ํ‹ฐ์Šคํ† ๋ฆฌ ๋ทฐ

CHALLENGE

[LOS] gremlin ํ’€์ด(1)

๐ŸŒง: 2020. 12. 5.

์ฒซ ๋ฒˆ์งธ ๋‹จ๊ณ„์ธ gremlin์—์„œ preg_match ํ•จ์ˆ˜๋ฅผ ๋ณด๋ฉด ๋ณ„๋‹ค๋ฅธ ์ž…๋ ฅ๊ฐ’ ๊ฒ€์ฆ์„ ํ•˜์ง€ ์•Š๊ณ  ID์™€ PW ๋ถ€๋ถ„์— ์ฟผ๋ฆฌ๊ฐ€ ๋ฐ”๋กœ ์‚ฝ์ž…๋˜๊ณ  ์žˆ๊ธฐ์— ์‚ฝ์ž…๋˜๋Š” ์ฟผ๋ฆฌ๋ฌธ์ด " ์ฐธ " ๊ฐ’์„ ๊ฐ€์ง€๋„๋ก " or " ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•ด์„œ ์ž‘์„ฑํ•ด์ฃผ์‹œ๋ฉด ์‰ฝ๊ฒŒ ํ†ต๊ณผ๋ฉ๋‹ˆ๋‹ค.

 

preg_match ํ•จ์ˆ˜์— ์ง€์ •ํ•ด๋‘” ,/(\) ๋“ฑ  ์ด ์ž…๋ ฅ๋  ๊ฒฝ์šฐ " No Hack "์ด๋ผ๋Š” ๋ฌธ๊ตฌ๋ฅผ ๋„์šฐ๋ฉฐ ์‹คํŒจํ•˜๊ณ  ์žˆ์œผ๋‹ˆ ํ•ด๋‹น ๋ฌธ๊ตฌ๋Š” ํ”ผํ•ด์„œ ์ž‘์„ฑํ•˜๋ฉด ๋˜๊ฒ ์Šต๋‹ˆ๋‹ค.

if(preg_match('/prob|_|\.|\(\)/i', $_GET[id])) exit("No Hack ~_~"); // do not try to attack another table, database!
if(preg_match('/prob|_|\.|\(\)/i', $_GET[pw])) exit("No Hack ~_~");

or ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•˜๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. or ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ๋‘˜ ์ค‘ ํ•œ ๊ฐ€์ง€๋งŒ ์ฐธ ์ด์—ฌ๋„ ๋ฌด์กฐ๊ฑด " ์ฐธ "์„ ๋ฐ˜ํ™˜ํ•˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

 

$query = "select id from prob_gremlin where id='{$_GET[id]}' and pw='{$_GET[pw]}'";

$_GET ๋ฐฉ์‹์œผ๋กœ ์ „๋‹ฌํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— URL์˜ php ๋’ค์— ์— ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ž‘์„ฑํ•ด์ฃผ๊ณ  ์ธ์ž ๊ฐ’์„ ๋งŒ๋“ค์–ด์ฃผ๋ฉด ๋ฉ๋‹ˆ๋‹ค.

 

" % " ๋Š” all ๊ฐ™์€ ์˜๋ฏธ๋ฅผ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉฐ " A% " ๋ผ๊ณ  ์ž…๋ ฅ๋  ๊ฒฝ์šฐ A ๋กœ ์‹œ์ž‘ํ•˜๋Š” ๋ชจ๋“  ID ๋ฅผ ์—ด๊ฑฐ,  pw= ์˜์—ญ์„ ํ™•์ธํ•ด๋ณด๋ฉด '1'='1'๋กœ ์ฐธ ๊ฐ’์ด ์„ฑ์‚ฌ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ SQL ๊ตฌ๋ฌธ์˜ "where" ์ ˆ์„ ์‰ฝ๊ฒŒ ๋ฌด๋ ฅํ™”์‹œํ‚ค๋Š” ๊ตฌ๋ฌธ์ด๊ธฐ์— ์ฟผ๋ฆฌ๊ฐ€ ์„ฑ์‚ฌ๋  ๊ฒฝ์šฐ ์ €์žฅ๋˜์–ด ์žˆ๋Š” ๋ชจ๋“  ์ •๋ณด๋ฅผ ๋ถˆ๋Ÿฌ์˜ค๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

 

PW ์—๋Š” ์‚ฝ์ž…ํ•˜์ง€ ์•Š๊ณ  ID ์˜์—ญ์—๋งŒ ์ฐธ ์ฟผ๋ฆฌ๋ฌธ์„ ์‚ฝ์ž…ํ•˜์—ฌ ํด๋ฆฌ์–ด๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์œ„์˜ ์ฟผ๋ฆฌ๋ฌธ์„ ๋ณด๋‹ˆ ID ๋’ท๋ถ€๋ถ„์— ์ฃผ์„์„ ์‚ฝ์ž…ํ•˜์—ฌ ํ•ด๋‹น ์ž…๋ ฅ๋œ ์ฟผ๋ฆฌ๋งŒ ์‹คํ–‰๋˜๋„๋ก ํ•œ๋‹ค๋Š” ๊ฑธ ๊นœ๋นกํ–ˆ๋„ค์š”.

 

ํ•œ ์ค„ ์ฃผ์„์ธ " --(๊ณต๋ฐฑ) "์„ ์ถ”๊ฐ€ํ•˜์—ฌ ํ•ด๋‹น ๊ตฌ๋ฌธ ์ดํ›„๋ถ€ํ„ฐ ์˜ค๋Š” ๋‚ด์šฉ๋“ค์€ ๋ชจ๋‘ ์ฃผ์„์ฒ˜๋ฆฌํ•˜๊ฒŒ ๋˜๊ธฐ์— PW ์˜์—ญ์—๋Š” ์ž…๋ ฅํ•˜์ง€ ์•Š์•„๋„ ์„ฑ๊ณต์ ์œผ๋กœ ํด๋ฆฌ์–ดํ•ฉ๋‹ˆ๋‹ค์ฃผ์„์˜ ์ข…๋ฅ˜์—๋Š” ๋ฒ”์œ„ ์ง€์ • ๊ฐ€๋Šฅํ•œ ์ฃผ์„๊ณผ ํ•œ ์ค„์„ ์ฃผ์„ํ•ด์ฃผ๋Š” ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๋‹ค. 

 

์ฃผ์„์ฒ˜๋ฆฌ
ํ•œ์ค„ -> # ๋˜๋Š” --%20
๋‹ค์ค‘ -> /*์ฃผ์„์ฒ˜๋ฆฌ*/ 

'CHALLENGE' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[LOS] goblin ํ’€์ด(3)  (0) 2020.12.05
[LOS] cobolt ํ’€์ด(2)  (0) 2020.12.05
XSS Challenges 2  (0) 2020.12.04
XSS Challenges 1  (0) 2020.12.03
XSS Challenges 0  (0) 2020.12.02
๊ณต์œ ํ•˜๊ธฐ ๋งํฌ
Comment