๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ณด์•ˆ/dreamhack6

[dreamhack] basic_exploitation_001 (pwnable) https://dreamhack.io/wargame/challenges/3/ basic_exploitation_001 Description ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(basicexploitation001)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ์„ ์ฝ์œผ์„ธ์š”. "flag" ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ dreamhack.io 1) ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์  -> 2) ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ ์ฝ๊ธฐ ์‚ฌ์‹ค Environment์— ๋Œ€ํ•œ ๋‚ด์šฉ์€ ๊ทธ๋ƒฅ ์•Œ๋ ค์ฃผ๋Š” ์ •๋ณด? ๊ฐ™์€ ๊ฑฐ๋ผ ์•„๋ฌด ์˜๋ฏธ ์—†๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ๋Š”๋ฐ ๋ฉ”๋ชจ๋ฆฌ ๋ณดํ˜ธ ๊ธฐ๋ฒ•์ด ์ ์šฉ๋˜์ง€ ์•Š์•˜๋‹ค๋Š” ๋‚˜๋ฆ„์˜ ์ •๋ณด๋ฅผ ์•Œ ์ˆ˜ ์žˆ๋‹ค ๊ทธ๋Ÿฌ๋‚˜ NX ๊ธฐ๋ฒ•์€ ์ ์šฉ๋˜์–ด ์žˆ๋‹ค https://kangsecu.tistory.com/138 ๋ฉ”๋ชจ๋ฆฌ .. 2021. 5. 31.
[dreamhack] basic_exploitation_000 (pwnable) basic_exploitation_000 (pwnable) 1) ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์  -> 2) ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด ์…€ ์ทจ๋“ -> 3) "flag" ํŒŒ์ผ ์ฝ๊ธฐ ๋‹ค๋ฅธ ํ•ดํ‚น ๋ถ„์•ผ์™€๋Š” ๋‹ค๋ฅด๊ฒŒ pwnable์€ ํ™˜๊ฒฝ ์…‹ํŒ… & ๋ฌธ์ œ๋ฅผ ํ‘ธ๋Š” ๋ฐ ๋ฐ˜๋‚˜์ ˆ์€ ์†Œ๋น„ํ•œ ๊ฒƒ ๊ฐ™๋‹ค 1) ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์  : ๋ณ€์ˆ˜ buf๋ฅผ 128byte(0x80)๋งŒํผ ํ• ๋‹นํ•œ ํ›„ ๋ณ€์ˆ˜ buf์˜ ์ฃผ์†Œ๋ฅผ ์ถœ๋ ฅํ•œ๋‹ค ๊ทธ ๋‹ค์Œ, buf์˜ ๊ณต๊ฐ„์€ 128byte์ธ๋ฐ, 141byte๋ฅผ ์ž…๋ ฅ๋ฐ›๋Š”๋‹ค-> ๋ฒ„ํผ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ ๋ฐœ์ƒ 2) ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด ์…€ ์ทจ๋“ : ์‰˜ ์ฝ”๋“œ ์ž‘์„ฑ ํ›„ python3 app.py ๋กœ ์‹คํ–‰ํ•ด ๋ณด๋‹ˆ pwn์ด ์ธ์‹์ด ์•ˆ๋˜์–ด์„œ pwntools, pip์„ ์„ค์น˜ํ–ˆ๋‹ค ์„ค์น˜ ์˜ค๋ฅ˜์™€ ์„ค์น˜ ๊ณผ์ •์€ ์ด ์‚ฌ์ดํŠธ์—์„œ ๋„์›€์„ ๋งŽ์ด ๋ฐ›์•˜๋‹ค https://whitel0tus.tistory.. 2021. 5. 31.
