ํ‹ฐ์Šคํ† ๋ฆฌ ๋ทฐ

CHALLENGE

[LOS] darkelf ํ’€์ด(6)

๐ŸŒง: 2020. 12. 5.

6๋ฒˆ์งธ ๋ฌธ์ œ " darkelf "์ž…๋‹ˆ๋‹ค. ORC ๋ ˆ๋ฒจ์—์„œ ์‹œ๊ฐ„์ด ์ข€ ์†Œ์š”๋˜์—ˆ์ง€๋งŒ ๊ทธ ์ดํ›„๋ฌธ์ œ๋Š” ๊ธˆ๋ฐฉ ํ•ด๊ฒฐ๋˜๋Š” ๋ฌธ์ œ๋“ค์ด ๋งŽ์Šต๋‹ˆ๋‹ค.ํ˜„์žฌ ์†Œ์Šค๋ฅผํ™•์ธํ•ด๋ณด๋ฉด ์ฟผ๋ฆฌ๋ฌธ์„ ๋ฐ›์•„ ์‹คํ–‰๋˜๋Š” ์ฝ”๋“œ๋Š” " $_GET [pw] ์ž…๋‹ˆ๋‹ค.

if(preg_match('/prob|_|\.|\(\)/i', $_GET[pw$_GET [pw])) exit("No Hack ~_~"); 
if(preg_match('/or|and/i', $_GET[pw$_GET [pw])) exit("HeHe"); 

 

๋‘ ๋ฒˆ์งธ ํ•„ํ„ฐ๋ง ๊ฒ€์ฆ์„ ๋ณด์‹œ๋ฉด ๋ฌธ์ž์—ด " or " ์™€ " and " ๊ตฌ๋ฌธ์„ ๊ฒ€์ฆํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด์•ผ ๋ฉ๋‹ˆ๋‹ค.

if($result ['id']'admin') solve("darkelf");

๋˜ํ•œ ํ•ด๋‹น๋ถ€๋ถ„์„ ๋ณด์‹œ๋ฉด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด ๊ธฐ์กด์˜ " Guest " ๊ณ„์ •์ด ์•„๋‹Œ " admin " ๊ณ„์ •์œผ๋กœ ์ ‘๊ทผํ•ด์•ผ ๋ฉ๋‹ˆ๋‹ค.

 

" or " ๊ตฌ๋ฌธ์„ ์ด์šฉํ•ด์„œ " admin "์„  ํ†ตํ•ด ์ฐธ๊ฐ’์„ ๋งŒ๋“ค์–ด์ฃผ๋ฉด ๋˜์ง€๋งŒ ๋ฌธ์ž์—ด ๊ฒ€์ฆ์„ ํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ๋Œ€์ฒด ๋ฌธ์ž๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์ฃผ์„์ฒ˜๋ฆฌ(#)๋ฅผ ํ•ด์„œ ํ•ด๋‹น ๊ตฌ๋ฌธ๋งŒ ์ธ์‹ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ฃผ๋ฉด ์šฐํšŒ๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

OR ์šฐํšŒ -> ||
AND ์šฐํšŒ -> &&(%26%26)

'CHALLENGE' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[LOS] ORGE ํ’€์ด(7)  (0) 2020.12.06
XSS Challenges 3  (0) 2020.12.05
[LOS] wolfman ํ’€์ด(5)  (0) 2020.12.05
[LOS] ORC ํ’€์ด(4)  (0) 2020.12.05
[LOS] goblin ํ’€์ด(3)  (0) 2020.12.05
๊ณต์œ ํ•˜๊ธฐ ๋งํฌ
Comment