Recent posts

(bWAPP)XML/XPath Injection (Login Form)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ๋กœ๊ทธ์ธ ํผ์ด ๊ตฌํ˜„๋˜์–ด ์žˆ๋‹ค. ํ•ด๋‹น ๋กœ๊ทธ์ธ ๊ธฐ๋Šฅ์„ XML ์„ ํ†ตํ•ด ์ด๋ฃจ์–ด์ง€๋Š” ๋“ฏ ํ•˜๋‹ค. โ€™ (์‹ฑ๊ธ€์ฟผํ„ฐ) ์ž…๋ ฅ์‹œ ํŽ˜์ด์ง€ ์ƒ๋‹จ์— XML Error๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒƒ์„ ...

(bWAPP)SQL Injection - Blind - Time-Based (SQLMap)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์„ ๋ฐ›์•„ ์˜ํ™” ์ œ๋ชฉ๊ณผ ๋งค์นญ๋˜๋Š” ๊ธฐ๋Šฅ์ธ ๋“ฏ ํ•˜๋‹ค. ๊ทธ์— ๋”ฐ๋ฅธ ๊ฒฐ๊ณผ๋Š” ์ด๋ฉ”์ผ๋กœ ์ „์†ก๋œ๋‹ค๋Š” ๋ฌธ๊ตฌ๊ฐ€ ํ•จ๊ป˜ ์ถœ๋ ฅ๋˜์–ด ์žˆ๋‹ค. ์—ฌ๋Ÿฌ ์ž…๋ ฅ๊ฐ’ ๋ฐ โ€˜(์‹ฑ๊ธ€์ฟผํ„ฐ)๋“ฑ์„ ์‚ฝ์ž…...

(bWAPP)SQL Injection - Stored (XML)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ํ•ด๋‹น Any bugs? ๋ฒ„ํŠผ์„ ํด๋ฆญํ•ด๋„ ์•„๋ฌด๋Ÿฐ ๋ณ€ํ™”๊ฐ€ ์ผ์–ด๋‚˜์ง€ ์•Š๋Š”๋‹ค. Burp Suite ๋ฅผ ํ†ตํ•ด ์š”์ฒญ๊ฐ’๊ณผ ์‘๋‹ต๊ฐ’ ํŒจํ‚ท์„ ์žก์•„ ํ™•ํ•ด๋ณด๋ฉด POST ํ˜•์‹์˜ XM...

(bWAPP)SQL Injection - Stored (User-Agent)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low HTTP ์š”์ฒญ ํ—ค๋”์˜ User-Agent ๊ฐ’์ด ํŽ˜์ด์ง€์ƒ์— ๋…ธ์ถœ๋˜๊ณ  ์žˆ๋‹ค. ์ถœ๋ ฅ๋˜๋Š” ๋ฌธ๊ตฌ๋ฅผ ๋ณด๋ฉด IP ์ฃผ์†Œ์™€ User-Agent ๋ฌธ์ž์—ด์„ ๊ฐ€์ง€๊ณ  ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋กœ๊ทธ์ธ๋œ๋‹ค....

(bWAPP)SQL Injection - Stored (SQLite)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ์ด์ „๊ณผ ๋™์ผํ•˜์ง€๋งŒ DBMS์˜ ์ข…๋ฅ˜๊ฐ€ SQLite์ด๋‹ค. ๊ณต๊ฒฉ ๋ฐฉ์‹์€ ๋™์ผํ•˜์ง€๋งŒ ๋ฌธ๋ฒ•์„ SQLite๋กœ ํ•˜๋ฉด ๋œ๋‹ค. users ๋ผ๋Š” ํ…Œ์ด๋ธ” ํ™•์ธ test',(s...