eli_ez3r
eli_ez3r
eli_ez3r
์ „์ฒด ๋ฐฉ๋ฌธ์ž
์˜ค๋Š˜
์–ด์ œ
  • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (202)
    • 0x01 ๋„์ ๋„์  :) (57)
      • Network (5)
      • Security (14)
      • Reversing (2)
      • Forensic (5)
      • Operation System (10)
      • Development (10)
      • Solution (7)
      • ๋ณด์•ˆ ์ƒ์‹ (3)
    • 0x02 Study :) (127)
      • Pwnable (59)
      • Webhacking (56)
      • Reversing (11)
      • Machine Learning (1)
    • 0x03 ETC :) (16)
      • IT Unpacking (5)
      • IT Information (1)
      • Enjoy (4)
      • Etc (6)
    • Admin :) (0)
      • 0x01 (0)

๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

  • ํ™ˆ
  • ํƒœ๊ทธ
  • ๋ฐฉ๋ช…๋ก

๊ณต์ง€์‚ฌํ•ญ

  • github.io ๋ธ”๋กœ๊ทธ ๊ฐœ์„ค

์ธ๊ธฐ ๊ธ€

ํƒœ๊ทธ

  • ์„ค๋ช…
  • hacking
  • ๋ฌธ์ œ
  • ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ
  • ๊ณต๊ฒฉ
  • BOF
  • ๋ฌธ์ œํ’€์ด
  • ์•”ํ˜ธ
  • LOB
  • pwnable
  • ํ’€์ด
  • hakcing
  • write
  • password
  • ๋ฉ”๋ชจ๋ฆฌ
  • ํŒจ์Šค์›Œ๋“œ
  • school
  • hack
  • LEVEL
  • web
  • ๊ณผ์ •
  • ํ•ดํ‚น
  • ์Šค์ฟจ
  • overflow
  • attack
  • buffer
  • Up
  • hacker
  • webhacking.kr
  • ํ•ด์ปค

์ตœ๊ทผ ๋Œ“๊ธ€

์ตœ๊ทผ ๊ธ€

ํ‹ฐ์Šคํ† ๋ฆฌ

hELLO ยท Designed By ์ •์ƒ์šฐ.
eli_ez3r

eli_ez3r

webhacking.kr Level 52 ๋ฌธ์ œํ’€์ด
0x02 Study :)/Webhacking

webhacking.kr Level 52 ๋ฌธ์ œํ’€์ด

2018. 7. 29. 10:44

Level 52



๐Ÿ˜ญ ์ฃฝ์–ด๋ผ ์‚ฝ์งˆํ–ˆ๋˜ ๋ฌธ์ œ... ์•„์ง๋„ ๋ฌธ์ œ ์ถœ์ œ์˜๋„ ์ดํ•ด๊ฐ€ ์•ˆ๊ฐ„๋‹ค.


์‚ฝ์งˆ ์ด์œ ๋ฅผ ๋งํ•˜์ž๋ฉด, ๋ฌธ์ œ์—์„œ id=haks2198๋ผ๋Š” ์ฟ ํ‚ค๋ฅผ ์ƒ์„ฑํ•˜๋ผ๊ณ  ํ•˜๋Š”๋ฐ, ์ฟ ํ‚ค์ƒ์„ฑํ•  ํ•„์š”๊ฐ€ ์—†๋‹ค ;;


 

๊ทธ๋ž˜๋„ ํ’€์ด ๊ณผ์ •์„ ์ ์–ด๋ณด์ž๐Ÿ’ข


'ํ—ค๋”์ธ์ ์…˜'์ด๋ผ๋Š” ๋‹จ์–ด๋ฅผ ์ฒ˜์Œ ์ ‘ํ•˜๊ฒŒ ๋˜์–ด ๊ตฌ๊ธ€๋ง์„ ํ•ด๋ณด์•˜๋‹ค.

