Recent posts

(bWAPP)XSS - Reflected (POST)

First name๊ณผ Last name ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ๋„˜์–ด๊ฐ€๋Š” ์‚ฌ์šฉ์ž ์ž…๋ ฅ๊ฐ’์ด GET ํ˜•์‹์ด ์•„๋‹Œ POST ํ˜•์‹์œผ๋กœ ๋„˜์–ด๊ฐ„๋‹ค. firstname=test&lastname=test&form=submit burp suite๋ฅผ ํ†ตํ•ด ์š”์ฒญ ํŒจํ‚ท์„ ํ™•์ธํ•ด๋ณด...

(bWAPP)XSS - Reflected (GET)

Level - Low ์‚ฌ์šฉ์ž์˜ ์„ฑ, ์ด๋ฆ„ ์ž…๋ ฅ๊ตฌ๊ฐ„์ด ์กด์žฌํ•˜๋ฉฐ, ์ž…๋ ฅ ๊ฐ’์€ URI ๋ฅผ ํ†ตํ•ด GET ํ˜•์‹์œผ๋กœ ์ „์†ก๋œ๋‹ค. /bWAPP/xss_get.php?firstname=test&lastname=name&form=submit ๊ทธ ํ›„ ์‚ฌ์šฉ์ž์˜ ์ž…...

(bWAPP)Broken Auth. - CAPTCHA Bypassing

Level - Low ์œ„ ๋‘ ์‚ฌ์ง„์„ ๋ณด๊ฒŒ๋˜๋ฉด ์ผ๋ฐ˜์ ์ธ ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์—์„œ CAPTCHA ๊ธฐ๋Šฅ์ด ์กด์žฌํ•˜๋Š” ๊ฑธ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด ๋•Œ ๋กœ๊ทธ์ธ ์„ฑ๊ณต ๋ฐ ์‹คํŒจ ์— ๋”ฐ๋ผ CAPTCHA์˜ ๋ฌธ์ž์—ด์€ ๋žœ๋คํ•œ ๋ฌธ์ž์—ด๋กœ ์ง€์†์ ์œผ๋กœ ๋ฐ”๋€Œ๊ฒŒ ๋œ๋‹ค. ์ด๋Ÿด ๊ฒฝ์šฐ BruteForce ๊ณต๊ฒฉ์ด...

(bWAPP)Session Mgmt. - Strong Sessions

Level - Low ์ด์ „ ์‹œ๋‚˜๋ฆฌ์˜ค์˜ ๋‚ด์šฉ๋“ค์„ ํ•ฉ์นœ ์‹œ๋‚˜๋ฆฌ์˜ค๋ผ๊ณ  ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ๊ฐ๊ฐ์˜ Level ๋งˆ๋‹ค ์ ์  ๊ฐ•ํ•œ ์„ธ์…˜๊ด€๋ฆฌ๋ฅผ ํ†ตํ•œ ์„ธ์…˜ ์ฒ˜๋ฆฌ๊ฐ€ ์ด๋ฃจ์–ด์ง€๋Š” ๋“ฏ ํ•˜๋‹ค. Low Level ์˜ ๊ฒฝ์šฐ ์ด์ „๊ณผ ๋™์ผํ•˜๊ฒŒ ํƒˆ์ทจํ•œ ์„ธ์…˜์„ ํ†ตํ•œ ๋ณ€์กฐ ํ›„ ํ•ด๋‹น ํŽ˜์ด์ง€ ์ ‘๊ทผ์‹œ์ •์ƒ์ ...