rosieblue
article thumbnail
728x90

์‚ฌ์‹ค BurpSuite์˜ Intruder ๊ธฐ๋Šฅ ์ค‘ Cluster Bomb์— ๋Œ€ํ•ด์„œ ํฌ์ŠคํŒ…์„ ์“ฐ๋˜ ๋„์ค‘, Pitchfork ๋ผ๋Š” ๊ณต๊ฒฉ์ด ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ๋˜์—ˆ๋Š”๋ฐ ์–˜๋„ค ๋‘˜์ด ๋น„์Šทํ•ด๋ณด์—ฌ์„œ ๋‘˜์ด ๋ฌด์—‡์ด ๋‹ค๋ฅผ๊นŒ? ์— ๋Œ€ํ•ด์„œ ์ฐพ์•„๋ณด๋‹ค๊ฐ€ ํฌ์ŠคํŒ…์„ ์ƒˆ๋กœ ์“ฐ๊ฒŒ ๋˜์—ˆ๋‹ค

 

https://systemweakness.com/attack-types-in-intruder-burpsuite-5c65900f71c7

 

Attack Types In Intruder (Burpsuite)

It has been a while since I’ve published any articles. Today I would like to write on the attack types used in intruder. I’m skipping all…

systemweakness.com

์œ„๋Š” Intruder ๊ธฐ๋Šฅ์— ๋Œ€ํ•ด ์ž˜ ์ •๋ฆฌ๋œ ๊ธ€๋กœ, ์˜ˆ์‹œ๋ฅผ ๋“ค์–ด ์„ค๋ช…ํ•ด ์ฃผ์…”์„œ ์‰ฝ๊ฒŒ ์ดํ•ดํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค. ์ด ํฌ์ŠคํŠธ๋Š” ์œ„ ๊ธ€์„ ์š”์•ฝํ•ด์„œ ์ ์€ ๊ธ€์ž„์„ ๋ฐํžŒ๋‹ค.

 

 

Sniper

๋‚ด๊ฐ€ ์ฃผ๋กœ ์šฉ๋„๋„ ๋ชจ๋ฅด๊ณ  ๋งค๋ฒˆ ์“ฐ๋˜ ๊ธฐ๋Šฅ์ด๋‹ค. 

Sniper๋Š” ํ•˜๋‚˜์˜ Payload set๋งŒ ์„ค์ •ํ•˜์—ฌ ๊ณต๊ฒฉํ•˜๊ณ , ๋งŒ์•ฝ ์—ฌ๋Ÿฌ๊ฐœ์˜ Payload Position์ด ์ •ํ•ด์ ธ์žˆ์œผ๋ฉด ํฌ์ง€์…˜๋ณ„๋กœ payload set์„ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์ด๋‹ค (์˜ˆ: position1 - set1์‹คํ–‰ ํ›„ position2 - set1 ์‹คํ–‰ ํ›„  position3 - set1 ....) 

 

์ฆ‰ ์ฒซ๋ฒˆ์งธ postion์— ํŽ˜์ด๋กœ๋“œ ์‹คํ–‰ํ•˜๊ณ , ๋‹ค ๋๋‚˜๋ฉด ๋‘๋ฒˆ์งธ position์— ํŽ˜์ด๋กœ๋“œ ์‹คํ–‰, ๋๋‚˜๋ฉด 3๋ฒˆ์งธ... ์ด๋Ÿฐ์‹์œผ๋กœ ๋ฐ˜๋ณตํ•˜๋Š”๊ฑฐ !

ํ•˜์ง€๋งŒ ํฌ์ง€์…˜ ๋ณ„๋กœ payload set๊ฐ€ ๋‹ฌ๋ผ์ง€๋Š” ๊ฒฝ์šฐ๋Š” ์ ํ•ฉํ•˜์ง€ ์•Š์Œ! (๊ณ„์† ๊ฐ™์€ ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ ์šฉํ•˜๋ฏ€๋กœ~)

 

 

payload set์ด {apple,ball,cat} ์ด๋ผ๊ณ  ์ •์˜๋˜์–ด์žˆ๋‹ค๊ณ  ํ•˜๊ณ  username๊ฐ€ password๋ผ๋Š” ๋‘ ํฌ์ง€์…˜์ด ์žˆ์„ ๋•Œ ๊ณต๊ฒฉ์€ ๋‹ค์Œ์ฒ˜๋Ÿผ ์ง„ํ–‰๋œ๋‹ค.

username=$apple$ and password=$password$
username=$ball$ and password=$password$
username=$cat$ and password=$password$
username=$username$ and password=$apple$
username=$username$ and password=$ball$
username=$username$ and password=$cat$

 

์ „์ฒด request ๊ฐœ์ˆ˜ = ํŽ˜์ด๋กœ๋“œ ์•ˆ์— ์žˆ๋Š” ์›์†Œ๊ฐœ์ˆ˜ * ํฌ์ง€์…˜ ๊ฐœ์ˆ˜

 

Battering ram

์–˜๋Š” ํ•œ๋ฒˆ๋„ ์จ๋ณธ์ ์€ ์—†๊ธดํ•œ๋ฐ Payload๋ฅผ ๋ฐ˜๋ณตํ•˜์—ฌ ์‚ฌ์šฉํ•˜๋ฉฐ Payload๊ฐ€ ์ •์˜๋œ ๋ชจ๋“  ์œ„์น˜์— ๋™์ผํ•œ Payload Set์„ ๋Œ€์ž…ํ•˜๋Š” ๋ฐฉ๋ฒ•์ด๋‹ค.

username=$apple$ and password=$apple$
username=$ball$ and password=$ball$
username=$cat$ and password=$cat$

 

postion1=$same_value$ and password=$same_value$ ํ˜•์‹์œผ๋กœ ํฌ์ง€์…˜์— ๋“ค์–ด๊ฐ€๋Š” ํŽ˜์ด๋กœ๋“œ๋“ค์ด ๋‹ค ๋™์ผํ•จ

๋‘ ํฌ์ง€์…˜์— ๊ฐ™์€ ๊ฐ’์ด ๋“ค์–ด๊ฐ€์•ผ ํ•  ๋•Œ ์ข‹์€ ๋ฐฉ๋ฒ•์ธ ๊ฒƒ ๊ฐ™๋‹ค.

