wargame ