215, 6/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bigshott
   php ¿ìȸ Áú¹® µå¸³´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=3 [º¹»ç]


¾È³çÇϼ¼¿ä~

sql ÀÎÁ§¼Ç °øºÎÇÏ´Ù°¡ ±Ã±ÝÇÑ ºÎºÐÀÌ À־ ÀÌ·¸°Ô Áú¹®µå¸³´Ï´Ù. ^^

¿äÁò °øºÎ ÇÏ´Ù º¸´Ï ¿ö³« ÇãÁ¢Çؼ­ ÀÚÁÖ Áú¹®µå¸®°Ô µÇ³×¿ä ^^

phpÇÔ¼ö¿¡ º¸¸é eregi ÇÔ¼ö·Î ÇÊÅ͸µÀ» °É´øµ¥¿ä~

if(eregi("--|2|50|\+|substring|from|infor|mation|lv|%20|=|!|<>|sysM|and|or|table|column",$ck)) exit("Access Denied!");

À§¿Í °°ÀÌ ÇÊÅ͸µÀÌ °É·Á ÀÖ½À´Ï´Ù.

?val=1 union select 2  

¿ä·¸°Ô ÀÔ·ÂÇØ¼­ °ªÀ» ³Ö¾î¾ß µÇ´Âµ¥¿ä~

2°¡ eregi ÇÔ¼ö¿¡ °É·Á¼­ ³Ñ¾î°¡Áú ¾Ê½À´Ï´Ù.

url encode, hex µîµî ´Ù ÇØºÁµµ °É¸®³×¿ä~

¿ìȸ ÇÒ¼ö ÀÖ´Â ÁÁÀº ¹æ¹ý ¾øÀ»±î¿ä?

°í¼ö´Ôµé Á¶¾ð Á» ºÎʵ右´Ï´Ù. ^^

¼ö°íÇϼ¼¿ä~



* ¸Û¸Û´Ô¿¡ ÀÇÇØ¼­ °Ô½Ã¹° À̵¿µÇ¾ú½À´Ï´Ù (2010-11-28 12:14)

  Hit : 8899     Date : 2010/11/10 04:37



    
lMaxl04 2°¡ %32 ·Î µÇÁö¾ÊÀ»±î¿ä?
Àü À¥À» ¸ô¶ó¼­... ¾ÆÇÏÇÏÇÏÇÏ
2010/11/10  
ÇÁ¶óÀ̵å 3-1 µµ 2 À̰í 5-3µµ 2ÀÔ´Ï´Ù ¤»¤»
select¹®À¸·Î °¡Á®¿Ã¶§ ¼ö½ÄÀ»°è»êÇÑ °á°úµµ °¡Á®¿Ã¼öÀÖ½À´Ï´Ù :D
2010/11/10  
zzguswhd ³ªµµ ¾ð³Õ PHPÇϰí½Í´ç ¤Ð¤Ð¤Ð¤Ð 2010/11/14  
bigshott ´Ùµé ´äº¯ Á¤¸» °¨»çÇÕ´Ï´Ù. ^^
ÇÁ¶óÀ̵å´Ô ±×·¸°Ôµµ µÇ´Â±º¿ä ^^. °¨»çÇÕ´Ï´Ù.
´Ùµé Áñ°Å¿î ÇÏ·çµÇ¼¼¿ä~
2010/11/17  
115   LFI¿ÍRFI½ÄÀ¸·Î ÆÄÀϾ÷·Îµå Áú¹®[1]     ygh357
10/18 5166
114   LibrettoCMS 2.2.2 - Arbitrary File Upload ¾Æ½Ã´ÂºÐ °è½Å°¡¿ä?     Á¦·Î½Ã
06/16 4356
113   load of sql injectinÀ» Ç®±¸ÀÖ½À´Ï´Ù..[3]     deadbeef
02/15 4757
112   Lord of SQL Injection Troll Áú¹®[1]     ÇØÅ·ÀßÇϰí½Í´Ù
02/18 1174
111   MySQL Áú¹®[2]     ka0r1
04/15 4385
110   Odysseus ¶ó´Â ÇÁ·Î±×·¥¿¡ ´ëÇØ ¿©ÂÞ¾î º¾´Ï´Ù.     ygh159
08/18 4579
109   Paros Åø °ü·Ã Áú¹®[2]     stalaction
10/21 5855
108   paros¸¦ ±¸µ¿ÇÑ »óÅ¿¡¼­ ¾î¶² À¥»çÀÌÆ®¸¦ µé¾î°¥ ¶§     asdwho
03/24 4692
107   passward cracking Áú¹®ÀÖ½À´Ï´Ù[2]     °æ³²123
01/27 4310
  php ¿ìȸ Áú¹® µå¸³´Ï´Ù.[4]     bigshott
11/10 8898
105   phpÃ¥ Ãßõ ºÎʵ右´Ï´Ù.[1]     h@cking2013
06/05 4877
104   PHP¿¡¼­ À̸ÞÀÏ Àü¼ÛÇÒ¶§ °¡·Îç ¼ö ÀÖ³ª¿ä?[9]     drrobot333
11/16 3799
103   php¿¡¼­ Á¡(.)[3]     ka0r1
07/11 4645
102   POST METHOD     ewqqw
03/13 3416
101   Post Method[2]     ewqqw
03/16 3561
100   Session º¯¼ö Á¶ÀÛ°ú IP ´ëÁ¶º¸¾È ÀÎÁõ Åë°ú°¡ °¡´ÉÇѰ¡¿ä ?[1]     $Zero
03/24 4333
99   sessionid´Â ¾î¶²Á¾·ùÀÇ ¾ÏÈ£·Î ÀÎÄÚµù µÇ´Â°Ç°¡¿ä?[2]     kangms0801
04/03 5852
98   shell ¿¡ ´ëÇØ ¼³¸íÁ» ÇØÁÖ¼¼¿ä![1]     v_0_0v_
06/04 4222
97   SQL Injection[5]     ka0r1
04/14 4490
96   sql injection Áú¹®ÀÖ½À´Ï´Ù ¿ìȸ°ü·Ã[1]     Qwed_na
09/04 4380
[1][2][3][4][5] 6 [7][8][9][10]..[11]

Copyright 1999-2026 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org