๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ145

์›น ์‚ฌ์ดํŠธ(์‹ค์Šต์šฉ) ์ทจ์•ฝ์  ์ ๊ฒ€ * ํ™ˆํŽ˜์ด์ง€ ๊ฒŒ์‹œํŒ๊ณผ ๊ด€๋ จ๋œ ๋ณด์•ˆ ์ทจ์•ฝ์ : ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์ , XSS(Cross Site Scripting), SQL ์ธ์ ์…˜ * ์‹ค์Šต ํ™ˆํŽ˜์ด์ง€ : OyesMall 1) ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์  : ๊ฒŒ์‹œํŒ ์ฒจ๋ถ€ํŒŒ์ผ ๊ธฐ๋Šฅ์„ ์ด์šฉํ•ด ํ—ˆ๊ฐ€๋˜์ง€ ์•Š์€ ํŒŒ์ผ ๋“ค์„ ์›น์„œ๋ฒ„๋กœ ์—…๋กœ๋“œ ํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์  โ€ป ํ—ˆ๊ฐ€๋˜์ง€ ์•Š์€ ํŒŒ์ผ ํ™•์žฅ์ž : php, jsp, asp, cgi, js, py, in, pl ๋“ฑ -> Q&A Board์—์„œ ๊ธ€์„ ์ž‘์„ฑํ•  ๋•Œ๋Š” ์ฒจ๋ถ€๊ฐ€๋Šฅํ•œ ํ™•์žฅ์ž๊ฐ€ jpg, hwp, pdf, jpeg, txt ๋งŒ ๊ฐ€๋Šฅํ•˜๋‹ค๊ณ  ํ•˜๋‚˜ ์‹ค์ œ๋กœ asp ํ™•์žฅ์ž ๋กœ ๋˜์–ด์žˆ๋Š” ์ฒจ๋ถ€ํŒŒ์ผ์„ ๋“ฑ๋กํ•œ user ๊ฐ€ ์žˆ์–ด ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์ ์ด ์žˆ๋‹ค๊ณ  ๋ณผ ์ˆ˜ ์žˆ์Œ -> ์—…๋กœ๋“œ ํŒŒ์ผ์— ๋Œ€ํ•œ ํ•„ํ„ฐ๋ง๊ณผ ํŒŒ์ผ ์—…๋กœ๋“œ ๋””๋ ‰ํ† ๋ฆฌ์— ๋Œ€ํ•œ ์‹คํ–‰ ” ๊ถŒํ•œ ์ œํ•œ์œผ๋กœ ์กฐ.. 2021. 6. 28.
[dreamhack] basic_exploitation_001 (pwnable) https://dreamhack.io/wargame/challenges/3/ basic_exploitation_001 Description ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(basicexploitation001)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์ ์„ ์ฐพ๊ณ  ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ์„ ์ฝ์œผ์„ธ์š”. "flag" ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ dreamhack.io 1) ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์  -> 2) ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด "flag" ํŒŒ์ผ ์ฝ๊ธฐ ์‚ฌ์‹ค Environment์— ๋Œ€ํ•œ ๋‚ด์šฉ์€ ๊ทธ๋ƒฅ ์•Œ๋ ค์ฃผ๋Š” ์ •๋ณด? ๊ฐ™์€ ๊ฑฐ๋ผ ์•„๋ฌด ์˜๋ฏธ ์—†๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ๋Š”๋ฐ ๋ฉ”๋ชจ๋ฆฌ ๋ณดํ˜ธ ๊ธฐ๋ฒ•์ด ์ ์šฉ๋˜์ง€ ์•Š์•˜๋‹ค๋Š” ๋‚˜๋ฆ„์˜ ์ •๋ณด๋ฅผ ์•Œ ์ˆ˜ ์žˆ๋‹ค ๊ทธ๋Ÿฌ๋‚˜ NX ๊ธฐ๋ฒ•์€ ์ ์šฉ๋˜์–ด ์žˆ๋‹ค https://kangsecu.tistory.com/138 ๋ฉ”๋ชจ๋ฆฌ .. 2021. 5. 31.
[dreamhack] basic_exploitation_000 (pwnable) basic_exploitation_000 (pwnable) 1) ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์  -> 2) ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด ์…€ ์ทจ๋“ -> 3) "flag" ํŒŒ์ผ ์ฝ๊ธฐ ๋‹ค๋ฅธ ํ•ดํ‚น ๋ถ„์•ผ์™€๋Š” ๋‹ค๋ฅด๊ฒŒ pwnable์€ ํ™˜๊ฒฝ ์…‹ํŒ… & ๋ฌธ์ œ๋ฅผ ํ‘ธ๋Š” ๋ฐ ๋ฐ˜๋‚˜์ ˆ์€ ์†Œ๋น„ํ•œ ๊ฒƒ ๊ฐ™๋‹ค 1) ํ”„๋กœ๊ทธ๋žจ์˜ ์ทจ์•ฝ์  : ๋ณ€์ˆ˜ buf๋ฅผ 128byte(0x80)๋งŒํผ ํ• ๋‹นํ•œ ํ›„ ๋ณ€์ˆ˜ buf์˜ ์ฃผ์†Œ๋ฅผ ์ถœ๋ ฅํ•œ๋‹ค ๊ทธ ๋‹ค์Œ, buf์˜ ๊ณต๊ฐ„์€ 128byte์ธ๋ฐ, 141byte๋ฅผ ์ž…๋ ฅ๋ฐ›๋Š”๋‹ค-> ๋ฒ„ํผ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ ๋ฐœ์ƒ 2) ์ต์Šคํ”Œ๋กœ์ž‡ํ•ด ์…€ ์ทจ๋“ : ์‰˜ ์ฝ”๋“œ ์ž‘์„ฑ ํ›„ python3 app.py ๋กœ ์‹คํ–‰ํ•ด ๋ณด๋‹ˆ pwn์ด ์ธ์‹์ด ์•ˆ๋˜์–ด์„œ pwntools, pip์„ ์„ค์น˜ํ–ˆ๋‹ค ์„ค์น˜ ์˜ค๋ฅ˜์™€ ์„ค์น˜ ๊ณผ์ •์€ ์ด ์‚ฌ์ดํŠธ์—์„œ ๋„์›€์„ ๋งŽ์ด ๋ฐ›์•˜๋‹ค https://whitel0tus.tistory.. 2021. 5. 31.
