๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ145

[dreamhack] welcome (pwnable) https://dreamhack.io/wargame/challenges/27/ welcome Description ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค(welcome)์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ์™€ ์†Œ์Šค ์ฝ”๋“œ๊ฐ€ ์ฃผ์–ด์ง‘๋‹ˆ๋‹ค. "์ ‘์† ์ •๋ณด ๋ณด๊ธฐ"๋ฅผ ๋ˆŒ๋Ÿฌ ์„œ๋น„์Šค ์ •๋ณด๋ฅผ ์–ป์€ ํ›„ ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ์„œ๋ฒ„๋กœ๋ถ€ํ„ฐ ์–ป์€ ํ”Œ๋ž˜ dreamhack.io ์ด ๋ฌธ์ œ๋Š” ์„œ๋ฒ„์— ์ ‘์†๋งŒ ๊ฐ€๋Šฅํ•˜๋‹ค๋ฉด ๋ฐ”๋กœ ํ’€ ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ œ์ด๋‹ค ์œˆ๋„์šฐ์—์„œ ๋ฐ”๋กœ ์ ‘์†ํ•  ์ˆ˜ ์—†์–ด์„œ ์šฐ๋ถ„ํˆฌ๋ฅผ ์„ค์น˜ํ•œ ํ›„ ์ ‘์†ํ–ˆ๋”๋‹ˆ ๋ฐ”๋กœ ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๋‚˜์™”๋‹ค * ๋‹ค์Œ ๋งํฌ๋Š” ์šฐ๋ถ„ํˆฌ๋ฅผ ์„ค์น˜ํ•  ๋•Œ ๋„์›€์„ ๋งŽ์ด ๋ฐ›์€ ๋งํฌ์ด๋‹ค https://m.blog.naver.com/PostView.naver?blogId=kwy1052aa&logNo=221530690198&proxyReferer=https:%.. 2021. 5. 26.
[N0Named] RE: xeh_desrev http://ctf.no-named.kr:1234/challenges#RE:%20xeh_desrev ์ด๋ฒˆ ๋ฌธ์ œ์—์„œ๋Š” 1) ์ผ๋‹จ png๋ฅผ ๋ณต๊ตฌํ•ด์•ผ ํ•˜๊ณ  2) xeh_deserev -> hex_reversed ํ—ฅ์Šค๊ฐ’์„ ๊ฑฐ๊พธ๋กœ ๋’ค์ง‘์œผ๋ผ๋Š” ์˜๋ฏธ์ธ ๊ฒƒ์„ ์œ ์ถ”ํ–ˆ๋‹ค ๋‹ค์‹œ ํ—ฅ์Šค์—๋””ํ„ฐ๋ฅผ ์‚ฌ์šฉํ–ˆ๋‹ค ๋”ฐ๋ผ์„œ ๊ฐ€์žฅ ๋’ท๋ถ€๋ถ„์„ ํ™•์ธํ–ˆ๋Š”๋ฐ ๋ฌธ์ œ์˜ ํžŒํŠธ์ฒ˜๋Ÿผ 89 50 4E 47 0D 0A 1A 0A ์ด๋ ‡๊ฒŒ ๋’ค๋ถ€ํ„ฐ png ํ—ค๋” ์‹œ๊ทธ๋‹ˆ์ฒ˜๊ฐ€ ์กด์žฌํ–ˆ๋‹ค ์ด ํŒŒ์ผ์„ ๊ฑฐ๊พธ๋กœ ๋’ค์ง‘๊ธฐ ์œ„ํ•ด ํ•˜๋‚˜ํ•˜๋‚˜ ๊ฐ’์„ ๋ฐ”๊ฟ”์ค„ ์ˆ˜๋„ ์žˆ์ง€๋งŒ ๊ทธ๋Ÿฌ๊ธฐ์—” ์‹œ๊ฐ„์ด ์—†์–ด์„œ ํŒŒ์ด์ฌ ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ•ด์„œ ๋ฐ”๊ฟ”์ฃผ์—ˆ๋‹ค ๋”ฐ๋ผ์„œ ํŒŒ์ด์ฌ ํŒŒ์ผ ์ฝ๊ธฐ/์“ฐ๊ธฐ ๊ฐœ๋…๊ณผ ํŒŒ์ผ ๋ฐ”์ด๋„ˆ๋ฆฌ ๊ฑฐ๊พธ๋กœ ์ €์žฅํ•˜๊ธฐ ์‚ฌ์ดํŠธ๋ฅผ ํ†ตํ•ด ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ–ˆ๋‹ค https://m.blog.naver.com/PostView.naver?b.. 2021. 5. 24.
