Recent posts

Command Injection (OS Injection)

Command Injection์ด๋ž€? Command Injection์ด๋ž€ ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์„ ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ๋ฐ›์•„ ์„œ๋ฒ„์ธก ๋ฐฑ์—”๋“œ์—์„œ ์šด์˜์ฒด์ œ ๋ช…๋ น์œผ๋กœ ์ „๋‹ฌ๋˜์–ด ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๊ณ  ๋‹ค์‹œ ๋ฐ˜ํ™˜๋  ๋•Œ ๋ฐœ์ƒํ•˜๋Š” ์ทจ์•ฝ์ ์œผ๋กœ ํ•ด๋‹น ์ทจ์•ฝ์ ์ด ์กฐ์žฌํ•  ๊ฒฝ ์šฐ ๋Œ€์ƒ ์„œ๋ฒ„๋ฅผ ์™„์ „ํžˆ ์ œ์–ด ๋ฐ ๋ฌด๋ ฅํ™” ํ•  ์ˆ˜...

(bWAPP)Host Header Attack (Cache Poisoning)

์ทจ์•ฝ์  ์„ค๋ช… ํ•ด๋‹น ์ทจ์•ฝ์ ์€ ์›น ์„œ๋ฒ„๊ฐ€ HTTP์š”์ฒญ ํ—ค๋”์ธ host ํ—ค๋”๋ฅผ ์ „์ ์œผ๋กœ ์‹ ๋ขฐํ•˜๊ณ  ์žˆ์„ ๊ฒฝ์šฐ ๋ฐœ์ƒํ•˜๋ฉฐ, ์ผ๋ฐ˜์ ์œผ๋กœ ์›น ์„œ๋ฒ„๋Š” ์š”์ฒญ์ด ๋„์ฐฉํ•œ ํ˜ธ์ŠคํŠธ๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด hostํ—ค๋”๋ฅผ ์‚ฌ์šฉํ•˜์ง€๋งŒ ์ด๋ฅผ ์กฐ์ž‘ํ•  ๊ฒฝ์šฐ ์•…์˜์ ์ธ ์‚ฌ์ดํŠธ๋กœ์˜ ์ด๋™์„ ์šฐ๋„ํ•  ์ˆ˜ ์žˆ๋‹ค. ํ™”๋ฉด์—...

(bWAPP)Directory Traversal - Files

์ทจ์•ฝ์  ์„ค๋ช… Directory Traversal ํ˜น์€ path traversal์€ ./(ํ˜„์žฌ ๋””๋ ‰ํ† ๋ฆฌ) ๋˜๋Š” ../(์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ด๋™)๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ๋ฌธ์ž๋“ค์ด ์ œ๋Œ€๋กœ ํ•„ํ„ฐ๋ง๋˜์ง€ ์•Š์•„ ํŒŒ์ผ ์‹œ์Šคํ…œ API๋กœ ์ „๋‹ฌ๋˜์–ด, ํ—ˆ์šฉ๋œ ๋””๋ ‰ํ† ๋ฆฌ๊ฐ€ ์•„๋‹Œ ์ˆจ๊ฒจ์ง„ ๋””๋ ‰ํ† ๋ฆฌ ๋ฐ ํŒŒ์ผ์— ๋Œ€ํ•œ ๋ฌด๋‹จ ...

(bWAPP)Directory Traversal - Directories

์ทจ์•ฝ์  ์„ค๋ช… Directory Traversal ํ˜น์€ path traversal์€ ./(ํ˜„์žฌ ๋””๋ ‰ํ† ๋ฆฌ) ๋˜๋Š” ../(์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ด๋™)๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ๋ฌธ์ž๋“ค์ด ์ œ๋Œ€๋กœ ํ•„ํ„ฐ๋ง๋˜์ง€ ์•Š์•„ ํŒŒ์ผ ์‹œ์Šคํ…œ API๋กœ ์ „๋‹ฌ๋˜์–ด, ํ—ˆ์šฉ๋œ ๋””๋ ‰ํ† ๋ฆฌ๊ฐ€ ์•„๋‹Œ ์ˆจ๊ฒจ์ง„ ๋””๋ ‰ํ† ๋ฆฌ ๋ฐ ํŒŒ์ผ์— ๋Œ€ํ•œ ๋ฌด๋‹จ ...

Path Traversal

Path Traversal ์ด๋ž€ ๋ฌด์—‡์ธ๊ฐ€? ./(ํ˜„์žฌ ๋””๋ ‰ํ† ๋ฆฌ) ๋˜๋Š” ../(์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ด๋™)๋ฅผ ๋‚˜ํƒ€๋‚ด๋Š” ๋ฌธ์ž๋“ค์ด ์ œ๋Œ€๋กœ ํ•„ํ„ฐ๋ง๋˜์ง€ ์•Š์•„ ํŒŒ์ผ ์‹œ์Šคํ…œ API๋กœ ์ „๋‹ฌ๋˜์–ด, ํ—ˆ์šฉ๋œ ๋””๋ ‰ํ† ๋ฆฌ๊ฐ€ ์•„๋‹Œ ์ˆจ๊ฒจ์ง„ ๋””๋ ‰ํ† ๋ฆฌ ๋ฐ ํŒŒ์ผ์— ๋Œ€ํ•œ ๋ฌด๋‹จ access๋ฅผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋Š” ์ทจ์•ฝ์ ์ด๋ฉฐ...