214, 3/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   hyunmin8
   file upload Ãë¾àÁ¡ Áú¹®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=162 [º¹»ç]


¼­¹ö¿¡ ±¸µ¿ÁßÀÎ ¾ð¾î°¡ PHP°¡ ±¸µ¿µÇ¾î µ¿ÀÛÇÏ°íÀִµ¥

ÆÄÀÏ ¾÷·Îµå Ãë¾àÁ¡ °ø°ÝÀ» ¹æ¾îÇϱâ À§ÇØ

phpÆÄÀϸ¸ ¸ø¿Ã¸®°Ô µÇ¾îÀִ°Ű°Àºµ¥

asp, jspÆÄÀÏÀº ¾÷·Îµå°¡ µË´Ï´Ù.

ÀÌ·²¶§ ¾î¶²¹®Á¦°¡ ¹ß»ýÇÏ´ÂÁö

¾Æ´Ï¸é ±×³É ÀÌ·¸°Ô ¿î¿µÇصµ µÇ´ÂÁö ±Ã±ÝÇÕ´Ï´Ù.

  Hit : 4185     Date : 2013/09/25 01:56



    
U_SoRang À¥ ½©(Web Shell) À̶ó°í µé¾îº¸¼Ì³ª¿ä?
ÀÌ°ÍÀº file upload Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÇÏ´Â °ø°Ý µµ±¸·Î »ç¿ëÇÏ´Â file À̸ç,
loginÀ¸·Î admin ±ÇÇÑÀ» ¹ÞÀ» ÇÊ¿ä ¾øÀÌ ÀÌ fileÀ» ºÒ·¯µé¿©¼­ admin ó·³ homepage ³»ÀÇ fileµéÀ» »ý¼º, ¼öÁ¤, »èÁ¦ ÇÒ ¼ö ÀÖ´Â ±â´ÉÀ» °¡Á³½À´Ï´Ù.

ÀÌ web shellÀº php, asp, jsp µîÀÇ ´Ù¾çÇÑ ¾ð¾î·Îµµ ¸¸µé ¼ö ÀÖ½À´Ï´Ù.
Áú¹®ÀÚ²²¼­ php file¸¸ ¸·¾Æ ³õÀ¸½Ã°í, asp, jsp´Â Çã¿ëÀ̶ó°í Çϼ̴µ¥,
asp, jsp·Î ¸¸µç web shellÀÌ upload µÈ´Ù¸é ¾î¶»°Ô µÉ±î¿ä?
ÇѸ¶µð·Î... [±× homepage´Â °ø°ÝÀÚÀÇ ¼Õ¿¡ ³Ñ¾î°£´Ù.]°¡ µË´Ï´Ù.
°ø°ÝÀÚ¿¡°Ô ³Ñ¾î°£´Ù¸é source-code¸¦ ¼öÁ¤ÇÏ¿© <iframe>À¸·Î »ç¿ëÀÚ ¸ô·¡ ¾Ç¼ºÄڵ带 ³»·Á¹Þµµ·Ï ÇÒ ¼ö ÀÖ°Ô µË´Ï´Ù.
Áï, cyber terror¸¦ ÁÖµµ ÇÒ ¼öµµ ÀÖ´Ù´Â ¶æÀÌ µÇÁö¿ä.
(½ÇÁ¦·Î, [file upload Ã뿪Á¡À¸·Î ÀÎÇÑ web shell »ðÀÔ]ÀÌ ¾Ç¼ºÄÚµåÀÇ °¨¿° ¿øÀÎÀÎ °æ¿ì°¡ ÀÖ½À´Ï´Ù.)

±×·¸±â ¶§¹®¿¡, ¸ðµç È®ÀåÀÚ¿¡ ´ëÇÑ °Ë»ç°¡ ÇÊ¿äÇϸç, ÀÌ È®ÀåÀÚµéÀ» Á¦ÇÑÇÏ´Â ±â´ÉÀÌ ÇÊ¿äÇÕ´Ï´Ù.
Áö±ÝÀÌ¶óµµ ±× È®ÀåÀÚ Á¦ÇÑÀ» ³ÐÈ÷½Ã´Â°Ô ÁÁ´Ù°í »ç·áµË´Ï´Ù.
2013/09/26  
exso ¼­¹ö¿¡ asp, jsp °¡ µ¿ÀÛ°¡´ÉÇÑÁö °Ë»çÇغ¸¼¼¿ä. php¸ðµâ¸¸ÀÖ´Ù¸é ¹®Á¦´Â¾ø°ÚÁÒ 2013/09/26  
Chris Ruiel asp ³ª jsp ÆÄÀÏÀÌ µ¿ÀÛ °¡´ÉÇÑÁö üũÇغ¸½Ã°í ÇÊ¿ä ¾øÀ¸½Ã´Ù¸é ¸·¾Æ³õÀ¸½Ã´Â°Ô ÁÁ±¸¿ä!

