Recent posts

(bWAPP)Session Mgmt. - Administrative Portals

Level - Low ν•΄λ‹Ή νŽ˜μ΄μ§€μ— λŒ€ν•œ 접근이 κ±°λΆ€λ˜κ³  μžˆλ‹€. μ£Όμ–΄μ§€λŠ” νžŒνŠΈλ‘œλŠ” URL을 κ²€μ‚¬ν•˜λΌκ³  ν•œλ‹€. ν•΄λ‹Ή μ‹œλ‚˜λ¦¬μ˜€λŠ” 일반 μ‚¬μš©μžκ°€ κ΄€λ¦¬μž νŽ˜μ΄μ§€μ— μ ‘κ·Όν•  수 μžˆλŠ” μ·¨μ•½μ μœΌλ‘œ ν™•μΈλœλ‹€. https://192.168.146.133/bWAPP/smgmt_ad...

(bWAPP)XML/XPath Injection (Search)

검증 둜직 Low Level μ—μ„œλŠ” λ³΄μ•ˆ λŒ€μ±…μ΄ μ μš©λ˜μ–΄ μžˆμ§€ μ•Šλ‹€. Level - Low 검색 λͺ©λ‘μ΄ μ‘΄μž¬ν•˜λ©°, λͺ©λ‘μ„ μ„ νƒν•˜μ—¬ κ²€μƒ‰ν•˜λ©΄ κ΄€λ ¨λ„λ”˜ 값듀이 μˆœμ°¨λ³„λ‘œ λ‚˜μ˜€λŠ” 것을 μ•Œ 수 μžˆλ‹€. λ˜ν•œ 데이터 전솑 방식은 GET ν˜•μ‹μœΌλ‘œ μ „μ†‘λ˜λŠ” 것을 μ•Œ 수...

(bWAPP)XML/XPath Injection (Login Form)

검증 둜직 Low Level μ—μ„œλŠ” λ³΄μ•ˆ λŒ€μ±…μ΄ μ μš©λ˜μ–΄ μžˆμ§€ μ•Šλ‹€. Level - Low 둜그인 폼이 κ΅¬ν˜„λ˜μ–΄ μžˆλ‹€. ν•΄λ‹Ή 둜그인 κΈ°λŠ₯을 XML 을 톡해 μ΄λ£¨μ–΄μ§€λŠ” λ“― ν•˜λ‹€. ’ (μ‹±κΈ€μΏΌν„°) μž…λ ₯μ‹œ νŽ˜μ΄μ§€ 상단에 XML Errorκ°€ λ°œμƒν•˜λŠ” 것을 ...

(bWAPP)SQL Injection - Blind - Time-Based (SQLMap)

검증 둜직 Low Level μ—μ„œλŠ” λ³΄μ•ˆ λŒ€μ±…μ΄ μ μš©λ˜μ–΄ μžˆμ§€ μ•Šλ‹€. Level - Low μ‚¬μš©μžμ˜ μž…λ ₯값을 λ°›μ•„ μ˜ν™” 제λͺ©κ³Ό λ§€μΉ­λ˜λŠ” κΈ°λŠ₯인 λ“― ν•˜λ‹€. 그에 λ”°λ₯Έ κ²°κ³ΌλŠ” μ΄λ©”μΌλ‘œ μ „μ†‘λœλ‹€λŠ” 문ꡬ가 ν•¨κ»˜ 좜λ ₯λ˜μ–΄ μžˆλ‹€. μ—¬λŸ¬ μž…λ ₯κ°’ 및 β€˜(μ‹±κΈ€μΏΌν„°)등을 μ‚½μž…...

(bWAPP)SQL Injection - Stored (XML)

검증 둜직 Low Level μ—μ„œλŠ” λ³΄μ•ˆ λŒ€μ±…μ΄ μ μš©λ˜μ–΄ μžˆμ§€ μ•Šλ‹€. Level - Low ν•΄λ‹Ή Any bugs? λ²„νŠΌμ„ 클릭해도 μ•„λ¬΄λŸ° λ³€ν™”κ°€ μΌμ–΄λ‚˜μ§€ μ•ŠλŠ”λ‹€. Burp Suite λ₯Ό 톡해 μš”μ²­κ°’κ³Ό 응닡값 νŒ¨ν‚·μ„ μž‘μ•„ 확해보면 POST ν˜•μ‹μ˜ XM...