214, 10/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bigshott
   php ¿ìȸ Áú¹® µå¸³´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=3 [º¹»ç]


¾È³çÇϼ¼¿ä~

sql ÀÎÁ§¼Ç °øºÎÇÏ´Ù°¡ ±Ã±ÝÇÑ ºÎºÐÀÌ À־ ÀÌ·¸°Ô Áú¹®µå¸³´Ï´Ù. ^^

¿äÁò °øºÎ ÇÏ´Ù º¸´Ï ¿ö³« ÇãÁ¢Çؼ­ ÀÚÁÖ Áú¹®µå¸®°Ô µÇ³×¿ä ^^

phpÇÔ¼ö¿¡ º¸¸é eregi ÇÔ¼ö·Î ÇÊÅ͸µÀ» °É´øµ¥¿ä~

if(eregi("--|2|50|\+|substring|from|infor|mation|lv|%20|=|!|<>|sysM|and|or|table|column",$ck)) exit("Access Denied!");

À§¿Í °°ÀÌ ÇÊÅ͸µÀÌ °É·Á ÀÖ½À´Ï´Ù.

?val=1 union select 2  

¿ä·¸°Ô ÀÔ·ÂÇؼ­ °ªÀ» ³Ö¾î¾ß µÇ´Âµ¥¿ä~

2°¡ eregi ÇÔ¼ö¿¡ °É·Á¼­ ³Ñ¾î°¡Áú ¾Ê½À´Ï´Ù.

url encode, hex µîµî ´Ù ÇغÁµµ °É¸®³×¿ä~

¿ìȸ ÇÒ¼ö ÀÖ´Â ÁÁÀº ¹æ¹ý ¾øÀ»±î¿ä?

°í¼ö´Ôµé Á¶¾ð Á» ºÎŹµå¸³´Ï´Ù. ^^

¼ö°íÇϼ¼¿ä~



* ¸Û¸Û´Ô¿¡ ÀÇÇؼ­ °Ô½Ã¹° À̵¿µÇ¾ú½À´Ï´Ù (2010-11-28 12:14)

  Hit : 7821     Date : 2010/11/10 04:37



    
lMaxl04 2°¡ %32 ·Î µÇÁö¾ÊÀ»±î¿ä?
Àü À¥À» ¸ô¶ó¼­... ¾ÆÇÏÇÏÇÏÇÏ
2010/11/10  
ÇÁ¶óÀ̵å 3-1 µµ 2 ÀÌ°í 5-3µµ 2ÀÔ´Ï´Ù ¤»¤»
select¹®À¸·Î °¡Á®¿Ã¶§ ¼ö½ÄÀ»°è»êÇÑ °á°úµµ °¡Á®¿Ã¼öÀÖ½À´Ï´Ù :D
2010/11/10  
zzguswhd ³ªµµ ¾ð³Õ PHPÇÏ°í½Í´ç ¤Ð¤Ð¤Ð¤Ð 2010/11/14  
bigshott ´Ùµé ´äº¯ Á¤¸» °¨»çÇÕ´Ï´Ù. ^^
ÇÁ¶óÀ̵å´Ô ±×·¸°Ôµµ µÇ´Â±º¿ä ^^. °¨»çÇÕ´Ï´Ù.
´Ùµé Áñ°Å¿î ÇÏ·çµÇ¼¼¿ä~
2010/11/17  
34   Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.     cjy559510
12/02 4548
33     [re] Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.[2]     cjy559510
12/02 4615
32   À¥»çÀÌÆ® ÇØÅ·°ü·Ã ¹®Àǵ帳´Ï´Ù.[1]     chniow
02/27 3218
31   ÇØÅ· °úÁ¤À» °øºÎÇÏ°í½ÍÀº ´ëÇлýÀÔ´Ï´Ù.[1]     chanhee92
07/22 3607
30   HTTP Çì´õ[1]     chaneyoon
04/30 2797
29   ¸ÆºÏÀ¸·Î À¥ ¸ðÀÇÇØÅ·     chachaco
06/16 3938
28   sql injection °ü·ÃÇؼ­ Áú¹®ÀÔ´Ï´Ù.[2]     cdpython
07/28 3469
27   ¿î¿µÁßÀÎ À¥»çÀÌÆ®ÀÇ DBÁ¤º¸ ÇØÅ·[2]     cameo305
07/01 8732
26   [À¥(mysql)Áú¹®ÀÌ ÀÖ½À´Ï´Ù.][3]     BkeMan
01/27 3732
25   [Web]php¼Ò½º Çؼ®Á¡ ºÎŹµå¸±°Ô¿ä..[2]     BkeMan
03/06 4111
24   À¥ ÇØÅ· ÀÚ½ÅÀÖÀ¸½Å ºÐµé ²À ºÁÁÖ¼¼¿ä     bird999
12/05 2960
  php ¿ìȸ Áú¹® µå¸³´Ï´Ù.[4]     bigshott
11/10 7820
22   ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ Áú¹® ÀÔ´Ï´Ù.[2]     bigshott
12/25 4999
21   À¥ÇØÅ· °ü·Ã Áú¹® Á» µå¸³´Ï´Ù.[2]     bigshott
12/16 5045
20   ÇØÄ¿ ¸ðÁý.»çÀÌÆ®´ç 600¸¸¿ø Áö±Þ, Ÿ°Ù 24°÷, ÀºÇà ¹× ±â°ü ¾Æ´Ô.[4]     bestloan
01/06 4302
19   ³×Æ®¿öÅ© °ü·Ã Áú¹®ÀÌ¿¡¿ä...[1]     babisss
02/23 3635
18   LibrettoCMS 2.2.2 - Arbitrary File Upload ¾Æ½Ã´ÂºÐ °è½Å°¡¿ä?     Á¦·Î½Ã
06/16 3356
17   À¥½© »ç¿ë¹ýÁ»[3]     À¥ÇØÅ·
12/30 15045
16   ¾È³çÇϼ¼¿ä. ÀÌ °Ô½ÃÆÇ¿¡ ¸ÂÁö ¾Ê´Â Áú¹®°°Áö¸¸ Áú¹®À» Çϳª Çغ¸·Á°í ÇÕ´Ï´Ù..[1]     Áú¹®ÀÚ
06/21 3486
15   À¥ÇØÅ·½Ã[1]     AutoFlow
10/24 3650
[1][2][3][4][5][6][7][8][9] 10 ..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org