Recent posts

(bWAPP)Session Mgmt. - Session ID in URL

Level - Low (Mideum & Haigh ์‹œ๋‚˜๋ฆฌ์˜ค ์—†์Œ) ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค์—์„œ๋Š” ์‚ฌ์šฉ์ž์˜ ์„ธ์…˜ ๊ฐ’์ด URI์— ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜์–ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์„ ๋‹ค๋ฃฌ ์‹œ๋‚˜๋ฆฌ์˜ค์ด๋‹ค. ๊ทธ๋ฆผ 1-2์™€ ๊ฐ™์ด URI ์˜ PHPSESSID ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋™ํ•ด GET ํ˜•์‹์œผ๋กœ ...

(bWAPP)Broken Auth. - Password Attacks

Level - Low ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์ด ๊ตฌํ˜„๋˜์–ด ์žˆ์œผ๋ฉฐ, ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค๋Š” ๋ถ€๋ฅดํŠธํฌ์Šค ๋ฐ ์‚ฌ์ „๋Œ€์ž…๊ณต๊ฒฉ์„ ์‚ฌ์šฉํ•˜๋Š” ์‹œ๋‚˜๋ฆฌ์˜ค์ธ๋“ฏ ํ•จ ๋กœ๊ทธ์ธ ์‹คํŒจ์‹œ ์œ„ ๊ทธ๋ฆผ1-2์™€ ๊ฐ™์€ ๋ฌธ์ž๊ฐ€ ์ถœ๋ ฅ๋จ ๋กœ๊ทธ์ธ ์‹œ์ ์—์„œ Intercept ๋ฅผ ํ†ตํ•ด ํŒจํ‚ท์„ ์žก์€ ํ›„ Intruder...

(bWAPP)Broken Auth. - Logout Management

Level - Low ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์•„์›ƒ ๊ธฐ๋Šฅ์ด ๊ตฌํ˜„๋˜์–ด ์žˆ์Œ ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค์˜ ๊ฒฝ์šฐ โ€œ๋’ค๋กœ๊ฐ€๊ธฐโ€ ๊ธฐ๋Šฅ์„ ํ†ตํ•ด ์ด์ „ ์‚ฌ์šฉ์ž์˜ ์„ธ์…˜์„ ๊ฐ€์ง€๊ณ  ๋‹ค์‹œ๊ธˆ ๋กœ๊ทธ์ธ ์ƒํƒœ๋กœ ๋Œ์•„๊ฐˆ ์ˆ˜ ์žˆ์Œ. ์„ฑ๊ณต์ ์œผ๋กœ ๋กœ๊ทธ ์•„์›ƒ๋˜์–ด BWAPP ์ดˆ๊ธฐ ํ™”๋ฉด์œผ๋กœ ๋Œ์•„์™”๋‹ค. โ€œ๋’ค๋กœ๊ฐ€๊ธฐโ€...

(bWAPP)Session Mgmt. - Cookies (Secure)

Level - Low ์ด์ „ ๋ฌธ์ œ์˜ Http Only ์™€ ๋ฌธ์ œ ์ž์ฒด๋Š” ๋™์ผํ•˜์ง€๋งŒ, Http Only ํ—ค๋”๊ฐ€ ์•„๋‹Œ Secure ํ—ค๋”์— ๋Œ€ํ•œ ํ•™์Šต์„ ์œ„ํ•œ ๋ฌธ์ œ์ด๋‹ค. Secure ํ—ค๋”๋ž€ SSL/TLS ์„ ์‚ฌ์šฉํ•œ HTTPS ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•ด ์ „์†ก๋˜๋Š” ์‘๋‹ต์—๋งŒ ์ฟ ํ‚ค๋ฅผ ํฌํ•จ...

(bWAPP)Session Mgmt. - Cookies (HTTPOnly)

Level - Low Cookies ๋ฒ„ํŠผ์„ ํด๋ฆญ์‹œ ์•„๋ž˜ ํ‘œ์— ์ฟ ํ‚ค ๊ฐ’์ด ์ถœ๋ ฅ ๋˜๋ฉฐ, here ๋ฒ„ํŠผ ํด๋ฆญ์‹œ alert ์ฐฝ์„ ํ†ตํ•ด ์ฟ ํ‚ค ๊ฐ’์ด ์ถœ๋ ฅ ๋œ๋‹ค. ์„ธ์…˜ ๊ฐ’๊ณผ ๊ฐ๊ฐ์˜ ์ฟ ํ‚ค๊ฐ’์„ ๋ณด์—ฌ์ค€๋‹ค. ํ•ด๋‹น ์‹œ๋‚˜๋ฆฌ์˜ค๋Š” ์„ธ์…˜๊ฐ’์„ ํƒˆ์ทจํ•˜๋Š” ์‹œ๋‚˜๋ฆฌ์˜ค๋กœ ์˜ˆ์ƒ๋˜๋ฉฐ, tes...