Recent posts

(bWAPP)Restrict Device Access

์ทจ์•ฝ์  ์„ค๋ช… Restrict Device Access ์ทจ์•ฝ์ ์€ ๋””์ง€ํ„ธ ๊ธฐ๊ธฐ์™€ ์‹œ์Šคํ…œ์—์„œ ํŠน์ • ๋””๋ฐ”์ด์Šค๋‚˜ ๋„คํŠธ์›Œํฌ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ์ œํ•œํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์— ์กด์žฌํ•˜๋Š” ์ทจ์•ฝ์ ์„ ์˜๋ฏธํ•œ๋‹ค. ์ผ๋ถ€ ์ธ์ฆ๋œ ๋””๋ฐ”์ด์Šค๋งŒ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํ˜„์žฌ ์ ‘๊ทผ ๋งค์ฒด๋Š” ์Šค...

(bWAPP)Remote & Local File Inclusion (RFI/LFI)

์ทจ์•ฝ์  ์„ค๋ช… ํ•ด๋‹น ์ทจ์•ฝ์ ์€ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ File์„ ๋ถˆ๋Ÿฌ ์˜ฌ ๋•Œ include๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ฝ”๋“œ๋‚ด์— Built ํ•˜๊ฑฐ๋‚˜ ๋™์ ์œผ๋กœ ํŒŒ์ผ์„ ํฌํ•จํ•˜๋Š” ๋กœ์ง์ด ๊ตฌํ˜„๋˜์–ด์žˆ์„๊ฒฝ์šฐ ์ผ๋ฐ˜์ ์œผ๋กœ ๋‚˜ํƒ€๋‚˜๋ฉฐ, ๋‹ค๋ฅธ Path Traversal ๊ณผ ๊ฐ™์€ ํƒ€ ์ทจ์•ฝ์ €๋ฏˆ๊ณผ ์—ฐ๊ณ„๋  ์ˆ˜ ์žˆ๋‹ค. ์ด๋Ÿฌํ•œ Fil...

Server Side Template Injection (SSTI)

SSTI๋ž€ ๋ฌด์—‡์ธ๊ฐ€? ์›น ํ…œํ”Œ๋ฆฟ ์—”์ง„์„ ์‚ฌ์šฉํ•˜๋Š” ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ์ผ์–ด๋‚˜๋Š” ์ทจ์•ฝ์ ์œผ๋กœ, ์›น ์„œ๋ฒ„์ธก์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์›น ํ…œํ”Œ๋ฆฟ ์—”์ง„์€ ๋‹ค์–‘ํ•˜๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์›น ํ…œํ”Œ๋ฆฟ ์—”์ง„ ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•˜์—ฌ, ์›น ์„œ๋ฒ„์ธก์— ํŽ˜์ด๋กœ๋“œ๋ฅผ ์‚ฝ์ž…ํ•  ์ˆ˜ ์žˆ๋‹ค. SSTI ์ทจ์•ฝ์ ์€ ๋‚˜์•„๊ฐ€ RCE, SSRF ๋“ฑ์œผ๋กœ...

Command Injection (OS Injection)

Command Injection์ด๋ž€? Command Injection์ด๋ž€ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์„ ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ๋ฐ›์•„ ์„œ๋ฒ„์ธก ๋ฐฑ์—”๋“œ์—์„œ ์šด์˜์ฒด์ œ ๋ช…๋ น์œผ๋กœ ์ „๋‹ฌ๋˜์–ด ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๊ณ  ๋‹ค์‹œ ๋ฐ˜ํ™˜๋  ๋•Œ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์œผ๋กœ ํ•ด๋‹น ์ทจ์•ฝ์ ์ด ์กฐ์žฌํ•  ๊ฒฝ ์šฐ ๋Œ€์ƒ ์„œ๋ฒ„๋ฅผ ์™„์ „ํžˆ ์ œ์–ด ๋ฐ ๋ฌด๋ ฅํ™” ํ•  ์ˆ˜...

(bWAPP)Host Header Attack (Cache Poisoning)

์ทจ์•ฝ์  ์„ค๋ช… ํ•ด๋‹น ์ทจ์•ฝ์ ์€ ์›น ์„œ๋ฒ„๊ฐ€ HTTP์š”์ฒญ ํ—ค๋”์ธ host ํ—ค๋”๋ฅผ ์ „์ ์œผ๋กœ ์‹ ๋ขฐํ•˜๊ณ  ์žˆ์„ ๊ฒฝ์šฐ ๋ฐœ์ƒํ•˜๋ฉฐ, ์ผ๋ฐ˜์ ์œผ๋กœ ์›น ์„œ๋ฒ„๋Š” ์š”์ฒญ์ด ๋„์ฐฉํ•œ ํ˜ธ์ŠคํŠธ๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด hostํ—ค๋”๋ฅผ ์‚ฌ์šฉํ•˜์ง€๋งŒ ์ด๋ฅผ ์กฐ์ž‘ํ•  ๊ฒฝ์šฐ ์•…์˜์ ์ธ ์‚ฌ์ดํŠธ๋กœ์˜ ์ด๋™์„ ์šฐ๋„ํ•  ์ˆ˜ ์žˆ๋‹ค. ํ™”๋ฉด์—...