Recent posts

(bWAPP)XML External Entity Attacks (XXE)

์ทจ์•ฝ์  ์„ค๋ช… ์›น ์–ดํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ๋ธŒ๋ผ์šฐ์ €์™€ ์„œ๋ฒ„๊ฐ„์— ๋ฐ์ดํ„ฐ ์ „๋‹ฌ์‹œ XML์„ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ XML ํŒŒ์„œ์˜ ์ž˜๋ชป๋œ ํŒŒ์‹ฑ๋ฐฉ์‹์œผ๋กœ ์ธํ•ด ์™ธ๋ถ€ ์—”ํ„ฐํ‹ฐ๋ฅผ ์ฐธ์กฐํ•˜๊ฒŒ๋  ๊ฒฝ์šฐ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์ด๋‹ค. ํ•ด๋‹น ์ทจ์•ฝ์ ์€ XML ํŒŒ์„œ๊ฐ€ ์œ„์น˜ํ•œ๊ณณ์œผ๋กœ ๋ถ€ํ„ฐ ๊ณต๊ฒฉ์ด ์ด๋ฃจ์–ด์ง€๊ธฐ ๋•Œ๋ฌธ์— SSRF, RCE๋“ฑ...

(bWAPP)Server Side Request Forgery (SSRF)

์ทจ์•ฝ์  ์„ค๋ช… SSRF๋Š” ํด๋ผ์ด์–ธํŠธ์ธก์˜ ์ž…๋ ฅ๊ฐ’์„ ์œ„์กฐ์‹œ์ผœ ์œ„์กฐ๋œ HTTP ์š”์ฒญ์„ ๋ณด๋‚ด, ์ผ๋ฐ˜์ ์œผ๋กœ ์™ธ๋ถ€์—์„œ ์ ‘๊ทผ์ด ๋ถˆ๊ฐ€๋Šฅํ•œ ์„œ๋ฒ„ ๋‚ด๋ถ€๋ง์— ์ ‘๊ทผ(Access) ํ•˜์—ฌ, ๋ฐ์ดํ„ฐ ์œ ์ถœ ๋ฐ ์„œ๋ฒ„์˜ ๊ธฐ๋ฐ€์„ฑ, ๊ฐ€์šฉ์„ฑ, ๋ฌด๊ฒฐ์„ฑ์„ ํŒŒ๊ดดํ•œ๋‹ค. SSRF ์˜ ๊ฒฝ์šฐ CSRF ๊ณต๊ฒฉ๊ณผ ์œ ์‚ฌํ•˜์ง€๋งŒ, ๊ณต๊ฒฉ์ด...

(bWAPP)SQLiteManager Local File Inclusion

์ทจ์•ฝ์  ์„ค๋ช… LFI๋Š” ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ File์„ ๋ถˆ๋Ÿฌ์˜ฌ ๋•Œ include๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ฝ”๋“œ ๋‚ด์— Bulit ํ•˜๊ฑฐ๋‚˜ ๋™์ ์œผ๋กœ ํŒŒ์ผ์„ ํฌํ•จํ•˜๋Š” ๋กœ์ง์ด ๊ตฌํ˜„๋˜์–ด ์žˆ์„ ๊ฒฝ์šฐ ์ผ๋ฐ˜์ ์œผ๋กœ ๋‚˜ํƒ€ ๋‚˜๋ฉฐ, LFI๋Š” ๋กœ์ปฌ ์‹œ์Šคํ…œ์˜ ํŒŒ์ผ์„ ๋ถˆ๋Ÿฌ์˜ฌ ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์ด๋‹ค. SQLiteMan...

(bWAPP)Restrict Folder Access

์ทจ์•ฝ์  ์„ค๋ช… Restrict Folder Access ์ทจ์•ฝ์ ์€ ํŠน์ • ํด๋”๋‚˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ œํ•œํ•˜๋Š” ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์—์„œ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ ์„ ์˜๋ฏธํ•œ๋‹ค. ๋‹ค์–‘ํ•œ ํŒŒ์ผ๋“ค์ด ์กด์žฌํ•˜๋ฉฐ, ๊ถŒํ•œ์ด ์žˆ์–ด์•ผ๋งŒ ๋ฌธ์„œ ํด๋”์— ์•ก์„ธ์Šค ํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค. ์ฆ‰ /bWA...

(bWAPP)Restrict Device Access

์ทจ์•ฝ์  ์„ค๋ช… Restrict Device Access ์ทจ์•ฝ์ ์€ ๋””์ง€ํ„ธ ๊ธฐ๊ธฐ์™€ ์‹œ์Šคํ…œ์—์„œ ํŠน์ • ๋””๋ฐ”์ด์Šค๋‚˜ ๋„คํŠธ์›Œํฌ ๋ฆฌ์†Œ์Šค์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ์ œํ•œํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์— ์กด์žฌํ•˜๋Š” ์ทจ์•ฝ์ ์„ ์˜๋ฏธํ•œ๋‹ค. ์ผ๋ถ€ ์ธ์ฆ๋œ ๋””๋ฐ”์ด์Šค๋งŒ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํ˜„์žฌ ์ ‘๊ทผ ๋งค์ฒด๋Š” ์Šค...