Recent posts

(bWAPP)Stored (User-Agent)

์‹œ๊ฐ„ ๋‚ ์งœ, ์‚ฌ์šฉ์ž์˜ ip, User-Agent ํ—ค๋”์˜ ๋ƒ‰์šฉ์ด ์ถœ๋ ฅ๋˜๋Š” ๊ฑธ ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ์ด์ „ ๋ฌธ์ œ๋“ค๊ณผ ๋™์ผํ•˜๊ฒŒ ์š”์ฒญ ํ—ค๋”๋ฅผ ๋ณ€์กฐํ•˜๋ฉด ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋˜๋ฉฐ ์‚ฌ์šฉ์ž์˜ ์ ‘๊ทผ ์‹œ๊ฐ„, ip, User-Agent ๋“ฑ์˜ ๊ฐ’๋“ค์œผ ์„œ๋ฒ„์ธก ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ €์žฅ ํ›„ ๋ถˆ๋Ÿฌ์˜ฌ ๋•Œ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ...

(bWAPP)Stored (Cookies)

์ข‹์•„ํ•˜๋Š” ์˜์–ด๋ฅผ ์ถ”์ฒœํ•˜๋„๋ก ๋˜์–ด ์žˆ๋‹ค. /xss_stored_2.php?genre=action&form=like ๋”ฐ๋กœ ์ถœ๋ ฅ๋˜๋Š” ๋ฌธ์ž๋Š” ์—†์œผ๋ฉฐ Cookie ๊ฐ’์— ์ถ”๊ฐ€๋˜์–ด ์ „์†ก๋œ๋‹ค. ์ „์†ก๋  ๋•Œ GET ํ˜•์‹์œผ๋กœ ์ „์†ก๋˜๋ฉฐ GENRE ํŒŒ๋ผ๋ฏธํ„ฐ์™€ FORM ํŒŒ...

(bWAPP)Stored (Change secret)

์‹œํฌ๋ฆฟ ๊ฐ’(ํŒจ์Šค์›Œ๋“œ ํžŒ๋“œ)๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ๋กœ์ง์ด ๊ตฌํ˜„๋˜์–ด ์žˆ๋Š” ๋“ฏ ํ•˜๋‹ค. ์ž…๋ ฅ๊ฐ’์„ ์ฃผ๊ณ  ๋ณ€๊ฒฝ์„ ํ•˜๋”๋ผ๋„ ์ž…๋ ฅ๊ฐ’์ด ํŽ˜์ด์ง€ ๋‚ด ํ˜น์€ ์‘๋‹ต๊ฐ’ ๋‚ด์— ์ถœ๋ ฅ๋˜์ง€๋Š” ์•Š๋Š”๋‹ค. ์œ„์™€ ๊ฐ™์ด ๋กœ๊ทธ์ธ ์‹คํŒจ์‹œ ํŒจ์Šค์›Œ๋“œ ํžŒํŠธ์— ๋Œ€ํ•œ secret ๊ฐ’์— test๋ฅผ ์ฃผ์—ˆ๋‹ค. ...

(bWAPP)Stored (Blog)

๊ธ€์“ฐ๊ธฐ ๊ธฐ๋Šฅ์ด ์กด์žฌํ•œ๋‹ค. ๋Œ€ํ‘œ์ ์ธ Stored XSS ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜๋Š” ์œ ํ˜•์ธ ๊ฒŒ์‹œ๊ธ€ ์œ ํ˜•์ด๋‹ค. ๊ธ€์„ ์“ฐ๋ฉด ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์€ ์„œ๋ฒ„ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ €์žฅ๋˜๊ณ  ๊ฒŒ์‹œ๊ธ€์„ ๋ณผ ๋–„ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ €์žฅ๋˜์–ด ์žˆ๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ๊ฐ€์ ธ์™€ ํŽ˜์ด์ง€ ์ƒ์— ์ถœ๋ ฅํ•˜๊ฒŒ ๋œ๋‹ค. ์ด ๋•Œ ์‚ฌ...

(bWAPP)SQLiteManager XSS

SQLite์˜ ๊ด€๋ฆฌ์ž ํŽ˜์ด์ง€์ธ main.php ๋ฐ index.php ์ทจ์•ฝ์ ์„ ์•…์šฉํ•œ xss์ทจ์•ฝ์ ์ด๋‹ค. CVE-2012-5105 ์œผ๋กœ ๋ช…๋ช…๋˜์–ด์žˆ๋‹ค. ํ•ด๋‹น ์ทจ์•ฝ์ ์€ SQLLiteManager 1.2.4 ์—์„œ ๋ฐœ์ƒํ•œ๋‹ค. SQLiteManager version ...