Recent posts

(bWAPP)SQLiteManager Local File Inclusion

์ทจ์•ฝ์  ์„ค๋ช… LFI๋Š” ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ File์„ ๋ถˆ๋Ÿฌ์˜ฌ ๋•Œ include๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ฝ”๋“œ ๋‚ด์— Bulit ํ•˜๊ฑฐ๋‚˜ ๋™์ ์œผ๋กœ ํŒŒ์ผ์„ ํฌํ•จํ•˜๋Š” ๋กœ์ง์ด ๊ตฌํ˜„๋˜์–ด ์žˆ์„ ๊ฒฝ์šฐ ์ผ๋ฐ˜์ ์œผ๋กœ ๋‚˜ํƒ€ ๋‚˜๋ฉฐ, LFI๋Š” ๋กœ์ปฌ ์‹œ์Šคํ…œ์˜ ํŒŒ์ผ์„ ๋ถˆ๋Ÿฌ์˜ฌ ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์ด๋‹ค. SQLiteMan...

(bWAPP)Restrict Folder Access

์ทจ์•ฝ์  ์„ค๋ช… Restrict Folder Access ์ทจ์•ฝ์ ์€ ํŠน์ • ํด๋”๋‚˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ œํ•œํ•˜๋Š” ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์—์„œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์„ ์˜๋ฏธํ•œ๋‹ค. ๋‹ค์–‘ํ•œ ํŒŒ์ผ๋“ค์ด ์กด์žฌํ•˜๋ฉฐ, ๊ถŒํ•œ์ด ์žˆ์–ด์•ผ๋งŒ ๋ฌธ์„œ ํด๋”์— ์•ก์„ธ์Šค ํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค. ์ฆ‰ /bWA...

(bWAPP)Restrict Device Access

์ทจ์•ฝ์  ์„ค๋ช… Restrict Device Access ์ทจ์•ฝ์ ์€ ๋””์ง€ํ„ธ ๊ธฐ๊ธฐ์™€ ์‹œ์Šคํ…œ์—์„œ ํŠน์ • ๋””๋ฐ”์ด์Šค๋‚˜ ๋„คํŠธ์›Œํฌ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ์ œํ•œํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์— ์กด์žฌํ•˜๋Š” ์ทจ์•ฝ์ ์„ ์˜๋ฏธํ•œ๋‹ค. ์ผ๋ถ€ ์ธ์ฆ๋œ ๋””๋ฐ”์ด์Šค๋งŒ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํ˜„์žฌ ์ ‘๊ทผ ๋งค์ฒด๋Š” ์Šค...

(bWAPP)Remote & Local File Inclusion (RFI/LFI)

์ทจ์•ฝ์  ์„ค๋ช… ํ•ด๋‹น ์ทจ์•ฝ์ ์€ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ File์„ ๋ถˆ๋Ÿฌ ์˜ฌ ๋•Œ include๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ฝ”๋“œ๋‚ด์— Built ํ•˜๊ฑฐ๋‚˜ ๋™์ ์œผ๋กœ ํŒŒ์ผ์„ ํฌํ•จํ•˜๋Š” ๋กœ์ง์ด ๊ตฌํ˜„๋˜์–ด์žˆ์„๊ฒฝ์šฐ ์ผ๋ฐ˜์ ์œผ๋กœ ๋‚˜ํƒ€๋‚˜๋ฉฐ, ๋‹ค๋ฅธ Path Traversal ๊ณผ ๊ฐ™์€ ํƒ€ ์ทจ์•ฝ์ €๋ฏˆ๊ณผ ์—ฐ๊ณ„๋  ์ˆ˜ ์žˆ๋‹ค. ์ด๋Ÿฌํ•œ Fil...

Server Side Template Injection (SSTI)

SSTI๋ž€ ๋ฌด์—‡์ธ๊ฐ€? ์›น ํ…œํ”Œ๋ฆฟ ์—”์ง„์„ ์‚ฌ์šฉํ•˜๋Š” ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ์ผ์–ด๋‚˜๋Š” ์ทจ์•ฝ์ ์œผ๋กœ, ์›น ์„œ๋ฒ„์ธก์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์›น ํ…œํ”Œ๋ฆฟ ์—”์ง„์€ ๋‹ค์–‘ํ•˜๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์›น ํ…œํ”Œ๋ฆฟ ์—”์ง„ ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•˜์—ฌ, ์›น ์„œ๋ฒ„์ธก์— ํŽ˜์ด๋กœ๋“œ๋ฅผ ์‚ฝ์ž…ํ•  ์ˆ˜ ์žˆ๋‹ค. SSTI ์ทจ์•ฝ์ ์€ ๋‚˜์•„๊ฐ€ RCE, SSRF ๋“ฑ์œผ๋กœ...