214, 11/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bigshott
   ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ Áú¹® ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=11 [º¹»ç]


À¥ÇØÅ· °ü·Ã °øºÎ ÇÏ´ÂÁßÀä~

¶Ç ¾î·Á¿î ºÎºÐÀÌ »ý°Ü¼­ Áú¹® µå¸³´Ï´Ù. ^^

php ¼Ò½º±¸¿ä~

¾Æ·¡ ó·³ ÆÄÀÏ ¾÷·Îµå¸¦ ÇÒ ¼ö ÀÖ½À´Ï´Ù.


<form method=post enctype="multipart/form-data" action=index.php>
<input type=file name=upfile><input type=submit>

ÆÄÀÏ ¾÷·Îµå¸¦ Çؼ­ ¶Ç ´Ù¸¥ phpÆÄÀÏ ¼Ò½º¸¦ ÀÐÀ» ¼ö°¡ ÀÖÀ»±î¿ä?

°ü·Ã Ãë¾àÁ¡À» ¾Æ¹«¸® ã¾ÆºÁµµ ¾ø³×¿ä~

aaa;../../test/index.php ¿ä·±½ÄÀ¸·Îµµ Çغôµ¥ Ãâ·ÂÀÌ µÇÁö ¾Ê½À´Ï´Ù.

aaa;cp ./test/index.php ./test/index.txt ¿ä·±°Íµµ Çغ¸±¸¿ä ¤Ì¤Ð

°í¼ö´Ôµé Á¶¾ð Á» ºÎŹµå¸³´Ï´Ù.

¼ö°íÇϼ¼¿ä~

  Hit : 4982     Date : 2010/12/25 12:44



    
º°ºûÀ»´ã¾Æ À¥ ÇØÅ·À̳ª httpd¸¦ Àß ¾Æ´Â °ÍÀº ¾Æ´ÏÁö¸¸... ÀÏ´Ü Á¦ »ý°¢À» ¸»¾¸µå·Áº¼°Ô¿ä.
¸ÕÀú ÆÄÀÏÀÌ ¾÷·ÎµåµÈ °÷ÀÌ /home/httpuser/public_html/test.php·Î ¿Ã¶ó°¬Áö¸¸ index´Â ÀüÇô ´Ù¸¥ °÷¿¡ ÀÖ´Ù´Â °¡Á¤ÇսôÙ. °èÁ¤Àº httpuserÀ̱¸¿ä.

±×·¸´Ù¸é index.php¿¡¼­ test.php·Î Á¢±ÙÀ» ÇÑ´Ù°í ÇÏ¸é °æ·Î ÀÚü°¡ Ʋ·Á¼­ ./¿Í °°Àº ÀÚ±â ÀÚ½ÅÀÇ À§Ä¡¿¡¼­ Á¢±ÙÀº Èûµé°Ì´Ï´Ù.

ÀÌ ¶§ Àú °÷¿¡ Á¢±ÙÇÏ½Ç ¶§´Â Á¦ »ý°¢¿¡´Â ÁÖ¼ÒâÀ» ÀÌ¿ëÇÑ Á¢±Ùµµ Çѹø »ý°¢ÇØ º¸½Ç¸¸ ÇÏ´Ù°í »ý°¢ÇÕ´Ï´Ù.
<a href=http://www.domain.com/../../../../../../../../../../../../../../../../../home/httpuser/public_html/test.php target=_blank>http://www.domain.com/../../../../../../../../../../../../../../../../../home/httpuser/public_html/test.php</a>
2010/12/25  
bigshott ¾Æ~ ±×·¸±º¿ä.
´äº¯ Á¤¸» °¨»çµå¸³´Ï´Ù. µµ¿ò ¸¹ÀÌ µÇ¾ú½À´Ï´Ù.
Áñ°Å¿î ¼ºÅºÀý º¸³»¼¼¿ä ^^
2010/12/25  
14   webhacking.kr °¡ÀÔ¹®Á¦ ¹Ù²¸¼­ Àß ¸ð¸£°Ú½À´Ï´Ù[1]     ¤»z¤Ól¤²q¤Çh¤§e¤Ñm
01/18 5805
13   ±Ã±ÝÇÑ°ÔÀִµ¥¿ä~...[1]     ÇØÅ·study
01/17 4040
12   htmlÄڵ带 Çí½º·Î º¯È¯ÇØ ½ÇÇàÇÒ¼ö ÀÖ³ª¿ä?[2]     kangms0801
01/16 4263
11   ´©³ª »çÀÌÆ® Çã¶ô¸º°í ÇØÅ·¿¬½À Çϴ´ë ......[2]     lsykoh2
01/16 6546
10   À¥ÇØÅ·,º¸¾È/ÇØÅ· À» ¹è¿ì·Á¸é...[1]     kn0ck
01/14 4349
9   À¥½© »ç¿ë¹ýÁ»[3]     À¥ÇØÅ·
12/30 15031
  ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ Áú¹® ÀÔ´Ï´Ù.[2]     bigshott
12/25 4981
7   ÆäÀ̽ººÏ[1]     smile_mut
12/22 4111
6   ÇØÄ¿µéÀÇÇØÅ·¹æ½Ä[2]     jhm2882
12/17 5564
5   À¥ÇØÅ· °ü·Ã Áú¹® Á» µå¸³´Ï´Ù.[2]     bigshott
12/16 5019
4   Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.     cjy559510
12/02 4530
3     [re] Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.[2]     cjy559510
12/02 4599
2   php ¿ìȸ Áú¹® µå¸³´Ï´Ù.[4]     bigshott
11/10 7808
1   googlebig.com/hackgame ¿¡¼­ ³ª¿À´Â XSS¹®Á¦ Áú¹®µå¸³´Ï´Ù.[2]     Ilios
11/23 5766
[1].. 11

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org