๐ŸŒ†โ”‚Web_Study/๐Ÿš โ”‚Lord_of_SQLInjection

๐ŸŒ†โ”‚Web_Study/๐Ÿš โ”‚Lord_of_SQLInjection

[LORD OF SQLINJECTION] orc

Write Up ์œ„ ๋ฌธ์ œ๋“ค์€ query๋ฌธ๊ณผ ํ•ด๋‹น ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์•Œ๋ ค์ค๋‹ˆ๋‹ค. ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ solve() ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰์‹œํ‚ค๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฌ๋Š” ํ˜•์‹์ž…๋‹ˆ๋‹ค. https://los.rubiya.kr/gate.php los.rubiya.kr ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ #Query_1 query execute if(preg_match('/prob|_|\.|\(\)/i', $_GET[pw])) exit("No Hack ~_~"); $query = "select id from prob_orc where id='admin' and pw='{$_GET[pw]}'"; echo "query : {$query} "; $result = @mysqli_fetch_array(mysqli_query($db,$query)); if($result['id'..

๐ŸŒ†โ”‚Web_Study/๐Ÿš โ”‚Lord_of_SQLInjection

[LORD OF SQLINJECTION] goblin

Write Up ์œ„ ๋ฌธ์ œ๋“ค์€ query๋ฌธ๊ณผ ํ•ด๋‹น ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์•Œ๋ ค์ค๋‹ˆ๋‹ค. ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ solve() ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰์‹œํ‚ค๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฌ๋Š” ํ˜•์‹์ž…๋‹ˆ๋‹ค. https://los.rubiya.kr/gate.php los.rubiya.kr ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ ... //change filtering pattern if(preg_match('/\'|\"|\`/i', $_GET[no])) exit("No Quotes ~_~"); //query import $query = "select id from prob_goblin where id='guest' and no={$_GET[no]}"; ... ํฌ๊ฒŒ ๋‹ฌ๋ผ์ง„ ๋ถ€๋ถ„์ด์ž ํ•ต์‹ฌ์ธ ๋ถ€๋ถ„์ž…๋‹ˆ๋‹ค. ' " ` ์„ ๋ง‰์•„๋ฒ„๋ฆฌ๊ณ  id=guest๋กœ ํƒ์ƒ‰ํ•˜๋‚˜, admin์œผ๋กœ ์šฐํšŒํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค. ํ•ต์‹ฌ์œผ๋กœ..

๐ŸŒ†โ”‚Web_Study/๐Ÿš โ”‚Lord_of_SQLInjection

[LORD OF SQLINJECTION] cobolt

Write Up ์œ„ ๋ฌธ์ œ๋“ค์€ query๋ฌธ๊ณผ ํ•ด๋‹น ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์•Œ๋ ค์ค๋‹ˆ๋‹ค. ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ solve() ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰์‹œํ‚ค๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฌ๋Š” ํ˜•์‹์ž…๋‹ˆ๋‹ค. ์ด์ „ gremlin ๋ฌธ์ œ์™€ ๋งค์šฐ ์œ ์‚ฌํ•˜๋„ค์š” https://los.rubiya.kr/gate.php los.rubiya.kr ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ ... #import point!! $query = "select id from prob_cobolt where id='{$_GET[id]}' and pw=md5('{$_GET[pw]}')"; ... if($result['id'] == 'admin') solve("cobolt"); elseif($result['id']) echo "Hello {$result['id']} You are not admin :("; ํฌ๊ฒŒ ๋‹ฌ๋ผ์ง„ ๋ถ€..

๐ŸŒ†โ”‚Web_Study/๐Ÿš โ”‚Lord_of_SQLInjection

[LORD OF SQLINJECTION]gremlin

Write Up ์ฒ˜์Œ์ด๋‹ˆ๊นŒ ์œ„ ๋ฌธ์ œ๋“ค์€ query๋ฌธ๊ณผ ํ•ด๋‹น ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์•Œ๋ ค์ค๋‹ˆ๋‹ค. ์ด๋ฅผ ์ด์šฉํ•˜์—ฌ solve() ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰์‹œํ‚ค๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฌ๋Š” ํ˜•์‹์ž…๋‹ˆ๋‹ค. https://los.rubiya.kr/gate.php los.rubiya.kr ์†Œ์Šค ์ฝ”๋“œ ๋ถ„์„ file setup ๋ถ€๋ถ„๊ณผ preg_match ๋ถ€๋ถ„์€ ๊ธฐ๋ณธ์ ์ธ php ๋ฌธ๋ฒ•์ด๋ฏ€๋กœ ์„ค๋ช…์„ ๋„˜์–ด๊ฐ€๊ณ  preg_match์˜ ๊ฒฝ์šฐ _, ., () ๋ถ€๋ถ„์„ ํ•„ํ„ฐ๋งํ•˜๋Š” ๋ชจ์Šต์ž…๋‹ˆ๋‹ค. ์ฐธ๊ณ ๋กœ ์ •๊ทœํ‘œํ˜„์‹์œผ๋กœ ์ •๋ฆฌํ•˜๋ฉฐ, ํ•ด์„์‚ฌ์ดํŠธ๋Š” ํ•˜๋‹จ์— ์žˆ์Šต๋‹ˆ๋‹ค. RegExr: Learn, Build, & Test RegEx RegExr is an online tool to learn, build, & test Regular Expressions (RegEx / RegExp). regex..

Jastes
'๐ŸŒ†โ”‚Web_Study/๐Ÿš โ”‚Lord_of_SQLInjection' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก