rosieblue
[๋“œ๋ฆผํ•ต(Dreamhack)] xss-1
๐Ÿ” Security/Web 2023. 9. 22. 22:22

@app.route("/flag", methods=["GET", "POST"]) def flag(): if request.method == "GET": return render_template("flag.html") elif request.method == "POST": param = request.form.get("param") form์—์„œ param์„ param์œผ๋กœ ์ €์žฅ if not check_xss(param, {"name": "flag", "value": FLAG.strip()}): return '' return '' ์—ฌ๊ธฐ์„œ check_xss(param, {"name": "flag", "value": FLAG.strip()}) ํ˜ธ์ถœ param์€ ์šฐ๋ฆฌ๊ฐ€ flag์—์„œ form์œผ๋กœ ์ž…๋ ฅํ•œ ์ธ์ž. @ap..

article thumbnail
[Security] ์ƒŒ๋“œ๋ฐ•์Šค(Sandbox)์™€ ์ƒŒ๋“œ๋ฐ•์Šค์˜ ์ทจ์•ฝ์ 
๐Ÿ” Security 2023. 5. 12. 19:05

์ƒŒ๋“œ๋ฐ•์Šค ์•„๋ž˜ ์ƒŒ๋“œ๋ฐ•์Šค์˜ ์ •์˜์— ๋Œ€ํ•ด ์‰ฝ๊ฒŒ ์„ค๋ช…ํ•ด ๋†“์€ ์ข‹์€ ๊ธ€์ด ์žˆ์–ด์„œ ์ด๋ฅผ ๋ฐœ์ทŒํ•ด ๋ณด์•˜๋‹ค. "Sandboxing is a form of software virtualization that lets programs and processes run in its isolated virtual environment. Typically, programs running within the sandbox have limited access to your files and system, and they can make no permanent changes. That means that whatever happens in the sandbox stays in the sandbox." (https://web.archi..

article thumbnail
[BurpSuite] Cluster Bomb Attack
๐Ÿ” Security/Web 2023. 3. 6. 15:55

์˜ค๋Š˜์€ ๋ฒ„ํ”„์Šค์œ„ํŠธ์˜ cluster bomb ๊ธฐ๋Šฅ์„ ๋Œ€์ถฉ ์š”์•ฝํ•œ ๊ธ€์ด๋‹ค. ์ฃผ์ €๋ฆฌ ๋งŽ์Œใ…Žใ…Ž ใ…  Burp Suite์˜ Intruder๋ฅผ ์ด์šฉํ•ด Blind SQL Injection์„ ์ง„ํ–‰ํ•˜๋˜ ๋„์ค‘ ๋ณ€์ˆ˜ 2๊ฐœ์— ๋Œ€ํ•ด ๊ฐ๊ธฐ ๋‹ค๋ฅธ ๊ทœ์น™์„ ์ ์šฉํ•ด์ฃผ์–ด์•ผํ•˜๋Š” ์ผ์ด ์žˆ์—ˆ๋‹ค. ๋‚˜๋Š” ๋ฐ”๋ณด๊ฐ™์ด......... Cluster Bomb์ด๋ผ๋Š” ๋ฉ‹์ง„ ์•„์ด๊ฐ€ ์žˆ๋Š” ์ค„๋„ ๋ชจ๋ฅด๊ณ  ...... ์ˆ˜๋™์œผ๋กœ ๊ณต๊ฒฉ์„ ์ง„ํ–‰ํ–ˆ๋‹ค....... ์œ„ ๊ธ€์— ๋”ฐ๋ฅด๋ฉด "This attack iterates through a different payload set for each defined position. The Cluster Bomb Attack is useful where an attack requires unrelated or unknown input t..

article thumbnail
[Security] Fuzzer, Fuzzing ์ด๋ž€?
๐Ÿ” Security 2023. 3. 3. 16:01

์˜ค๋Š˜์€ Fuzzer, Fuzzing์— ๋Œ€ํ•ด์„œ ๊ฐ„๋‹จํ•˜๊ฒŒ ๋‹ค๋ค„๋ณด๋ ค๊ณ  ํ•œ๋‹ค "Fuzzing refers to a process of repeatedly running a program with generated inputs to test if a program violates a correctness policy." ๋ผ๊ณ  ํ•œ๋‹ค. ๊ฑ ์ทจ์•ฝ์  ๋ถ„์„์„ ์œ„ํ•ด์„œ ์ธํ’‹์„ ๋ฐ˜๋ณตํ•ด์„œ ์—„์ฒญ ๋งŽ์ด ๋„ฃ์–ด๋ด์„œ(๋žœ๋คํ•˜๋“  ์•ˆ ๋žœ๋คํ•˜๋“ ) ๋ฒ„๊ทธ๊ฐ™์€ ๊ฑฐ ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๋Š” ๊ฑฐ๋‹ค!!!! ๊ทธ ๋‚ด๊ฐ€ Python ํ†ตํ•ด์„œ Blind SQL Injection ์ž๋™ํ™” ๋„๊ตฌ ๋งŒ๋“ค๋ ค๊ณ  ํ–ˆ๋˜๊ฑฐ๋ž‘ ๋น„์Šทํ•œ๊ฑธ๋กœ ๋ณด์ธ๋‹ค(์•„๋งˆ?) ๊ทผ๋ฐ ์ผ๋‹จ ์ € Python ํ†ตํ•ด์„œ ๋งŒ๋“œ๋Š”๊ฑฐ๋ž‘ ใ„นใ…‡๋กœ ๋น„์Šทํ•œ ๊ฑฐ๋ฉด fuzzer ๋งŒ๋“œ๋Š”๊ฑด ๊ฝค๋‚˜ ๋‚ด ์ทจํ–ฅ์ผ ์ˆ˜๋„...? ์™œ๋ƒ๋ฉด ๊ฐœ๋ฐœ๋„ ์žฌ๋ฐŒ๊ณ  ๋ณด์•ˆ..