 

 

Pitchfork 

์„ค์ •ํ•œ Payload Position์˜ ๊ฐœ์ˆ˜๋งŒํผ Payload Set์„ ์„ค์ •ํ•˜๋Š” ๋ฐฉ์‹์ด๋‹ค. ๋’ค์— ๋‚˜์˜ฌ cluster bomb๊ณผ ์œ ์‚ฌํ•˜๋‹ค!! ๊ฑ”๋„ ํฌ์ง€์…˜ ๋ณ„๋กœ payload ์„ธํŠธ๊ฐ€ ๋‹ค๋ฅธ ๊ฒฝ์šฐ๋‹ค !

 

Wordlist1:
1. apple
2. Ball
3. Cat
4. Dog

Wordlist2:
1. 11111
2. 2222
3. 333
4. 4444
5. 5555

 

Wordlist1์˜ k๋ฒˆ์งธ ์›์†Œ์™€ Wordlist2์˜ k๋ฒˆ์งธ ์›์†Œ๊ฐ€ ๋Œ€์‘๋˜๋Š” ๋ฐฉ์‹์ด๋‹ค. ๋”ฐ๋ผ์„œ Wordlist2์˜ 5๋ฒˆ์งธ ์›์†Œ๋Š” ๋ฌด์‹œ๋œ๋‹ค!!

 

username=$apple$ and password=$11111$
username=$ball$ and password=$2222$
username=$cat$ and password=$333$
username=$dog$ and password=$4444$

์ „์ฒด request ๊ฐœ์ˆ˜= min(#wordlist1,#wordlist2,...)

 

 

Cluster bomb 

์–˜๋„ ์œ„์˜ pitchfork์ฒ˜๋Ÿผ payload set์„ ์—ฌ๋Ÿฌ ๊ฐœ ์ •ํ•ด์ฃผ๋Š” ๊ณต๊ฒฉ์ด๋‹ค. ํ•˜์ง€๋งŒ ์–˜๋Š” ์ข€๋” ๋‹ค์–‘ํ•˜๊ฒŒ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜๋Š”๋ฐ ์˜ˆ์‹œ๋ฅผ ๋ณด์ž.

 

Wordlist1:
1. apple
2. Ball
3. Cat

Wordlist2:
1. 11111
2. 2222
3. 333

 

์ด๋ ‡๊ฒŒ ๋˜์–ด์žˆ์œผ๋ฉด, ์–ด๋–ค ๋ฐฉ์‹์œผ๋กœ ์ฝ”๋“œ๊ฐ€ ๋‚˜์˜ค๋ƒ๋ฉด

username=$apple$ and password=$11111$
username=$apple$ and password=$2222$
username=$apple$ and password=$333$
username=$ball$ and password=$11111$
username=$ball$ and password=$2222$
username=$ball$ and password=$333$
username=$cat$ and password=$11111$
username=$cat$ and password=$2222$
username=$ball$ and password=$333$

์ด๋Ÿฐ์‹์ด๋‹ค.

๋”ฐ๋ผ์„œ ์ „์ฒด request ๊ฐœ์ˆ˜=#wordlist1 * #wordlist2 ์ด๋‹ค.

'

 

์•„๋ฌดํŠผ ์ด๋ ‡๊ฒŒ Intruder ์•ˆ์— ์žˆ๋Š” ๊ธฐ๋Šฅ์„ ์‚ดํŽด๋ณด์•˜๋‹ค!

 

 

์•„๋ž˜ ๊ธ€๋„ ์‰ฝ๊ฒŒ ์ž˜ ์„ค๋ช…์ด ๋˜์–ด์žˆ๋‹ค!

https://securitycode.tistory.com/21

 

Burp Suite(๋ฒ„ํ”„์Šค์œ„ํŠธ) ๋ฉ”๋‰ด Intruder

์ด ๋„๊ตฌ๋ฅผ ์ด์šฉํ•˜์—ฌ ํ—ˆ์šฉ๋ฐ›์ง€ ์•Š์€ ์„œ๋น„์Šค ๋Œ€์ƒ์œผ๋กœ ํ•ดํ‚น์„ ์‹œ๋„ํ•˜๋Š” ํ–‰์œ„๋Š” ๋ฒ”์ฃ„ ํ–‰์œ„ ์ž…๋‹ˆ๋‹ค. ํ•ดํ‚น์„ ์‹œ๋„ํ•  ๋•Œ์— ๋ฐœ์ƒํ•˜๋Š” ๋ฒ•์ ์ธ ์ฑ…์ž„์€ ๊ทธ๊ฒƒ์„ ํ–‰ํ•œ ์‚ฌ์šฉ์ž์—๊ฒŒ ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ๋ช…์‹ฌํ•˜์‹œ๊ธฐ

securitycode.tistory.com

 

profile

rosieblue

@Rosieblue

ํฌ์ŠคํŒ…์ด ์ข‹์•˜๋‹ค๋ฉด "์ข‹์•„์š”โค๏ธ" ๋˜๋Š” "๊ตฌ๋…๐Ÿ‘๐Ÿป" ํ•ด์ฃผ์„ธ์š”!