Recent posts

Authorization Header Bypass

ํ•ด๋‹น ์ทจ์•ฝ์ ์€ ๋ฌด์—‡์ธ๊ฐ€? HTTP Authorization ์š”์ฒญ ํ—ค๋”๋Š” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์˜ ์ž๊ฒฉ ์ฆ๋ช…์„ ์ œ๊ณตํ•˜๋Š”๋ฐ ์‚ฌ์šฉ๋œ๋‹ค. ์ฆ‰ ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ์˜ ๋ฆฌ๋กœ์Šค์— ๋Œ€ํ•œ ์ธ์ฆ์„ ํ•˜๋Š”๋ฐ ์ฃผ๋กœ ์‚ฌ์šฉ๋œ๋‹ค. ์„œ๋ฒ„์—์„œ 401 Unauthorized ์ƒํƒœ๋ฅผ WWW-Authenti...

(bWAPP)XSS - Reflected (AJAX/XML)

Level - Low ์˜ํ™” ๊ฒ€์ƒ‰๊ธฐ๋Šฅ์ด ์กด์žฌํ•œ๋‹ค. ์ด ๋–„ ๋ฐ์ดํ„ฐ์˜ ์š”์ฒญ๊ณผ ์‘๋‹ต์ด AJAX-XML ํ˜•์‹์œผ๋กœ ์ „๋‹ฌ๋˜๋Š” ๋“ฏ ํ•˜๋‹ค. HTTP/1.1 200 OK Date: Sun, 31 Mar 2024 12:58:47 GMT Server: Apache/2.2.8 (Ubunt...

(bWAPP)XSS - Reflected (POST)

First name๊ณผ Last name ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ๋„˜์–ด๊ฐ€๋Š” ์‚ฌ์šฉ์ž ์ž…๋ ฅ๊ฐ’์ด GET ํ˜•์‹์ด ์•„๋‹Œ POST ํ˜•์‹์œผ๋กœ ๋„˜์–ด๊ฐ„๋‹ค. firstname=test&lastname=test&form=submit burp suite๋ฅผ ํ†ตํ•ด ์š”์ฒญ ํŒจํ‚ท์„ ํ™•์ธํ•ด๋ณด...

(bWAPP)XSS - Reflected (GET)

Level - Low ์‚ฌ์šฉ์ž์˜ ์„ฑ, ์ด๋ฆ„ ์ž…๋ ฅ๊ตฌ๊ฐ„์ด ์กด์žฌํ•˜๋ฉฐ, ์ž…๋ ฅ ๊ฐ’์€ URI ๋ฅผ ํ†ตํ•ด GET ํ˜•์‹์œผ๋กœ ์ „์†ก๋œ๋‹ค. /bWAPP/xss_get.php?firstname=test&lastname=name&form=submit ๊ทธ ํ›„ ์‚ฌ์šฉ์ž์˜ ์ž…...

(bWAPP)Broken Auth. - CAPTCHA Bypassing

Level - Low ์œ„ ๋‘ ์‚ฌ์ง„์„ ๋ณด๊ฒŒ๋˜๋ฉด ์ผ๋ฐ˜์ ์ธ ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์—์„œ CAPTCHA ๊ธฐ๋Šฅ์ด ์กด์žฌํ•˜๋Š” ๊ฑธ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด ๋•Œ ๋กœ๊ทธ์ธ ์„ฑ๊ณต ๋ฐ ์‹คํŒจ ์— ๋”ฐ๋ผ CAPTCHA์˜ ๋ฌธ์ž์—ด์€ ๋žœ๋คํ•œ ๋ฌธ์ž์—ด๋กœ ์ง€์†์ ์œผ๋กœ ๋ฐ”๋€Œ๊ฒŒ ๋œ๋‹ค. ์ด๋Ÿด ๊ฒฝ์šฐ BruteForce ๊ณต๊ฒฉ์ด...