wargame ๐Ÿด‍โ˜ ๏ธ write-up/Lord of SQLInjection

troll

Kortsec1 2022. 4. 2. 17:32
<?php  
  include "./config.php"; 
  login_chk(); 
  $db = dbconnect(); 
  if(preg_match('/\'/i', $_GET[id])) exit("No Hack ~_~");
  if(preg_match("/admin/", $_GET[id])) exit("HeHe");
  $query = "select id from prob_troll where id='{$_GET[id]}'";
  echo "<hr>query : <strong>{$query}</strong><hr><br>";
  $result = @mysqli_fetch_array(mysqli_query($db,$query));
  if($result['id'] == 'admin') solve("troll");
  highlight_file(__FILE__);
?>

 

admin์„ ํ•„ํ„ฐ๋ง ํ•˜๊ณ ์žˆ๋‹ค.

orcํŽธ์—์„œ ๋งํ–ˆ๋“ฏ์ด mysql์—์„œ ๋Œ€๋ถ€๋ถ„์˜ ๋ฌธ์ž์ž๋ฃŒํ˜•์€ ๋น„๊ต์—ฐ์‚ฐ์‹œ ๋Œ€์†Œ๊ตฌ๋ถ„์„ ํ•˜์ง€ ์•Š๋Š”๋‹ค.

 

๋”ฐ๋ผ์„œ adMin๊ณผ ๊ฐ™์ด ๋Œ€๋ฌธ์ž๋ฅผ ์„ž์–ด ๋ณด๋‚ด์ฃผ๋ฉด, ํ’€๋ฆด๊ฒƒ์ด๋‹ค.

?id=adMin

 

๊ทธ๋ฆผ1 ์„ฑ๊ณต

'wargame ๐Ÿดโ€โ˜ ๏ธ write-up > Lord of SQLInjection' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

skeleton  (0) 2022.04.02
vampire  (0) 2022.04.02
orge  (0) 2022.04.02
darkelf  (0) 2022.04.02