[N0Named] magicIMAGE http://ctf.no-named.kr:1234/challenges#magicIMAGE ์ด๋ฒˆ ๋ฌธ์ œ๋Š” png๋ฅผ ๋ณต๊ตฌํ•˜๋Š” ๋ฌธ์ œ์ด๋‹ค ์ผ๋‹จ mandu.png๋ฅผ ๋‹ค์šด ๋ฐ›์•˜๋Š”๋ฐ, ์—ญ์‹œ ํŒŒ์ผ์ด ๊นจ์ ธ์žˆ์—ˆ๋‹ค ์ผ๋‹จ ์ด ์ƒํƒœ์—์„œ๋Š” ์•„๋ฌด๋Ÿฐ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์—†์œผ๋ฏ€๋กœ ํ—ฅ์Šค์—๋””ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•ด์„œ ๋จผ์ € ํ—ค๋” ์‹œ๊ทธ๋‹ˆ์ฒ˜๋ฅผ ํ™•์ธํ–ˆ๋‹ค https://know0how.tistory.com/6 [HxD] Hex Editor ํ”„๋กœ๊ทธ๋žจ ๋‹ค์šด๋กœ๋“œ ๋ฐ ์‚ฌ์šฉ๋ฒ• Hex Editor(์ดํ•˜ Hxd), ํ—ฅ์Šค ์—๋””ํ„ฐ ๋˜๋Š” ํ—ฅ์Šค ์ฝ”๋“œ ์—๋””ํ„ฐ๋ผ๋Š” ๋ช…์นญ์„ ์ผ์ปซ๊ณ  ์žˆ์œผ๋ฉฐ ์ด ํ”„๋กœ๊ทธ๋žจ์— ๋Œ€ํ•ด ์ƒ์„ธํžˆ ์•Œ๊ณ  ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๊ธฐ๋ณธ์ ์œผ๋กœ ์•Œ์•„๋‘˜ ๊ฒŒ ์žˆ์Šต๋‹ˆ๋‹ค. ํ—ฅ์Šค(Hex)๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ '์‹ญ์œก know0how.tistory.com 89 50 4E 47 ๊นŒ์ง€๋Š” PNG ํ—ค๋” ์‹œ๊ทธ๋‹ˆ์ฒ˜์™€ ๊ฐ™.. 2021. 5. 24.
[dreamhack] xss-1 (web) https://dreamhack.io/wargame/challenges/28/ xss-1 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Client-side Basic dreamhack.io ์ด๋ฒˆ์—๋Š” XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ‘ธ๋Š” ๋ฌธ์ œ์ด๋‹ค XSS ์ทจ์•ฝ์ ์ด๋ž€? ๊ฒŒ์‹œํŒ์„ ํฌํ•จํ•œ ์›น์—์„œ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ๊ฐ™์€ ์Šคํฌ๋ฆฝํŠธ ์–ธ์–ด๋ฅผ ์‚ฝ์ž…ํ•ด ๊ฐœ๋ฐœ์ž๊ฐ€ ์˜๋„ํ•˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์„ ์ž‘๋™์‹œํ‚ค๋Š”๊ฒƒ ์ถœ์ฒ˜ : https://kevinthegrey.tistory.com/36 2-2) XSS(Cross Site Scripting) ๊ณต๊ฒฉ๊ธฐ๋ฒ•, ์‹œํ์–ด ์ฝ”๋”ฉ Client-script language - HTML, jav.. 2021. 5. 24.
[dreamhack] file-download-1 (web) https://dreamhack.io/wargame/challenges/37/ file-download-1 File Download ์ทจ์•ฝ์ ์ด ์กด์žฌํ•˜๋Š” ์›น ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. flag.py๋ฅผ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์œผ๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io ์ด๋ฒˆ ๋ฌธ์ œ๋Š” File Download ์ทจ์•ฝ์ ์ด ์กด์žฌํ•˜๋Š” ์›น ์„œ๋น„์Šค์—์„œ flag.py๋ฅผ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์œผ๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์ ์ด๋ž€? https://blog.naver.com/mkgk888/150107625078 [์›น ํ•ดํ‚น ๊ธฐ๋ฒ•] ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์  FileDownload ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์šฐ์„  FileDownload๋ž€.. ์›น ์ƒ์—์„œ ํŒŒ์ผ์„ ์‚ฌ์šฉ์ž์˜ ์ปดํ“จ.... 2021. 5. 24.
[dreamhack] ์‹ค์Šต ํ™˜๊ฒฝ ๊ตฌ์ถ• pwnable vmware ๋ฐ ์šฐ๋ถ„ํˆฌ ์„ค์น˜ https://m.blog.naver.com/PostView.naver?blogId=kwy1052aa&logNo=221530690198&proxyReferer=https:%2F%2Fwww.google.com%2F vmware workstation 15 ๋ฐ ์šฐ๋ถ„ํˆฌ ๋ฆฌ๋ˆ…์Šค 18.04 ์„ค์น˜ ๊ณผ์ • ์˜ค๋Š˜์€ ์œˆ๋„์šฐ10 OS์— vmware workstation 15๋ฅผ ์„ค์น˜ํ•œ ํ›„ ์šฐ๋ถ„ํˆฌ ๋ฆฌ๋ˆ…์Šค๋ฅผ ์˜ฌ๋ ค์„œ ๋Œ๋ ค๋ณด๋ ค๊ณ  ํ•œ๋‹ค. ํ˜„... blog.naver.com web Host: host1.dreamhack.games Port: *****/tcp -> ์ ‘์† ์‹œ host1.dreamhack.games:***** ๋กœ ์ž…๋ ฅ 2021. 5. 24.