Recent posts

(bWAPP)SQL Injection - Stored (Blog)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์ด DB ์— ์ €์žฅ๋œ ํ›„ ๋ถˆ๋Ÿฌ์™€ ๋‹ค์‹œ๊ธˆ ์ถœ๋ ฅํ•˜๋Š” ๋“ฏ ํ•˜๋‹ค. ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์ด Entry์— ์ž…๋ ฅ๋˜๋Š” ๊ฑธ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋Ÿด ๊ฒฝ์šฐ ๋ณดํ†ต XSS ...

(bWAPP)SQL Injection - Blind - Boolean-Based (Python Code)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low โ€˜(์‹ฑ๊ธ€์ฟผํ„ฐ) ์ž…๋ ฅ์‹œ Error ๋Š” ๋ฐœ์ƒ ํ•˜์ง€๋งŒ DBMS Error ์™€ ๊ฐ™์ด ํŠน์ • ์ •๋ณด๋ฅผ ์ถœ๋ ฅํ•˜์ง€๋Š” ์•Š๋Š”๋‹ค. ์ž…๋ ฅ๊ฐ’์„ ์ฐธ์œผ๋กœ ๋งŒ๋“ค๋ฉด โ€œThe movie exist...

(bWAPP)Drupal SQL Injection (Drupageddon)

๊ฒ€์ฆ ๋กœ์ง Low Level ์—์„œ๋Š” ๋ณด์•ˆ ๋Œ€์ฑ…์ด ์ ์šฉ๋˜์–ด ์žˆ์ง€ ์•Š๋‹ค. Level - Low CVE-2014-3794๋Š” Dryupal 7์—์„œ ๋ฐœ๊ฒฌ๋œ SQL ์ธ์ ์…˜ ์ทจ์•ฝ์ ์œผ๋กœ, Drupal ์›น ์‚ฌ์ดํŠธ์˜ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์›๊ฒฉ์œผ๋กœ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋Š” views_qu...

unshadow

unshadow ๋ž€ ๋ฌด์—‡์ธ๊ฐ€? ์ผ๋ฐ˜์ ์ธ ๋ฆฌ๋ˆ…์Šค ์‹œ์Šคํ…œ ์ƒ์—์„œ passwd ํŒŒ์ผ๊ณผ shadowํŒŒ์ผ์„ ํ•ฉ์ณ์ค€๋‹ค. ์ด๋ฅผ ํ†ตํ•ด john๊ณผ ๊ฐ™์€ Password Cracking Tool์„ ํ†ตํ•œ Hash Cracking์ด ๊ฐ€๋Šฅํ•˜๋‹ค. ๊ธฐ๋ณธ์ ์ธ ์‚ฌ์šฉ ๋ฐฉ๋ฒ• unshadow /etc/p...

keepass2john

keepass2john๋ž€ ๋ฌด์—‡์ธ๊ฐ€? keePass ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํŒŒ์ผ(.kdbx)์„ John the Ripper๊ฐ€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ํ˜•์‹์œผ๋กœ ๋ณ€ํ™˜ํ•ด์ค€๋‹ค. ์ด๋ฅผ ํ†ตํ•ด Keepass ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์—์„œ ์ถ”์ถœํ•œ ํ•ด์‹œ๋ฅผ John the Ripper ๋กœ ์‚ฌ์šฉํ•˜์˜ ํ•˜์—ฌ Password Cra...