Recent posts

(bWAPP)SQL Injection - Stored (XML)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ํ•ด๋‹น Any bugs? ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ด๋„ ์•„๋ฌด๋Ÿฐ ๋ณ€ํ™”๊ฐ€ ์ผ์–ด๋‚˜์ง€ ์•Š๋Š”๋‹ค. Burp Suite ๋ฅผ ํ†ตํ•ด ์š”์ฒญ๊ฐ’๊ณผ ์‘๋‹ต๊ฐ’ ํŒจํ‚ท์„ ์žก์•„ ํ™•ํ•ด๋ณด๋ฉด POST ํ˜•์‹์˜ XM...

(bWAPP)SQL Injection - Stored (User-Agent)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low HTTP ์š”์ฒญ ํ—ค๋”์˜ User-Agent ๊ฐ’์ด ํŽ˜์ด์ง€์ƒ์— ๋…ธ์ถœ๋˜๊ณ  ์žˆ๋‹ค. ์ถœ๋ ฅ๋˜๋Š” ๋ฌธ๊ตฌ๋ฅผ ๋ณด๋ฉด IP ์ฃผ์†Œ์™€ User-Agent ๋ฌธ์ž์—ด์„ ๊ฐ€์ง€๊ณ  ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋กœ๊ทธ์ธ๋œ๋‹ค....

(bWAPP)SQL Injection - Stored (SQLite)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ์ด์ „๊ณผ ๋™์ผํ•˜์ง€๋งŒ DBMS์˜ ์ข…๋ฅ˜๊ฐ€ SQLite์ด๋‹ค. ๊ณต๊ฒฉ ๋ฐฉ์‹์€ ๋™์ผํ•˜์ง€๋งŒ ๋ฌธ๋ฒ•์„ SQLite๋กœ ํ•˜๋ฉด ๋œ๋‹ค. users ๋ผ๋Š” ํ…Œ์ด๋ธ” ํ™•์ธ test',(s...

(bWAPP)SQL Injection (SQLite)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low โ€˜(์‹ฑ๊ธ€ ์ฟผํ„ฐ) ์ž…๋ ฅ์‹œ Error ๋ฐœ์ƒ DBMS ์˜ ์ข…๋ฅ˜๊ฐ€ SQLite ์ด๋‹ค. union Based ๋กœ ๋ฐฉํ–ฅ์„ ์žก์•˜์œผ๋ฉฐ, ์ด์ „์˜ DBMS ๋“ค๊ณผ์˜ ๋ฌธ๋ฒ•์ด ์ƒ์ดํ•˜๋‹ค. ...

(bWAPP)SQL Injection POST/Search

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low Select ๊ธฐ๋Šฅ์„ ํ†ตํ•ด ํŠน์ • ๊ฐ’์„ ์ถ”์ถœํ•จ ์ž…๋ ฅ๊ฐ’์„ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ์•ˆ์ด ํŽ˜์ด์ง€์ƒ์— ์—†์–ด Proxy Tool์„ ์‚ฌ์šฉ ์ž…๋ ฅ๊ฐ’์€ POST ํ˜•์‹์œผ๋กœ ์ „์†ก m...