Recent posts

(bWAPP)Insecure DOR - Insecure DOR (Change Secret)

Level - Low ์ด์ „ xss ๋ฌธ์ œ์™€ ๋™์ผํ•˜๊ฒŒ ํŠน์ • ๊ณ„์ •์— ๋Œ€ํ•œ secret๊ฐ’์„ ๋ณ€๊ฒฝํ•˜๋Š” ๋ถ€๋ถ„์ด ์กด์žฌํ•œ๋‹ค. ํ•ด๋‹น ๋ฌธ์ œ๋Š” IDOR ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜๋Š” ๋ฌธ์ œ์ด๋‹ค. ์ˆ˜ํ‰์  ๊ถŒํ•œ ์ƒ์Šน ๋ฐ ๋ณ€๊ฒฝ์„ ํ†ตํ•ด ํƒ€์ธ์˜ secret ๊ฐ’์„ ๋ณ€๊ฒฝํ•˜๋Š” ๋“ฏ ํ•˜๋‹ค. test ๊ณ„์ •์œผ...

UltraTech - WriteUP

ํ•ด๋‹น ๋ฌธ์ œ๋Š” https://tryhackme.com/r/room/ultratech1 ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. UltraTech ์‹œ์Šคํ…œ ๋ชจ์˜ ์นจํˆฌ ์ˆ˜ํ–‰ ๋‚ด์šฉ ์ •๋ณด ์ˆ˜์ง‘ robots.txt ๋ฐ sitemap ๋ฐœ๊ฒฌ restAPI์‚ฌ์šฉ์„ ํ†ตํ•œ ์ˆจ๊ฒจ์ง„ ํŽ˜์ด์ง€ ๋ฐ Comma...

(bWAPP)phpMyAdmin BBCode Tag XSS

phpmyadmin ๋‚ด์— error.php ํŽ˜์ด์ง€์˜ BBcode์—์„œ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์ธ ๊ฑฐ ๊ฐ™๋‹ค. CVE-2010-4480 ์œผ๋กœ ๋ช…๋ช…๋˜์–ด์žˆ๋‹ค. ํ•ด๋‹น ์ทจ์•ฝ์ ์€ PhpMyAdmin 3.3.8.1 ํ˜น์€ 3.4.0-beta1 ์ด์ „ ๋ฒ„์ „์—์„œ ๋ฐœ์ƒํ•œ๋‹ค. BBc...

(bWAPP)Stored (User-Agent)

์‹œ๊ฐ„ ๋‚ ์งœ, ์‚ฌ์šฉ์ž์˜ ip, User-Agent ํ—ค๋”์˜ ๋ƒ‰์šฉ์ด ์ถœ๋ ฅ๋˜๋Š” ๊ฑธ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ์ด์ „ ๋ฌธ์ œ๋“ค๊ณผ ๋™์ผํ•˜๊ฒŒ ์š”์ฒญ ํ—ค๋”๋ฅผ ๋ณ€์กฐํ•˜๋ฉด ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋˜๋ฉฐ ์‚ฌ์šฉ์ž์˜ ์ ‘๊ทผ ์‹œ๊ฐ„, ip, User-Agent ๋“ฑ์˜ ๊ฐ’๋“ค์œผ ์„œ๋ฒ„์ธก ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ €์žฅ ํ›„ ๋ถˆ๋Ÿฌ์˜ฌ ๋•Œ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ...

(bWAPP)Stored (Cookies)

์ข‹์•„ํ•˜๋Š” ์˜์–ด๋ฅผ ์ถ”์ฒœํ•˜๋„๋ก ๋˜์–ด ์žˆ๋‹ค. /xss_stored_2.php?genre=action&form=like ๋”ฐ๋กœ ์ถœ๋ ฅ๋˜๋Š” ๋ฌธ์ž๋Š” ์—†์œผ๋ฉฐ Cookie ๊ฐ’์— ์ถ”๊ฐ€๋˜์–ด ์ „์†ก๋œ๋‹ค. ์ „์†ก๋  ๋•Œ GET ํ˜•์‹์œผ๋กœ ์ „์†ก๋˜๋ฉฐ GENRE ํŒŒ๋ผ๋ฏธํ„ฐ์™€ FORM ํŒŒ...