Recent posts

(bWAPP)SQL Injection POST/Search

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ๊ฒŒ์‹œ๊ธ€์„ ์ถœ๋ ฅํ•˜๋Š” ๊ธฐ๋Šฅ์ด ์กด์žฌ ์ž…๋ ฅ๊ฐ’์€ POST ํ˜•์‹์œผ๋กœ ์ „๋‹ฌ๋จ โ€˜(์‹ฑ๊ธ€ ์ฟผํ„ฐ) ์ž…๋ ฅ์‹œ DBMS Error๊ฐ€ ์ถœ๋ ฅ๋จ Proxy Tool์„ ์‚ฌ์šฉํ•˜์—ฌ ์ž…๋ ฅ...

(bWAPP)SQL Injection (Login Form/User)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low Login Form์ด ์กด์žฌ โ€˜(์‹ฑ๊ธ€ ์ฟผํ„ฐ) ์ž…๋ ฅ์‹œ DBMS Error๊ฐ€ ๋ฐœ์ƒ Error ์€ ๋ฐœ์ƒํ•˜์˜€์œผ๋‚˜, ์ผ๋ฐ˜์ ์ธ ์šฐํšŒ๋Š” ๋˜์ง€ ์•Š์Œ. ๊ฒ€์ฆ ๋กœ์ง 1...

(bWAPP)SQL Injection (Login Form/Hero)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ์ผ๋ฐ˜์ ์ธ Login Form์ด ์กด์žฌํ•œ๋‹ค. โ€˜(์‹ฑ๊ธ€ ์ฟผํ„ฐ) ์ž…๋ ฅ์„ ํ†ตํ•œ DBMS Error ์œ /๋ฌด ํ™•์ธ์‹œ Error ๋ฐœ์ƒ ์ผ๋ฐ˜์ ์ธ โ€˜ or 1=1โ€“ ์™€ ๊ฐ™์€...

(bWAPP)SQL Injection - Blind (SQLite) (SQLMap)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ์•ž์„œ ์‹ค์Šตํ•œ ์ผ๋ฐ˜์ ์ธ Boolean Based SQLI ์ด๋‹ค. ํ•˜์ง€๋งŒ DBMS๊ฐ€ SQLIte ๋ผ๋Š” ์ ์„ ์œ ์˜ํ•ด์•ผํ•œ๋‹ค. SQLIte์˜ ๊ฒฝ์šฐ ํƒ€ DBMS ์™€ ๋‹ค๋ฅธ SQL...

(bWAPP)SQL Injection (AJAX/JSON/jQuery)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ๊ฒ€์ƒ‰์ฐฝ์— ์ž„์˜์˜ ๋ฌธ์ž๋ฅผ ์ฃผ๊ณ  ์ „์†กํ•˜๋Š” ๋ฐฉ์‹์ด ์•„๋‹Œ ๋ฌธ์ž์—ด ์ž…๋ ฅ์‹œ ์ฆ‰์‹œ ๋ฐ˜์˜๋˜๋Š” AJAX ํ˜•ํƒœ์˜ ๊ฒ€์ƒ‰์ฐฝ์ด ์กด์žฌ Ajax๋Š” ๋น„๋™๊ธฐ์‹ javascript, X...