๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ ๋ฉ”๋‰ด ๋ฐ”๋กœ๊ฐ€๊ธฐ
ABOUT

โ˜๏ธ Guleum LAB

sql injection giant (1)
ํ”„๋กœํ•„์‚ฌ์ง„
๐ŸŒง:
Guluem
๊ฒ€์ƒ‰ํ•˜๊ธฐ
  • ALL (109)
    • WEB (27)
    • MOBILE (23)
    • CLOUD (1)
    • CHALLENGE (43)
    • ETC (15)
ยซ   2025/05   ยป
์ผ ์›” ํ™” ์ˆ˜ ๋ชฉ ๊ธˆ ํ† 
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Tags
  • xss ๊ณต๊ฒฉ ์˜ˆ์ œ
  • rubiya sql injection
  • sudo.co.il xss
  • SQL INJECTION ๊ฒŒ์ž„
  • sql injection ๋ฌธ์ œ
  • xss ์šฐํšŒ
  • nopernik XSS
  • xss ๊ณต๊ฒฉ์ด๋ž€
  • xss ํ…Œ์ŠคํŠธ
  • XSS ๊ฒŒ์ž„
  • los ๋ฌธ์ œ
  • lord of sql injection
  • xss ์‹ค์Šต
  • xss ๋ž€
  • cross site scripting
more
[LOS] Giant ํ’€์ด(14)

14๋ฒˆ์งธ ๋ฌธ์ œ์ธ " giant "์ž…๋‹ˆ๋‹ค. if(strlen($_GET[shit])>1) exit("No Hack ~_~"); if(preg_match('/ |\n|\r|\t/i', $_GET[shit])) exit("HeHe"); ์ด๋ฒˆ์—๋Š” id ๋‚˜ pw ๋ณ€์ˆ˜๊ฐ€ ์•„๋‹Œ shit ์ด๋ผ๋Š”๋ณ€์ˆ˜๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ๋˜๋ฉฐ ์ž…๋ ฅ๋˜๋Š” ๊ฐ’์˜ ๊ธธ์ด๋Š” 1๋ณด๋‹ค ๊ธธ๋ฉด " No Hack " ์ด๋ผ๋Š” ๋ฌธ๊ตฌ๋ฅผ ๋„์šฐ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ |\n|\r|\t/ ๋“ฑ ์—ฌ๋Ÿฌ ๊ณต๋ฐฑ ์šฐํšŒ ๊ธฐ๋ฒ•์„ ์ฐจ๋‹จํ•˜๊ณ  ์žˆ๊ธฐ์— ํ—ˆ์šฉ๊ฐ€๋Šฅํ•œ ๊ณต๋ฐฑ ๊ตฌ๋ฌธ์„ ์ฐพ์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค. $query = "select 1234 from{$_GET[shit]}prob_giant where 1"; if($result[1234]) solve("giant"); ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ์œ„ํ•ด์„  ๊ฒฐ๊ด๊ฐ’์— 1234 ๊ฐ€ ์ถœ๋ ฅ..

CHALLENGE
์ด์ „ 1 ๋‹ค์Œ

  • ๊ธ€์“ฐ๊ธฐ
  • ๊ด€๋ฆฌ
  • ํƒœ๊ทธ
Contact guleum.zone@gmail.com

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”