Apollo89 · Author

apollo89

아폴로89 입니다.
783 articles
Security

보호된 글: webhacking.kr 57 [web, 600]

   문제 : index.phps 가 존재한다. <html> <head> <title>Challenge 57</title> </head> <body> <? $secret_key="????"; if(time()>1309064400) exit("오후 2시에 공개됩니다."); if($_POST[pw]) { if($_POST[pw]==$secret_key) { mysql_query("delete from challenge57msg"); @solve(); exit(); } } if($_GET[msg] && $_GET[se]) { if(eregi("from|union|select|and|or|not|&|\||benchmark",$_GET[se])) exit("Access Denied"); mysql_query("insert into challenge57msg(id,msg,pw,op) values('$_SESSION[id]','$_GET[msg]','$secret_key',$_GET[se])"); echo("Done<br><br>"); }…

읽어보기 →
Security

보호된 글: webhacking.kr 45 [web, 550]

  문제 : SQL INJECTION 이라고 떡 적혀있따... 소스보기를 하니 index.phps 가 힌트로 있다. <html> <head> <title>Challenge 45</title> </head> <body> <h1>SQL INJECTION</h1> <form method=get action=index.php> id : <input name=id value=guest><br> pw : <input name=pw value=guest><br> <input type=submit>&nbsp;&nbsp;&nbsp;<input type=reset> </form> <? if(time()<1256900400) exit();…

읽어보기 →
Security

보호된 글: webhacking.kr 30 [web, 550]

  문제 : 파일 업로드 문제다.. 힌트를 보니 http://webhacking.kr/challenge/web/web-15/upload/index.php 파일의 소스가 제공된다. <? mysql_connect() or die(); mysql_select_db("challenge_30_table") or die(); $q=mysql_query("select password from challenge_30_answer") or die(); $data=mysql_fetch_array($q) or die(); if($data) { $pw="????"; echo("Password is $pw"); } ?> 파일업로드 문제 같은데 DB라... http://webhacking.kr/challenge/web/web-15/upload/index.php 에…

읽어보기 →
Security

보호된 글: webhacking.kr 44 [web, 500]

  문제 : name에 test를 입력하고 make 를 누르면 파라미터로 html=test 으로 넘어가고 index/go.html 으로 리다이렉션 후 go.html에서 hello test 가 나온다.. (입력문자는 5글자로 제한이 되어있다.) 동작하는 걸로봐서 html 변수에 들어온 것을 한번 처리하고(system?) 결과를 index/go.html 파일에 쓰는 것이 아닌가 하는 생각이…

읽어보기 →
Security

보호된 글: webhacking.kr 40 [web, 500]

  문제 : 로그인 창인데 no 가 있는 로그인 창이다. 일단 입력된데로 login을 하니 Success - guest 가 뜬다. no 를 2으로 변경해서 login 하니 Failure 가 나온다. 이번에는 sql injection 테스트를 위해 no에 1or1=1를 넣어보니 access denied 가 나온다. 아마 키워드…

읽어보기 →
Security

보호된 글: webhacking.kr 28 [web, 500]

  문제 : 힌트로 upload/index.php 가 주어졌는데 접속해보면 read me 라고만 적혀있다. 그리고 파일 업로드 기능이 있다.. 테스트 파일을 하나 만들어 업로드를 해보니 아래와 같은 문구와 힌트가 나왔다. .htaccess관련 취약점을 찾아보니 꽤많이 나온다. (http://hyunmini.tistory.com/48) (http://php.net/manual/kr/configuration.changes.php) 위의 내용을 참고해서 .htaccess 파일의 내용을 아래와…

읽어보기 →
Security

보호된 글: webhacking.kr 22 [bonus, 500]

  문제 : 로그인창이 있고... 힌트가 있다. admin의 비밀번호를 찾는 문제다.. 소스보기에도 추가힌트는 없고 index.phps 도 없다. 일단 test / 1234 계정을 생성하고 로그인을 했더니.. id 와 user key 가 보인다. user key 값이 md5으로 보여 구글에 검색해봤더니.. 운좋게 검색이 되었다.. 해시값은…

읽어보기 →
Security

보호된 글: webhacking.kr 2 [web, 500]

  문제 : 웬 도를 닦는 사진이.. 사이트 구성을 보기 위해 여기저기 들어가 보니 BOARD 메뉴에 FreeB0aRd 가 있고 글이 딱하나 있는데, 비밀글이다! 여기 비밀번호를 알아야 할 것 같다 소스보기를 하니.. 이미지맵에 admin 이 딱보인다. admin으로 로그인하기 위해 sql injection 을 시도해봤지만…

읽어보기 →
Security

보호된 글: webhacking.kr 50 [web, 450]

  문제 : SQL INJECTION 문제다. 소스보기를 하니 index.phps 파일이 힌트로 나와있다. <html> <head> <title>Challenge 50</title> </head> <body> <h1>SQL INJECTION</h1> <form method=get action=index.php> id : <input name=id value='guest'><br> pw : <input name=pw value='guest'><br> <input type=submit>&nbsp;&nbsp;&nbsp;<input type=reset> </form> <? if(time()<1258110000) exit(); ?> <!--…

읽어보기 →
Tech

릴리카메라 주문! (Lily camera Pre-Order)

계속 드론을 하나 사고 싶어서 고민하다가... 최근에 Lily camera 소개 영상을 보고 완전 맘에 들었다... https://www.youtube.com/watch?v=4vGcH0Bk3hg 결국 질렀다.. 대박! 무엇보다 트레킹센서가 있어 따라다니면서 나를 찍는 다는 것이 최고의 장점. 비행시간은 20분이고 방수 기능도 있다. 그리고 귀엽다! 가격은 Pre-Oreder으로 6.15일까지만 국제배송비 포함 $529에…

읽어보기 →