Recent posts

Weak Authorization mechanism

Weak Authorization mechanism ์ด๋ž€? ์ง์—ญํ•˜๋ฉด ์ทจ์•ฝํ•œ ์ธ์ฆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์œผ๋กœ, ๊ฐ๊ฐ์˜ ๊ธฐ๋Šฅ๋“ค์— ๋Œ€ํ•œ ์ •์ƒ์ ์ธ ์ธ์ฆ ์ ˆ์ฐจ๋ฅผ ์šฐํšŒํ•˜์—ฌ ๋น„์ •์ƒ์ ์ธ ๋ฐฉ๋ฒ•์œผ๋กœ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ทจ๋“ํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์ด๋‹ค. ์ฆ‰, ๋ชจ๋ฐ”์ผ ์•ฑ์˜ ๋ฐฑ์—”๋“œ ์„œ๋ฒ„์— ์„œ๋น„์Šค ์š”์ฒญ์„ ์ œ์ถœํ•˜์—ฌ, ์ธ์ฆ์„ ์œ„...

(bWAPP)Text Files (Accounts)

์ทจ์•ฝ์  ์„ค๋ช… ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค์˜ ์ทจ์•ฝ์ ์€ ํ‰๋ฌธ ๋ฐ sha-1๊ณผ ๊ฐ™์€ ์•ฝํ•œ ํ•ด์‹œ ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ํ†ตํ•œ ๋ฐ์ดํ„ฐ ์ „์†ก์‹œ ์ด๋ฅผ ํฌ๋ž™ํ•˜์—ฌ ์ „์†ก ๋ฐ์ดํ„ฐ ์œ ์ถœ์ด ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋œ๋‹ค. Low-Level ํ…์ŠคํŠธ ํŒŒ์ผ์— ๊ณ„์ •์„ ์ž…๋ ฅํ•˜๋Š” ๋“ฏํ•œ ๊ธฐ๋Šฅ์ด ์กด์žฌํ•œ๋‹ค. ๊ณ„์ • ์ •๋ณด ์ž…๋ ฅ์‹œ ํŒŒ์ผ์— ...

(bWAPP)POODLE Vulnerability

์ทจ์•ฝ์  ์„ค๋ช… POODLE ์ทจ์•ฝ์ ์€ SSL3.0์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์œผ๋กœ, ์ค‘๊ฐ„์ž ๊ณต๊ฒฉ์„ ํ†ตํ•ด ์•”ํ˜ธํ™”๋œ ํ†ต์‹ ์„ ํ•ด๋…ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ํ•ด๋‹น ์›น ์„œ๋ฒ„๋Š” POODLE ์ทจ์•ฝ์ ์ด ์กด์žฌ ํ•œ๋‹ค๊ณ  ํ•œ๋‹ค. nmap -p443 --script ssl-poodle -s...

(bWAPP)Host Header Attack (Reset Poisoning)

์ทจ์•ฝ์  ์„ค๋ช… Host Header Attack์˜ ๊ฒฝ์šฐ ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ํ˜ธ์ŠคํŠธ ํ—ค๋”๋ฅผ ์‹ ๋ขฐํ•˜๊ณ  ๊ฒ€์ฆํ•˜์ง€ ์•Š์„ ๋•Œ ๋ฐœ์ƒํ•˜๋ฉฐ, ํ˜ธ์ŠคํŠธ ํ—ค๋”๋Š” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์— ์š”์ฒญํ•˜๋Š” ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ๋‚˜ํƒ€๋‚ธ๋‹ค. ์ด๋กœ ์ธํ•ด, ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ ์œ ์ถœ, ์„ธ์…˜ ํ•˜์ด์žฌํ‚น, xss ๋“ฑ์˜ ๋ณด์•ˆ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•  ์ˆ˜...

(bWAPP)Heartbleed Vulnerability

์ทจ์•ฝ์  ์„ค๋ช… Heartbleed ์ทจ์•ฝ์ ์€ OpenSSL ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ๋ณด์•ˆ ์ทจ์•ฝ์ ์œผ๋กœ, OpenSSL์€ ๋งŽ์€ ์›น ์„œ๋ฒ„์—์„œ ใ……์šฉ๋˜๋Š” ์•”ํ˜ธํ™” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ด๋‹ค. ์ด๋Š” https๋ฅผ ๋น„๋กฏ ๋‹ค์–‘ํ•œ ๋ณด์•ˆ ํ”„๋กœํ† ์ฝœ์„ ๊ตฌํ˜„ํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋œ๋‹ค. Heartbeat Extension ๋ผ๋Š” T...