ʿ (α׷)[2]     ralehgus123
05/12 5458
20   webhacking.kr Թ 帳ϴ[3]     kangms0801
03/29 5481
19   Ǵ ߽ IP[1]     zaksalna
04/22 5501
18   Ŀŷ[2]     jhm2882
12/17 5602
17   googlebig.com/hackgame XSS 帳ϴ.[2]     Ilios
11/23 5804
16   webhacking.kr Թ ٲ 𸣰ڽϴ[1]     zlqhem
01/18 5850
15   ǽù Green guard α׷ ˷ ּ[1]     wqw3
04/19 6066
[1][2][3][4][5][6][7][8][9] 10 ..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org