Recent posts

(bWAPP)POODLE Vulnerability

์ทจ์•ฝ์  ์„ค๋ช… POODLE ์ทจ์•ฝ์ ์€ SSL3.0์—์„œ ๋ฐœ๊ฒฌ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ ์œผ๋กœ, ์ค‘๊ฐ„์ž ๊ณต๊ฒฉ์„ ํ†ตํ•ด ์•”ํ˜ธํ™”๋œ ํ†ต์‹ ์„ ํ•ด๋…ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ํ•ด๋‹น ์›น ์„œ๋ฒ„๋Š” POODLE ์ทจ์•ฝ์ ์ด ์กด์žฌ ํ•œ๋‹ค๊ณ  ํ•œ๋‹ค. nmap -p443 --script ssl-poodle -s...

(bWAPP)Host Header Attack (Reset Poisoning)

์ทจ์•ฝ์  ์„ค๋ช… Host Header Attack์˜ ๊ฒฝ์šฐ ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ํ˜ธ์ŠคํŠธ ํ—ค๋”๋ฅผ ์‹ ๋ขฐํ•˜๊ณ  ๊ฒ€์ฆํ•˜์ง€ ์•Š์„ ๋•Œ ๋ฐœ์ƒํ•˜๋ฉฐ, ํ˜ธ์ŠคํŠธ ํ—ค๋”๋Š” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์— ์š”์ฒญํ•˜๋Š” ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ๋‚˜ํƒ€๋‚ธ๋‹ค. ์ด๋กœ ์ธํ•ด, ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ ์œ ์ถœ, ์„ธ์…˜ ํ•˜์ด์žฌํ‚น, xss ๋“ฑ์˜ ๋ณด์•ˆ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•  ์ˆ˜...

(bWAPP)Heartbleed Vulnerability

์ทจ์•ฝ์  ์„ค๋ช… Heartbleed ์ทจ์•ฝ์ ์€ OpenSSL ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ๋ณด์•ˆ ์ทจ์•ฝ์ ์œผ๋กœ, OpenSSL์€ ๋งŽ์€ ์›น ์„œ๋ฒ„์—์„œ ใ……์šฉ๋˜๋Š” ์•”ํ˜ธํ™” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ด๋‹ค. ์ด๋Š” https๋ฅผ ๋น„๋กฏ ๋‹ค์–‘ํ•œ ๋ณด์•ˆ ํ”„๋กœํ† ์ฝœ์„ ๊ตฌํ˜„ํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋œ๋‹ค. Heartbeat Extension ๋ผ๋Š” T...

(bWAPP)HTML5 Web Storage (Secret)

์ทจ์•ฝ์  ์„ค๋ช… HTML5 Web Storge๋Š” ์›น ๋ธŒ๋ผ์šฐ์ €์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ํด๋ผ์ด์–ธํŠธ ์ธก์— ์ €์žฅํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ์ˆ ์ด๋‹ค. ๋ณดํ†ต Web Storage๋Š” ๋กœ์ปฌ ์Šคํ† ๋ฆฌ์ง€์™€ ์„ธ์…˜ ์Šคํ† ๋ฆฌ์ง€๋ผ๋Š” ๋‘ ๊ฐœ์˜ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ด ์กด์žฌํ•˜๋ฉฐ, ๊ฐ๊ฐ ์˜๊ตฌ์ ์œผ๋กœ ์ €์žฅ๋˜๊ฑฐ๋‚˜ ์„ธ์…˜ ์ค‘์—๋งŒ ์œ ์ง€๋˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ œ๊ณตํ•œ๋‹ค. ์ด...

(bWAPP)Clear Text HTTP (Credentials)

์ทจ์•ฝ์  ์„ค๋ช… ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค์˜ ์ทจ์•ฝ์ ์€ HTTP ํ†ต์‹ ์„ ํ•˜๋Š” ๊ณผ์ •์—์„œ ์•”ํ˜ธํ™”๋˜์ง€ ์•Š์•„ ํ‰๋ฌธ์œผ๋กœ ์ „์†ก๋˜์–ด ์•…์˜์ ์ธ ์‚ฌ์šฉ์ž๊ฐ€ ์ค‘๊ฐ„์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ๋„์ฒญํ•  ์ˆ˜ ์žˆ๋Š” ์Šค๋‹ˆํ•‘ ์ทจ์•ฝ์ ์ด๋‹ค. Low-Level ์ผ๋ฐ˜์ ์ธ ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์ด ๊ตฌํ˜„๋˜์–ด ์žˆ๋‹ค. ํฌ์ƒ์ž PC์—์„œ bWA...