article thumbnail
[BurpSuite] Intruder ๊ธฐ๋Šฅ ์•ˆ์˜ ๊ณต๊ฒฉ๋“ค ์ •๋ฆฌ
๐Ÿ” Security/Web 2023. 3. 3. 12:41

์‚ฌ์‹ค BurpSuite์˜ Intruder ๊ธฐ๋Šฅ ์ค‘ Cluster Bomb์— ๋Œ€ํ•ด์„œ ํฌ์ŠคํŒ…์„ ์“ฐ๋˜ ๋„์ค‘, Pitchfork ๋ผ๋Š” ๊ณต๊ฒฉ์ด ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ๋˜์—ˆ๋Š”๋ฐ ์–˜๋„ค ๋‘˜์ด ๋น„์Šทํ•ด๋ณด์—ฌ์„œ ๋‘˜์ด ๋ฌด์—‡์ด ๋‹ค๋ฅผ๊นŒ? ์— ๋Œ€ํ•ด์„œ ์ฐพ์•„๋ณด๋‹ค๊ฐ€ ํฌ์ŠคํŒ…์„ ์ƒˆ๋กœ ์“ฐ๊ฒŒ ๋˜์—ˆ๋‹ค https://systemweakness.com/attack-types-in-intruder-burpsuite-5c65900f71c7 Attack Types In Intruder (Burpsuite) It has been a while since I’ve published any articles. Today I would like to write on the attack types used in intruder. I’m skipping all… system..

article thumbnail
[SQL Injection ํŒ] ๋‚ด๊ฐ€ ์ถ”์ธกํ•œ ๋ฉ”ํƒ€์ •๋ณด(ํ…Œ์ด๋ธ”๋ช…/์นผ๋Ÿผ๋ช… ๋“ฑ)์ด ๋งž๋Š”์ง€ ํ™•์ธํ•˜๋Š” ๋ฐฉ๋ฒ•
๐Ÿ” Security/Web 2023. 3. 2. 20:44

WHERE ์ ˆ์ด ์žˆ๊ณ , ๊ทธ WHERE ์ ˆ์ด ์ฐธ์ด๋ผ๋Š”๊ฒƒ์ด ๊ฐ€์ •๋˜์–ด์žˆ์„ ๋•Œ, ๊ทธ WHERE์ ˆ ๋’ค์— AND ๋ฅผ ์‚ฝ์ž…ํ•˜๋ฉด ๊ฐ€ ์ฐธ์ผ ๋•Œ๋งŒ ์ฟผ๋ฆฌ๋ฌธ์ด ์ž‘๋™ํ•œ๋‹ค. ์šฐ๋ฆฌ๋Š” ๋ถ€๋ถ„์ด ์ฐธ์ธ์ง€ ๊ฑฐ์ง“์ธ์ง€ ๊ฒ€์‚ฌํ•˜๊ณ  ์‹ถ์„ ๋•Œ ์ด ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•œ๋‹ค. ๋งŒ์•ฝ ์ฟผ๋ฆฌ๋ฌธ์ด ์ œ๋Œ€๋กœ ์ž‘๋™ํ–ˆ๋‹ค๋ฉด ๋ถ€๋ถ„์ด ์ฐธ์ด๋ผ๋Š” ๋œป์ผ ๊ฒƒ์ด๋‹ค. ์œ„ ๋‚ด์šฉ์ด Blind Injection ๊ณต๊ฒฉ์˜ ํ๋ฆ„์ด๋‹ค. ๊ณต๊ฒฉ์„ ํ–‰ํ•  ๋•Œ ๊ผญ ์ค‘์š”ํ•œ ์ •๋ณด(ex: password ์ฒซ๊ธ€์ž๊ฐ€ 'm'์ธ๊ฐ€? ์ด๋Ÿฐ๊ฑฐ ๋ง๊ณ ) ๊ฐ„๋‹จํ•œ ์ •๋ณด(๋ฉ”ํƒ€ ์ •๋ณด)๋„ ์ด์™€ ๊ฐ™์€ ๋ฐฉ์‹์œผ๋กœ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ๋‹ค. ์—ฌ๊ธฐ์„œ ์‹ ๊ธฐํ•œ ๊ฒƒ์€ ์–ด๋–ค ์ •๋ณด๊ฐ€ ์กด์žฌํ•˜๋ƒ, ๋งˆ๋Š๋ƒ๋„ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์ด๋‹ค!! ๊ทธ๋ ‡๋‹ค๋ฉด ์กด์žฌ์„ฑ์— ๋Œ€ํ•œ ์ฟผ๋ฆฌ๋Š” ์–ด๋–ป๊ฒŒ ์งœ๋ฉด ์ข‹์„๊นŒ? ์•ž์— ์ƒ์ˆ˜๋ฅผ select ํ•ด์ฃผ๋ฉด๋œ๋‹ค. ์ด๊ฒŒ ๋ฌด์Šจ ๋œป์ผ๊นŒ? ์˜ˆ๋ฅผ ๋“ค์–ด 'users' ๋ผ๋Š”..