RAON CTF ์‹ค์Šต ๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€ ์ž…๋‹ˆ๋‹ค. 2021. 5. 31.
[HackCTF] Welcome_Forensics, Question? (forensics) https://ctf.j0n9hyun.xyz/challenges HackCTF Do you wanna be a God? If so, Challenge! ctf.j0n9hyun.xyz Welcome_Forensics ์ผ๋‹จ ์‚ฌ์ง„์ด ์„ธ๋กœ๋กœ ์™„์ „ํžˆ ์••์ถ•๋˜์—ˆ๋‹ค ์–ด๋–ป๊ฒŒ ํฌ๋ Œ์‹ ๋ฌธ์ œ์ธ์ง€๋Š” ๋ชจ๋ฅด๊ฒ ๋Š”๋ฐ ์ผ๋‹จ ํŒŒ์›Œํฌ์ธํŠธ๋กœ ๋ณต๋ถ™ํ•ด๋ณด๋‹ˆ ๋ฐ”๋กœ ์ด๋ ‡๊ฒŒ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ์ œ๋Œ€๋กœ ๋‚˜์™”๊ณ  ๋‘๋ฒˆ์งธ๋กœ๋Š” ๋‹ค๋ฅธ์ด๋ฆ„์œผ๋กœ ์ €์žฅํ–ˆ์„ ๋•Œ๋„ ์ •๋ง ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๊ทธ๋Œ€๋กœ ๋‚˜์™”๋‹ค HackCTF{w3lc0m3_70_f0r3n51c_w0rld!} Question? ์••์ถ•ํŒŒ์ผ์„ ํ•ด์ œํ•ด์„œ ๋”๋ธ”ํด๋ฆญํ•˜๋ฉด HxD๋กœ ํ™•์ธํ•˜๋ฉด ํŒŒ์ผ ์‹œ๊ทธ๋‹ˆ์ฒ˜์—๋Š” ์ด์ƒ์ด ์—†๋‹ค ๊ทธ๋Ÿผ Decoded text์—์„œ HackCTF๋ฅผ ๊ฒ€์ƒ‰ํ•ด๋ดค๋”๋‹ˆ ์ด๋ ‡๊ฒŒ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๋‚˜์˜จ๋‹ค HackCTF{P1e45e_find_.. 2021. 5. 29.
[HackCTF] Who Am I?, QRCODE (misc) https://ctf.j0n9hyun.xyz/login?next=%2Fchallenges HackCTF Do you wanna be a God? If so, Challenge! ctf.j0n9hyun.xyz Who am I? ๋ง ๊ทธ๋Œ€๋กœ x86 Instruction์—์„œ eip๋ฅผ ํ„ฐ๋œจ๋ ค์ฃผ๋Š” ์—ญํ• ์„ ์ฐพ๋Š” ๋ฌธ์ œ์ด๋‹ค eip๋ž€? ๋ช…๋ น ํฌ์ธํ„ฐ ๋ ˆ์ง€์Šคํ„ฐ์ด๋ฉฐ ๋‹ค์Œ์— ์‹คํ–‰ํ•ด์•ผ ํ•  ๋ช…๋ น์–ด๊ฐ€ ์กด์žฌํ•˜๋Š” ๋ฉ”๋ชจ๋ฆฌ ์ฃผ์†Œ๊ฐ€ ์ €์žฅ๋œ๋‹ค. ํ˜„์žฌ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ ์™„๋ฃŒํ•œ ํ›„์— eip ๋ ˆ์ง€์Šคํ„ฐ์— ์ €์žฅ๋˜์–ด ์žˆ๋Š” ์ฃผ์†Œ์— ์œ„์น˜ํ•œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๊ฒŒ ๋œ๋‹ค. https://chriskhj6296.tistory.com/24 x86 CPU ๋ ˆ์ง€์Šคํ„ฐ ์กฐ์‚ฌ x86 CPU ๋ ˆ์ง€์Šคํ„ฐ ์กฐ์‚ฌ 1. ๋ ˆ์ง€์Šคํ„ฐ์˜ ์ข…๋ฅ˜์™€ ๊ทธ ์—ญํ•  ๋จผ์ € ์ข…๋ฅ˜๊ฐ€ ๊ทธ ๋ชฉ์ ์— ๋”ฐ๋ผ ๋ฒ”์šฉ ๋ ˆ์ง€์Šคํ„ฐ, ์„ธ.. 2021. 5. 29.