<?php
include "./config.php";
login_chk();
$db = dbconnect();
if(preg_match('/\'/i', $_GET[id])) exit("No Hack ~_~");
if(preg_match("/admin/", $_GET[id])) exit("HeHe");
$query = "select id from prob_troll where id='{$_GET[id]}'";
echo "<hr>query : <strong>{$query}</strong><hr><br>";
$result = @mysqli_fetch_array(mysqli_query($db,$query));
if($result['id'] == 'admin') solve("troll");
highlight_file(__FILE__);
?>
admin์ ํํฐ๋ง ํ๊ณ ์๋ค.
orcํธ์์ ๋งํ๋ฏ์ด mysql์์ ๋๋ถ๋ถ์ ๋ฌธ์์๋ฃํ์ ๋น๊ต์ฐ์ฐ์ ๋์๊ตฌ๋ถ์ ํ์ง ์๋๋ค.
๋ฐ๋ผ์ adMin๊ณผ ๊ฐ์ด ๋๋ฌธ์๋ฅผ ์์ด ๋ณด๋ด์ฃผ๋ฉด, ํ๋ฆด๊ฒ์ด๋ค.
?id=adMin
'wargame ๐ดโโ ๏ธ write-up > Lord of SQLInjection' ์นดํ ๊ณ ๋ฆฌ์ ๋ค๋ฅธ ๊ธ
skeleton (0) | 2022.04.02 |
---|---|
vampire (0) | 2022.04.02 |
orge (0) | 2022.04.02 |
darkelf (0) | 2022.04.02 |