214, 9/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ka0r1
   ·Î±×ÀÎ ÆäÀÌÁö ±¸ÇöÁß header ÇÔ¼öÀÇ ÀǹÌ

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=141 [º¹»ç]


<?php
        $user="asdf";
        $pass="asdf";

        if($_SERVER["PHP_AUTH_USER"]==$user&&$_SERVER["PHP_AUTH_PW"]==$pass){
                echo "Succeed Access!";
        }

        else{
            header('WWW-Authenticate: Basic realm="You need to login"');
            header("HTTP/1.0 401 Unauahorized");
            echo "Failed Access!";
            exit;
        }
?>


else¹®¿¡¼­ header ÇÔ¼ö 2°³°¡ Àִµ¥
header ÇÔ¼ö´Â À¥ ºê¶ó¿ìÀú·Î »ç¿ëÀÚ ÀÎÁõÀ» ¿ä±¸Çϸç
Çì´õ Á¤º¸¸¦ À¥ ºê¶ó¿ìÀú·Î Àü¼ÛÇÑ´Ù°í Ã¥¿¡¼­ ³ª¿ÍÀÖ½À´Ï´Ù.
±×·¡µµ ¹º°¡ Á» ¸ð¸£°Ú¾î¿ä.
"·Î±×ÀÎ ÆäÀÌÁö ±¸Çö -> °Ô½ÃÆÇ ¸¸µé±â -> À¥ ÇØÅ·"À» Ä¿¸®Å§·³À¸·Î °øºÎÇÏ°í Àִµ¥
¹¹¶ö±î... ¼Ò½º Äڵ常 º¸°í¼± Ŭ¶óÀ̾ðÆ®¿Í À¥¼­¹ö°£¿¡ ÀÌ·ç¾îÁö´Â ÀÏ·ÃÀÇ °úÁ¤µéÀÌ
È®½ÇÇÏ°Ô ¸ô¶ó¼­...  ¹» °øºÎÇØ¾ß µÉÁö ¸ð¸£°Ú³×¿ä;;
¼Ó ½Ã¿øÇÏ°Ô ¹æÇâÀ» Á¦½ÃÇØÁÖ½Ã¸é °¨»çÇÏ°Ú½À´Ï´Ù.

  Hit : 4738     Date : 2013/04/10 01:47



    
rubiya header ¶ó´Â °ÍÀº Ŭ¶óÀ̾ðÆ®°¡ ¿äûÇÑ ÆäÀÌÁö¸¦ ºê¶ó¿ìÀú¿¡ Ãâ·ÂÇϱâ Àü¿¡ ¹Ì¸® ºê¶ó¿ìÀú¿¡ ÀÌ ÆäÀÌÁö°¡ °¡Áö°í ÀÖ´Â ³»¿ëÀº ¾î¶² °Í ÀÌ´Ù ¶ó°í ¹Ì¸® ¾Ë·ÁÁ༭ ºê¶ó¿ìÀú°¡ ´ëºñ ÇÒ ¼ö ÀÖµµ·Ï ÇØÁÖ´Â °ÍÀÔ´Ï´Ù.

¶ó´Â ¼³¸íÀÌ ¸íÄèÇϳ׿ä.

±×·±µ¥ php_auth_user ´Â ½ÇÁ¦·Î´Â °ÅÀÇ »ç¿ëµÇÁö ¾Ê¾Æ¿ä¤Ð¤Ð

htmlÀÇ formű׸¦ »ç¿ëÇؼ­ post ¸Þ¼Òµå·Î ¼­¹ö¿¡ °ªÀ» º¸³»ÁÖ¸é ±× °ªÀ» µ¥ÀÌÅͺ£À̽º¿¡¼­ Á¶È¸Çغ¸´Â ¹æ½ÄÀÌ ´ëºÎºÐÀÔ´Ï´Ù.

