๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๋ณด์•ˆ/dreamhack

[dreamhack] xss-1 (web)

by - ์˜คํŠธ - 2021. 5. 24.

https://dreamhack.io/wargame/challenges/28/

 

xss-1

์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” flag.txt, FLAG ๋ณ€์ˆ˜์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Client-side Basic

dreamhack.io

์ด๋ฒˆ์—๋Š” XSS ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ‘ธ๋Š” ๋ฌธ์ œ์ด๋‹ค

 

XSS ์ทจ์•ฝ์ ์ด๋ž€?
๊ฒŒ์‹œํŒ์„ ํฌํ•จํ•œ ์›น์—์„œ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ๊ฐ™์€ ์Šคํฌ๋ฆฝํŠธ ์–ธ์–ด๋ฅผ ์‚ฝ์ž…ํ•ด ๊ฐœ๋ฐœ์ž๊ฐ€ ์˜๋„ํ•˜์ง€ ์•Š์€ ๊ธฐ๋Šฅ์„ ์ž‘๋™์‹œํ‚ค๋Š”๊ฒƒ

์ถœ์ฒ˜ : https://kevinthegrey.tistory.com/36

 

2-2) XSS(Cross Site Scripting) ๊ณต๊ฒฉ๊ธฐ๋ฒ•, ์‹œํ์–ด ์ฝ”๋”ฉ

Client-script language  - HTML, javascript Server-script language  - PHP SQL ์šฐ๋ฆฌ๊ฐ€ ๋‹ค๋ค˜๋˜ ์–ธ์–ด๋“ค์ด๋‹ค. ์ด์ค‘์—์„œ ์šฐ๋ฆฌ๋Š” ๋จผ์ € Javascript ๋ฅผ ์ด์šฉํ•œ ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์ž. XSS : Cross Site Scripting..

kevinthegrey.tistory.com

 

xss-1 ํŽ˜์ด์ง€๋กœ ์ ‘์†ํ•˜๋ฉด xss, memo, flag ์ด 3ํ•ญ๋ชฉ์ด ๋‚˜์˜จ๋‹ค

 

  • flag ํ•ญ๋ชฉ์€ ์Šคํฌ๋ฆฝํŠธ ์–ธ์–ด๋ฅผ ๋„ฃ์–ด์„œ ๊ณต๊ฒฉํ•˜๋ฉด ๋˜๋Š” ํŽ˜์ด์ง€
  • memo ํ•ญ๋ชฉ์€ flag์— ์ž…๋ ฅํ•œ ๊ณต๊ฒฉ๊ฐ’์ด ์„ฑ๊ณตํ•  ๋•Œ flag ๊ฐ’์ด ๋‚˜์˜ค๋Š” ํŽ˜์ด์ง€๋ผ๊ณ  ์ƒ๊ฐํ•  ์ˆ˜ ์žˆ์Œ(๊ทธ๋Ÿฌ๋‚˜ cookie๊ฐ€ memo์— ์กด์žฌํ•œ๋‹ค๋Š” ์ •ํ™•ํ•œ ๊ทผ๊ฑฐ๊นŒ์ง€๋Š” ๋ชจ๋ฅด๊ฒ ๋‹ค)
  • xss ํ•ญ๋ชฉ์€ alert๊ฐ€ ํด๋ผ์ด์–ธํŠธ์—์„œ ์ž‘๋™ํ•˜๊ณ  ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค (์œ„ ์ถœ์ฒ˜์— ๋”ฐ๋ฅด๋ฉด ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ๋Š” ํด๋ผ์ด์–ธํŠธ์ธก ์–ธ์–ด๋ผ์„œ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋  ์ˆ˜ ์žˆ๋‹ค๋Š”๊ฒƒ ์ž์ฒด๋งŒ์œผ๋กœ๋„ ์ทจ์•ฝ์ ์ด ๋œ๋‹ค)

์ฝ”๋“œ๋ฅผ ๋ณด๋ฉด <script></script> ํƒœ๊ทธ์™€ cookie ๊ฐ€ ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค

 

์ž…๋ ฅํ•œ ์Šคํฌ๋ฆฝํŠธ ์ฝ”๋“œ : 

<script> location.href="/memo?memo="+document.cookie; </script>

 

memo์— ์ฟ ํ‚ค๊ฐ€ ์กด์žฌํ•จ -> location.href="/memo?memo="

์ฟ ํ‚ค๊ฐ’ -> +document.cookie; 

 

 

๋”ฐ๋ผ์„œ ์ œ์ถœํ•œ ๋’ค memo ํ•ญ๋ชฉ์œผ๋กœ ๋“ค์–ด๊ฐ€๋ฉด ํ”Œ๋ž˜๊ทธ ๊ฐ’์ด ๋‚˜์˜จ๋‹ค

 

* ์ด๋ฒˆ ๋ฌธ์ œ๋Š” ์ด ๋ถ„์˜ ๋ผ์—…์„ ์ฐธ๊ณ ํ•˜์—ฌ ์ž‘์„ฑํ•˜์˜€์Šต๋‹ˆ๋‹ค

https://hobbylists.tistory.com/entry/XSSCross-Site-Scripting%EA%B3%B5%EA%B2%A9-%EC%8B%A4%EC%8A%B5-Dreamhack-%EC%8B%A4%EC%8A%B5%EC%98%88%EC%A0%9C

 

[XSS] XSS(Cross Site Scripting)๊ณต๊ฒฉ ์‹ค์Šต - (Dreamhack ์‹ค์Šต์˜ˆ์ œ)

XSS Attack -์„œ๋ฒ„์˜ ์‘๋‹ต์— ๊ณต๊ฒฉ์ž๊ฐ€ ์‚ฝ์ž…๋œ ์•…์„ฑ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋ฐ›์€ ์‚ฌ์šฉ์ž์˜ ์›น ๋ธŒ๋ผ์šฐ์ €์—์„œ ์•…์„ฑ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋˜๋Š” ๊ณต๊ฒฉ XSS ๊ณต๊ฒฉ์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด ์š”๊ตฌ๋˜๋Š” ์กฐ๊ฑด โ–ผ 1. ์•…์„ฑ script๊ฐ€ ์‚ฝ์ž…๋ ์ˆ˜

hobbylists.tistory.com

 

'๋ณด์•ˆ > dreamhack' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[dreamhack] basic_exploitation_001 (pwnable)  (0) 2021.05.31
[dreamhack] basic_exploitation_000 (pwnable)  (2) 2021.05.31
[dreamhack] welcome (pwnable)  (0) 2021.05.26
[dreamhack] file-download-1 (web)  (0) 2021.05.24
[dreamhack] ์‹ค์Šต ํ™˜๊ฒฝ ๊ตฌ์ถ•  (0) 2021.05.24