λ³΄μ•ˆ/dreamhack

[dreamhack] xss-1 (web)

- 였트 - 2021. 5. 24. 21:36

https://dreamhack.io/wargame/challenges/28/

 

xss-1

μ—¬λŸ¬ κΈ°λŠ₯κ³Ό μž…λ ₯받은 URL을 ν™•μΈν•˜λŠ” 봇이 κ΅¬ν˜„λœ μ„œλΉ„μŠ€μž…λ‹ˆλ‹€. XSS 취약점을 μ΄μš©ν•΄ ν”Œλž˜κ·Έλ₯Ό νšλ“ν•˜μ„Έμš”. ν”Œλž˜κ·ΈλŠ” flag.txt, FLAG λ³€μˆ˜μ— μžˆμŠ΅λ‹ˆλ‹€. Reference Client-side Basic

dreamhack.io

μ΄λ²ˆμ—λŠ” XSS 취약점을 μ΄μš©ν•΄ ν‘ΈλŠ” λ¬Έμ œμ΄λ‹€

 

XSS μ·¨μ•½μ μ΄λž€?
κ²Œμ‹œνŒμ„ ν¬ν•¨ν•œ μ›Ήμ—μ„œ μžλ°”μŠ€ν¬λ¦½νŠΈκ°™μ€ 슀크립트 μ–Έμ–΄λ₯Ό μ‚½μž…ν•΄ κ°œλ°œμžκ°€ μ˜λ„ν•˜μ§€ μ•Šμ€ κΈ°λŠ₯을 μž‘λ™μ‹œν‚€λŠ”κ²ƒ

좜처 : https://kevinthegrey.tistory.com/36

 

2-2) XSS(Cross Site Scripting) 곡격기법, μ‹œνμ–΄ μ½”λ”©

Client-script language  - HTML, javascript Server-script language  - PHP SQL μš°λ¦¬κ°€ λ‹€λ€˜λ˜ 언어듀이닀. μ΄μ€‘μ—μ„œ μš°λ¦¬λŠ” λ¨Όμ € Javascript λ₯Ό μ΄μš©ν•œ 취약점에 λŒ€ν•΄ μ•Œμ•„λ³΄μž. XSS : Cross Site Scripting..

kevinthegrey.tistory.com

 

xss-1 νŽ˜μ΄μ§€λ‘œ μ ‘μ†ν•˜λ©΄ xss, memo, flag 총 3ν•­λͺ©μ΄ λ‚˜μ˜¨λ‹€

 

  • flag ν•­λͺ©μ€ 슀크립트 μ–Έμ–΄λ₯Ό λ„£μ–΄μ„œ κ³΅κ²©ν•˜λ©΄ λ˜λŠ” νŽ˜μ΄μ§€
  • memo ν•­λͺ©μ€ flag에 μž…λ ₯ν•œ 곡격값이 성곡할 λ•Œ flag 값이 λ‚˜μ˜€λŠ” νŽ˜μ΄μ§€λΌκ³  생각할 수 있음(κ·ΈλŸ¬λ‚˜ cookieκ°€ memo에 μ‘΄μž¬ν•œλ‹€λŠ” μ •ν™•ν•œ κ·Όκ±°κΉŒμ§€λŠ” λͺ¨λ₯΄κ² λ‹€)
  • xss ν•­λͺ©μ€ alertκ°€ ν΄λΌμ΄μ–ΈνŠΈμ—μ„œ μž‘λ™ν•˜κ³  μžˆλ‹€λŠ” 것을 μ•Œ 수 μžˆλ‹€ (μœ„ μΆœμ²˜μ— λ”°λ₯΄λ©΄ μžλ°”μŠ€ν¬λ¦½νŠΈλŠ” ν΄λΌμ΄μ–ΈνŠΈμΈ‘ μ–Έμ–΄λΌμ„œ μŠ€ν¬λ¦½νŠΈκ°€ 싀행될 수 μžˆλ‹€λŠ”κ²ƒ μžμ²΄λ§ŒμœΌλ‘œλ„ 취약점이 λœλ‹€)

μ½”λ“œλ₯Ό 보면 <script></script> νƒœκ·Έμ™€ cookie κ°€ μžˆμŒμ„ μ•Œ 수 μžˆλ‹€

 

μž…λ ₯ν•œ 슀크립트 μ½”λ“œ : 

<script> location.href="/memo?memo="+document.cookie; </script>

 

memo에 μΏ ν‚€κ°€ μ‘΄μž¬ν•¨ -> location.href="/memo?memo="

μΏ ν‚€κ°’ -> +document.cookie; 

 

 

λ”°λΌμ„œ μ œμΆœν•œ λ’€ memo ν•­λͺ©μœΌλ‘œ λ“€μ–΄κ°€λ©΄ ν”Œλž˜κ·Έ 값이 λ‚˜μ˜¨λ‹€

 

* 이번 λ¬Έμ œλŠ” 이 λΆ„μ˜ 라업을 μ°Έκ³ ν•˜μ—¬ μž‘μ„±ν•˜μ˜€μŠ΅λ‹ˆλ‹€

https://hobbylists.tistory.com/entry/XSSCross-Site-Scripting%EA%B3%B5%EA%B2%A9-%EC%8B%A4%EC%8A%B5-Dreamhack-%EC%8B%A4%EC%8A%B5%EC%98%88%EC%A0%9C

 

[XSS] XSS(Cross Site Scripting)곡격 μ‹€μŠ΅ - (Dreamhack μ‹€μŠ΅μ˜ˆμ œ)

XSS Attack -μ„œλ²„μ˜ 응닡에 κ³΅κ²©μžκ°€ μ‚½μž…λœ μ•…μ„± 슀크립트λ₯Ό 받은 μ‚¬μš©μžμ˜ μ›Ή λΈŒλΌμš°μ €μ—μ„œ μ•…μ„± μŠ€ν¬λ¦½νŠΈκ°€ μ‹€ν–‰λ˜λŠ” 곡격 XSS 곡격을 μˆ˜ν–‰ν•˜κΈ° μœ„ν•΄ μš”κ΅¬λ˜λŠ” 쑰건 β–Ό 1. μ•…μ„± scriptκ°€ μ‚½μž…λ μˆ˜

hobbylists.tistory.com