¿¹¸¦µé¾î

<form method=post action=login.php>
¾ÆÀ̵ð : <input name=id type=text>
Æнº¿öµå : <input name=pw type=password>
<input type=submit>

ÀÌ·± ÆäÀÌÁö¿¡ ¾ÆÀ̵ð¿Í Æнº¿öµå¸¦ ³ÖÀ¸¸é login.php¿¡¼­ $_POST[id] ¿Í $_POST[pw] º¯¼ö¸¦ »ç¿ëÇؼ­

mysql("select * from table where id='$_POST[id]' and pw='$_POST[pw]'");

ÀÌ·¸°Ô µ¥ÀÌÅͺ£À̽º¿¡ ÁúÀǹ®À» º¸³» °á°ú°ªÀÌ ¹ÝȯµÇ´ÂÁö¸¦ üũÇÏ´Â ¹æ½ÄÀÔ´Ï´Ù.
2013/04/10  
ka0r1 rubiya // µ¥ÀÌÅͺ£À̽º¸¦ °£°úÇؼ­ ±×³É ³Ñ¾î°£°Ô Å»ÀÌ µÇ¾ú³×¿ä.
Á¦°¡ Ã¥À» º¸¸é¼­ ÇϳªÇϳª¾¿ ´Ù º»°Ô ¾Æ´Ï°í Áøµµ¸¦ »¡¸® ³ª°¥·Á°í ±×³É ³Ñ¾î°£ ºÎºÐÀÌ Á» ÀÖ½À´Ï´Ù.
¾î¶µç ÁÁÀº ´äº¯ °¨»çÇÕ´Ï´Ù.
2013/04/10  
54   Æķνº ±ò¾Æ¼­ ½ÇÇà½ÃÄ״µ¥ ¿ÖÀÌ·¯ÁÒ?(»çÁøêó)[1]     ygh159
07/13 4314
53   À¥ÇØÅ·ÀÇ°úÁ¤[3]     °¡¸é¼ÓÀǹ̼Ò
04/28 4316
52   ÇØÄ¿ ¸ðÁý.»çÀÌÆ®´ç 600¸¸¿ø Áö±Þ, Ÿ°Ù 24°÷, ÀºÇà ¹× ±â°ü ¾Æ´Ô.[4]     bestloan
01/06 4321
51   wpe°°Àº ÇÁ·Î±×·¥ÀÇ ¿ø¸®¸¦ ÀÌÇØÇÏ·Á¸é..[1]     attainer
11/01 4352
50   ¾È³çÇϼ¼¿ä À̹ø¿¡ ¾Èµå·ÎÀ̵å sql¼­¹ö¸¦ ±¸ÃàÇÏ°Ô µÇ¾ú´Âµ¥¿ä..[2]     ±î¹³´Ù¸£³¢
07/18 4359
49   À¥ÇØÅ·,º¸¾È/ÇØÅ· À» ¹è¿ì·Á¸é...[1]     kn0ck
01/14 4383
48   webhacking.kr 33-4¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[3]     hygasyde
03/26 4463
47   À¥ÇØÅ·À» Çغ¸°í½Í½À´Ï´Ù.[2]     real_khy
09/01 4470
46   À¥ÇØÅ·À» ¾î¶»°Ô ÇÏ´ÂÁö ¸ð¸£°Ú½À´Ï´Ù[4]     rappit
02/14 4506
45   ¾È³çÇϼ¼¿ä. webgoat¿¡ °üÇؼ­ Áú¹® µå¸±·Á±¸¿ä.[2]     GaOnNuRI
07/05 4507
44   sql injection ½Ç½À ÇÏ·Á´Âµ¥¿ä ...¤Ð¤Ð[1]     wjscjfalsWkd1
06/20 4514
43   webhacking.kr 30¹ø µµ¿òÁ» ÁֽǺÐ...[1]     kumi123
07/30 4541
42   Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.     cjy559510
12/02 4561
41     [re] Á¦°¡ À¥ÇØÅ·À» ¹è¿ì·ÁÇϴµ¥¿ä.[2]     cjy559510
12/02 4633
40   À̹ÌÁö¾È¿¡ ¸®´ÙÀÌ·ºÆ® ¼Ò½º(¾Ç¿ë¸ñÀûX)[2]     tjdgus1515
12/06 4641
39   header¿Í body°¡ ±¸ºÐµÇ¾î ÀÖ´Â ÀÌÀ¯?[4]     ka0r1
04/12 4675
38   À¥½© °ü·Ã Áú¹®ÀÖ½À´Ï´Ù.     stoopynice
07/26 4692
37   À¥ÇØÅ· °øºÎ¼ø¼­¸¦ ¾Ë·ÁÁÖ¼¼¿ä..[2]     nooooooob
02/28 4714
  ·Î±×ÀÎ ÆäÀÌÁö ±¸ÇöÁß header ÇÔ¼öÀÇ ÀǹÌ[2]     ka0r1
04/10 4737
35   XSS ÇØÅ· Áú¹®[3]     test11
03/07 4744
[1][2][3][4][5][6][7][8] 9 [10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org