[dreamhack] welcome (pwnable) https://dreamhack.io/wargame/challenges/27/ welcome Description ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(welcome)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. "์ ‘์† ์ •๋ณด ๋ณด๊ธฐ"๋ฅผ ๋ˆŒ๋Ÿฌ ์„œ๋น„์Šค ์ •๋ณด๋ฅผ ์–ป์€ ํ›„ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ์„œ๋ฒ„๋กœ๋ถ€ํ„ฐ ์–ป์€ ํ”Œ๋ž˜ dreamhack.io ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์— ์ ‘์†๋งŒ ๊ฐ€๋Šฅํ•˜๋‹ค๋ฉด ๋ฐ”๋กœ ํ’€ ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ œ์ด๋‹ค ์œˆ๋„์šฐ์—์„œ ๋ฐ”๋กœ ์ ‘์†ํ•  ์ˆ˜ ์—†์–ด์„œ ์šฐ๋ถ„ํˆฌ๋ฅผ ์„ค์น˜ํ•œ ํ›„ ์ ‘์†ํ–ˆ๋”๋‹ˆ ๋ฐ”๋กœ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๋‚˜์™”๋‹ค * ๋‹ค์Œ ๋งํฌ๋Š” ์šฐ๋ถ„ํˆฌ๋ฅผ ์„ค์น˜ํ•  ๋•Œ ๋„์›€์„ ๋งŽ์ด ๋ฐ›์€ ๋งํฌ์ด๋‹ค https://m.blog.naver.com/PostView.naver?blogId=kwy1052aa&logNo=221530690198&proxyReferer=https:%.. 2021. 5. 26.
[dreamhack] xss-1 (web) https://dreamhack.io/wargame/challenges/28/ xss-1 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Client-side Basic dreamhack.io ์ด๋ฒˆ์—๋Š” XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ‘ธ๋Š” ๋ฌธ์ œ์ด๋‹ค XSS ์ทจ์•ฝ์ ์ด๋ž€? ๊ฒŒ์‹œํŒ์„ ํฌํ•จํ•œ ์›น์—์„œ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ๊ฐ™์€ ์Šคํฌ๋ฆฝํŠธ ์–ธ์–ด๋ฅผ ์‚ฝ์ž…ํ•ด ๊ฐœ๋ฐœ์ž๊ฐ€ ์˜๋„ํ•˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์„ ์ž‘๋™์‹œํ‚ค๋Š”๊ฒƒ ์ถœ์ฒ˜ : https://kevinthegrey.tistory.com/36 2-2) XSS(Cross Site Scripting) ๊ณต๊ฒฉ๊ธฐ๋ฒ•, ์‹œํ์–ด ์ฝ”๋”ฉ Client-script language - HTML, jav.. 2021. 5. 24.
[dreamhack] file-download-1 (web) https://dreamhack.io/wargame/challenges/37/ file-download-1 File Download ์ทจ์•ฝ์ ์ด ์กด์žฌํ•˜๋Š” ์›น ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. flag.py๋ฅผ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์œผ๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io ์ด๋ฒˆ ๋ฌธ์ œ๋Š” File Download ์ทจ์•ฝ์ ์ด ์กด์žฌํ•˜๋Š” ์›น ์„œ๋น„์Šค์—์„œ flag.py๋ฅผ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์œผ๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์ ์ด๋ž€? https://blog.naver.com/mkgk888/150107625078 [์›น ํ•ดํ‚น ๊ธฐ๋ฒ•] ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์  FileDownload ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์šฐ์„  FileDownload๋ž€.. ์›น ์ƒ์—์„œ ํŒŒ์ผ์„ ์‚ฌ์šฉ์ž์˜ ์ปดํ“จ.... 2021. 5. 24.
[dreamhack] ์‹ค์Šต ํ™˜๊ฒฝ ๊ตฌ์ถ• pwnable vmware ๋ฐ ์šฐ๋ถ„ํˆฌ ์„ค์น˜ https://m.blog.naver.com/PostView.naver?blogId=kwy1052aa&logNo=221530690198&proxyReferer=https:%2F%2Fwww.google.com%2F vmware workstation 15 ๋ฐ ์šฐ๋ถ„ํˆฌ ๋ฆฌ๋ˆ…์Šค 18.04 ์„ค์น˜ ๊ณผ์ • ์˜ค๋Š˜์€ ์œˆ๋„์šฐ10 OS์— vmware workstation 15๋ฅผ ์„ค์น˜ํ•œ ํ›„ ์šฐ๋ถ„ํˆฌ ๋ฆฌ๋ˆ…์Šค๋ฅผ ์˜ฌ๋ ค์„œ ๋Œ๋ ค๋ณด๋ ค๊ณ  ํ•œ๋‹ค. ํ˜„... blog.naver.com web Host: host1.dreamhack.games Port: *****/tcp -> ์ ‘์† ์‹œ host1.dreamhack.games:***** ๋กœ ์ž…๋ ฅ 2021. 5. 24.