Recent posts

(bWAPP)Session Mgmt. - Strong Sessions

Level - Low ์ด์ „ ์‹œ๋‚˜๋ฆฌ์˜ค์˜ ๋‚ด์šฉ๋“ค์„ ํ•ฉ์นœ ์‹œ๋‚˜๋ฆฌ์˜ค๋ผ๊ณ  ๋ณผ ์ˆ˜ ์žˆ๋‹ค. ๊ฐ๊ฐ์˜ Level ๋งˆ๋‹ค ์ ์  ๊ฐ•ํ•œ ์„ธ์…˜๊ด€๋ฆฌ๋ฅผ ํ†ตํ•œ ์„ธ์…˜ ์ฒ˜๋ฆฌ๊ฐ€ ์ด๋ฃจ์–ด์ง€๋Š” ๋“ฏ ํ•˜๋‹ค. Low Level ์˜ ๊ฒฝ์šฐ ์ด์ „๊ณผ ๋™์ผํ•˜๊ฒŒ ํƒˆ์ทจํ•œ ์„ธ์…˜์„ ํ†ตํ•œ ๋ณ€์กฐ ํ›„ ํ•ด๋‹น ํŽ˜์ด์ง€ ์ ‘๊ทผ์‹œ์ •์ƒ์ ...

(bWAPP)Session Mgmt. - Session ID in URL

Level - Low (Mideum & Haigh ์‹œ๋‚˜๋ฆฌ์˜ค ์—†์Œ) ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค์—์„œ๋Š” ์‚ฌ์šฉ์ž์˜ ์„ธ์…˜ ๊ฐ’์ด URI์— ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜์–ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์„ ๋‹ค๋ฃฌ ์‹œ๋‚˜๋ฆฌ์˜ค์ด๋‹ค. ๊ทธ๋ฆผ 1-2์™€ ๊ฐ™์ด URI ์˜ PHPSESSID ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋™ํ•ด GET ํ˜•์‹์œผ๋กœ ...

(bWAPP)Broken Auth. - Password Attacks

Level - Low ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์ด ๊ตฌํ˜„๋˜์–ด ์žˆ์œผ๋ฉฐ, ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค๋Š” ๋ถ€๋ฅดํŠธํฌ์Šค ๋ฐ ์‚ฌ์ „๋Œ€์ž…๊ณต๊ฒฉ์„ ์‚ฌ์šฉํ•˜๋Š” ์‹œ๋‚˜๋ฆฌ์˜ค์ธ๋“ฏ ํ•จ ๋กœ๊ทธ์ธ ์‹คํŒจ์‹œ ์œ„ ๊ทธ๋ฆผ1-2์™€ ๊ฐ™์€ ๋ฌธ์ž๊ฐ€ ์ถœ๋ ฅ๋จ ๋กœ๊ทธ์ธ ์‹œ์ ์—์„œ Intercept ๋ฅผ ํ†ตํ•ด ํŒจํ‚ท์„ ์žก์€ ํ›„ Intruder...

(bWAPP)Broken Auth. - Logout Management

Level - Low ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์•„์›ƒ ๊ธฐ๋Šฅ์ด ๊ตฌํ˜„๋˜์–ด ์žˆ์Œ ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค์˜ ๊ฒฝ์šฐ โ€œ๋’ค๋กœ๊ฐ€๊ธฐโ€ ๊ธฐ๋Šฅ์„ ํ†ตํ•ด ์ด์ „ ์‚ฌ์šฉ์ž์˜ ์„ธ์…˜์„ ๊ฐ€์ง€๊ณ  ๋‹ค์‹œ๊ธˆ ๋กœ๊ทธ์ธ ์ƒํƒœ๋กœ ๋Œ์•„๊ฐˆ ์ˆ˜ ์žˆ์Œ. ์„ฑ๊ณต์ ์œผ๋กœ ๋กœ๊ทธ ์•„์›ƒ๋˜์–ด BWAPP ์ดˆ๊ธฐ ํ™”๋ฉด์œผ๋กœ ๋Œ์•„์™”๋‹ค. โ€œ๋’ค๋กœ๊ฐ€๊ธฐโ€...