ÆÄÀÏ ¾÷·Îµå°¡ °¡´ÉÇÑ µð·ºÅ丮´Â ½ÇÇà±ÇÇÑ ÀÚü¸¦ ¸·¾Æ³õÀ¸½Ã´Â°Íµµ ¹æ¹ýÀÌ µÇ°Ú³×¿ä!^^
2013/09/27  
chlxogns92 ±×¸®°í, phpÄÚµå´Â phpÈ®ÀåÀÚ¸¸ÀÌ ¾Æ´Ï¶ó php5,php4µîÀÇ È®ÀåÀÚ¿¡¼­µµ ½ÇÇàÀÌ µÇ´Â °æ¿ì°¡ ¸¹¾Æ¿ä.
¾î¶² È®ÀåÀÚ¸¸ Çã¿ë¾ÈÇÏ´Â°Ô ¾Æ´Ï¶ó, ¾î¶² È®ÀåÀÚ¸¸ Çã¿ëÇÏ´Â Çü½ÄÀ¸·Î ¹Ù²ãº¸¼¼¿ä.
2013/09/30  
kumi123 »çÀÌÆ®°¡ ISS ¸¦ »ç¿ëÇÏÁö ¾Ê´Â´Ù¸é, asp´Â »ç¿ëÇÏÁö ¸øÇÏ°í,

jsp´Â µ¿ÀÛÀÌ °¡´ÉÇϸé, °ø°ÝÀÌ °¡´ÉÇÕ´Ï´Ù.

±×¸®°í, php ¸¦, Php PHp µîµîÀ¸·Î·Îµµ Àû¿ëÀÌ °¡´ÉÇÕ´Ï´Ù.
2014/02/03  
174     [re] Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.[2]     cjy559510
12/02 4614
173   Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.     cjy559510
12/02 4546
172   webhacking.kr 30¹ø µµ¿òÁ» ÁֽǺÐ...[1]     kumi123
07/30 4518
171   sql injection ½Ç½À ÇÏ·Á´Âµ¥¿ä ...¤Ð¤Ð[1]     wjscjfalsWkd1
06/20 4490
170   ¾È³çÇϼ¼¿ä. webgoat¿¡ °üÇؼ­ Áú¹® µå¸±·Á±¸¿ä.[2]     GaOnNuRI
07/05 4488
169   À¥ÇØÅ·À» ¾î¶»°Ô ÇÏ´ÂÁö ¸ð¸£°Ú½À´Ï´Ù[4]     rappit
02/14 4486
168   À¥ÇØÅ·À» Çغ¸°í½Í½À´Ï´Ù.[2]     real_khy
09/01 4452
167   webhacking.kr 33-4¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[3]     hygasyde
03/26 4444
166   À¥ÇØÅ·,º¸¾È/ÇØÅ· À» ¹è¿ì·Á¸é...[1]     kn0ck
01/14 4366
165   ¾È³çÇϼ¼¿ä À̹ø¿¡ ¾Èµå·ÎÀ̵å sql¼­¹ö¸¦ ±¸ÃàÇÏ°Ô µÇ¾ú´Âµ¥¿ä..[2]     ±î¹³´Ù¸£³¢
07/18 4340
164   wpe°°Àº ÇÁ·Î±×·¥ÀÇ ¿ø¸®¸¦ ÀÌÇØÇÏ·Á¸é..[1]     attainer
11/01 4331
163   ÇØÄ¿ ¸ðÁý.»çÀÌÆ®´ç 600¸¸¿ø Áö±Þ, Ÿ°Ù 24°÷, ÀºÇà ¹× ±â°ü ¾Æ´Ô.[4]     bestloan
01/06 4301
162   À¥ÇØÅ·ÀÇ°úÁ¤[3]     °¡¸é¼ÓÀǹ̼Ò
04/28 4300
161   Æķνº ±ò¾Æ¼­ ½ÇÇà½ÃÄ״µ¥ ¿ÖÀÌ·¯ÁÒ?(»çÁøêó)[1]     ygh159
07/13 4296
160   htmlÄڵ带 Çí½º·Î º¯È¯ÇØ ½ÇÇàÇÒ¼ö ÀÖ³ª¿ä?[2]     kangms0801
01/16 4278
159   ½ÎÀÌÇØÅ·´çÇÑ°Å ´©°¡ÇÑÁþÀÎÁö ¾Ë¼ö ÀÖ³ª¿ä?[1]     hackerwook
08/11 4254
158   ÀÌ ÇÁ·Î±×·¥ ¹ºÁö ¾Æ½Ã´ÂºÐ?(»çÁøêó)[8]     ygh357
12/16 4222
157   Ä£±¸°¡ Á¦ÄÄ¿¡ ÇØÅ·ÇÁ·Î±×·¥ ±ò¾Æ³ù´Ù°í ¤Ð¤Ð °í¼ö´Ôµé µµ¿ÍÁÖ¼¼¿ä[2]     ipon7878
06/20 4213
156   ½ÎÀÌ¿ùµå ºñ¹ø¿ä[1]     madhetter
05/15 4198
  file upload Ãë¾àÁ¡ Áú¹®ÀÔ´Ï´Ù.[5]     hyunmin8
09/25 4184
[1][2] 3 [4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org