ํ—ค๋”์ธ์ ์…˜์€ ๊ณต๊ฒฉ์ž๊ฐ€ ํ—ค๋”์— ๊ฐœํ–‰๋ฌธ์ž๋ฅผ ์‚ฝ์ž…ํ•ด ํ—ค๋”๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ๊ณต๊ฒฉํ•˜๋Š” ์ˆ˜๋™์  ๊ณต๊ฒฉ๋ฐฉ๋ฒ•์ด๋‹ค.

์ฆ‰ ๊ฐœํ–‰๋ฌธ์ž('\r\n')๋ฅผ ํ•„ํ„ฐ๋งํ•˜์ง€ ์•Š์œผ๋ฉด ์ƒ๊ธฐ๋Š” ๋ฌธ์ œ์ด๋‹ค.

\r(%0d) : Carrige Return ์ปค์„œ๋ฅผ ๋งจ ์•ž์œผ๋กœ ์ด๋™์‹œํ‚จ๋‹ค.

\n(%0a) : Line Feed ์ปค์„œ๋ฅผ ๋‹ค์Œ์ค„๋กœ ์ด๋™์‹œํ‚จ๋‹ค.

 

์ฟ ํ‚ค๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์€ 'Set-cookie:'๋ฅผ ์ด์šฉํ•˜๋ฉด ๋œ๋‹ค.

 

๋จผ์ € 'ํ—ค๋”์ƒ์„ฑ'์„ ๋ˆŒ๋ €์„ ๋•Œ ํŒจํ‚ท์„ ์‚ดํŽด๋ดค๋‹ค.



Request Headers ๋ฅผ ๋ณด๋ฉด ์ด๋ฏธ id=haks2198 ์ด๋ผ๋Š” ์ฟ ํ‚ค๊ฐ’์ด ๋“ค์–ด๊ฐ€ ์žˆ๋‹ค. ๐Ÿ˜ญ


Response Headers์—๋„ ์ •์ƒ์ ์œผ๋กœ ๋“ค์–ด๊ฐ€ ์žˆ๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.


๋”ฐ๋ผ์„œ Set-Cookie ๋ช…๋ น์„ ๋„ฃ์–ด ๊ตณ์ด ์•ˆ๋ฐ”๊ฟ”๋„ ๋œ๋‹ค๋Š” ๋ง์”€....๐Ÿ˜ฉ (์ด ์ƒ๊ฐ์ด ๋งž๋Š”๊ฑด์ง€ ํ™•์‹ ์€ ์—†๋‹ค.)


์ด ์‚ฌ์‹ค์„ ๋ชฐ๋ž์œผ๋ฏ€๋กœ, ์‚ฝ์งˆํ•œ ๊ณผ์ •์„ ์„ค๋ช…ํ•˜์ž๋ฉด...


์ฟ ํ‚ค์— id=haks2198๋ฅผ ๋„ฃ๊ธฐ ์œ„ํ•ด ?id=haks2198%0d%0aSet-Cookie:%20id=haks2198 ์ด๋ผ๋Š” url์„ ๋„˜๊ฒจ์ฃผ์—ˆ๋‹ค.


๋‹น์—ฐํžˆ ์•ˆํ’€๋ฆฐ๋‹ค.


์ด ๋ฌธ์ œ๋Š” 'clear: haks2198'์„ ๋„˜๊ฒจ์ฃผ๋ฉด ๋ฌธ์ œ๊ฐ€ ํ’€๋ฆฐ๋‹ค.


?id=haks2198%0d%0aclear:%20haks2198



 

 

 

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ ๋ณ€๊ฒฝ๊ธˆ์ง€ (์ƒˆ์ฐฝ์—ด๋ฆผ)
    '0x02 Study :)/Webhacking' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
    • webhacking.kr Level 56 ๋ฌธ์ œํ’€์ด
    • webhacking.kr Level 54 ๋ฌธ์ œํ’€์ด
    • webhacking.kr Level 51 ๋ฌธ์ œํ’€์ด
    • webhacking.kr Level 47 ๋ฌธ์ œํ’€์ด
    eli_ez3r
    eli_ez3r

    ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”