Jastes 2022. 4. 7. 20:30
 

2๋‹จ๊ณ„ : command-injection-1

์ด ๋ฌธ์ œ์— ๋Œ€ํ•˜์—ฌ ํ’€์–ด๋ด…์‹œ๋‹ค!!
ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ํ•˜์‹œ๊ณ  ์‹œ์ž‘ํ•ด์š”

Code!

์ž ์ฝ”๋“œ ํ™•์ธ๊นŒ์ง€ ํ–ˆ์ฃ  ๋นจ๊ฐ„์ƒ‰์œผ๋กœ ํ‘œ์‹œํ•œ ๋ถ€๋ถ„์ด ํ•ต์‹ฌ์ด์ฃ 

cmd = f๋ถ€๋ถ„์—์„œ ๋ฐ”๋กœ ๋ฌธ์ž์—ด ํƒ€์ž…์œผ๋กœ ๋ฐ›์•„๋“œ๋ ค cmd๋ฅผ ์‹คํ–‰ํ•˜๋Š” cmd injection ๊ณต๊ฒฉํ•˜๋ผ๋Š” ๊ฑฐ์ฃ 

์—ญ์‹œ๋‚˜ ์ •๊ทœํ‘œํ˜„์‹์œผ๋กœ ๋ธ”๋ž™๋ฆฌ์ŠคํŠธ๊ฐ€ ์žˆ๊ตฐ์š”

์—ญ์‹œ ๊ทœ์•ฝ์ด ์–ด๋А์ •๋„ ์ •ํ•ด์ง„ ๋ชจ์Šต์ด์˜ˆ์š” ๋งž๊ฒŒ ํ•ด์•ผ๊ฒ ์ฃ  ์•„๊นŒ ๋ฌธ์ž์—ด๋กœ ๋ฐ›๋Š”๋‹ค๊ณ  ํ–ˆ์œผ๋‹ˆ๊นŒ์ € ํŒจํ„ด๋งŒ ๋ถ„์„ํ•˜๋ฉด ์‰ฝ๊ฒŒ ๋”ธ ์ˆ˜ ์žˆ๊ฒ ์ฃ 

[A-Za-z0-9.]{5,20} ์ •๊ทœ์‹ ๋ถ„์„
๐Ÿ’ก"[A-Za-z0-9.]{5,20}"์€ ๊ฐ„๋‹จํ•˜๊ฒŒ ํ•ด์„ํ•˜์ž๋ฉด ์†Œ๋ฌธ์ž๋ถ€ํ„ฐ ๋Œ€๋ฌธ์ž๊นŒ์ง€ ์ „๋ถ€ ํ—ˆ์šฉ, ๊ณต๋ฐฑ X,
์ˆซ์ž๋Š” 0๋ถ€ํ„ฐ 9๊นŒ์ง€ ํ—ˆ์šฉ, .๋ฌธ์ž๋„ ํ—ˆ์šฉ(pingํ•˜๋Š” ์›น ์‚ฌ์ดํŠธ๋‹ˆ๊นŒ..) ๋งˆ์ง€๋ง‰์ธ ๋ฌธ์ž์—ด 5-20๊นŒ์ง€

์ •๊ทœ์‹ ํ‘œํ˜„ ๋ฐฉ์‹์„ ๋” ์ž์„ธํžˆ ์•Œ๋ ค์ค„๊ป˜์š” ๋‚˜์ค‘์—.. ๋” ์ž์„ธํžˆ ์ •๋ฆฌํ•ด์„œ ์˜ฌ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค ใ… 
๋ฐ‘์— ์‚ฌ์ดํŠธ๋Š” ์ •๊ทœ์‹ ํ‘œํ˜„ ์‰ฝ๊ฒŒ ๋„์™€์ฃผ๋Š” ์‚ฌ์ดํŠธ์ž…๋‹ˆ๋‹ค! ๊ฐ•์ถ”!!!
 

RegExr: Learn, Build, & Test RegEx

RegExr is an online tool to learn, build, & test Regular Expressions (RegEx / RegExp).

regexr.com

๊ทธ๋ ‡๋‹ค๋ฉด ๊ธˆ๋ฐฉ ๋‹ค ๊ตฌํ–ˆ์ฃ  Burp Suite๋กœ ๋”ฐ์„œ ํ™•์ธํ•ด๋ณด๋ฉด

8.8.8.8";"ls ๋ช…๋ น์–ด injection!

ํŒŒ์ผ์„ ๋ณด์—ฌ์ฃผ๋Š” ๋ถ€๋ถ„!

๊ทผ๋ฐ ์•„๊นŒ ์ •๊ทœํ‘œํ˜„์‹์—์„œ ๊ณต๋ฐฑ ์ ์šฉ X ์ด๋‹ˆ๊นŒ ๋ฌธ์ž์—ด์„ ๊ทธ๋ƒฅ ๋„ฃ์–ด์„œ ๊ณต๋ฐฑ์ฒ˜๋Ÿผ ๋งŒ๋“ ๋‹ค๋ฉด

8.8.8.8";"cat"+"flag.py ์œผ๋กœ ํ•ด๋„ ๋  ๋“ฏ

๊ทธ๋Ÿฌ๊ธฐ์— flag๊ฐ€ ๋‚˜์˜จ ๋ชจ์Šต์ด์ฃ ! ์ฐธ ์‰ฝ๋„ค์š” ใ…Žใ…Ž ๊ทผ๋ฐ ๋ง‰์ƒ ์›น์—์„œ ํ•˜๋ฉด ํ‘œํ˜„์‹ ์˜ค๋ฅ˜๊ฐ€ ์ƒ๊ธฐ๋˜๋ฐ..

๊ทธ๊ฑด ์™œ์ผ๊นŒ์š”? ๋ญ ์ผ๋‹จ ์—ฌ๊ธฐ๊นŒ์ง€!! flag = DH{pingpingppppppppping!!} ์ž…๋‹ˆ๋‹ค!


์ฐธ๊ณ  ์ž๋ฃŒ

 

command-injection-1

ํŠน์ • Host์— ping ํŒจํ‚ท์„ ๋ณด๋‚ด๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. Command Injection์„ ํ†ตํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.py์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking

dreamhack.io

์ฐธ๊ณ  ์ด๋ฏธ์ง€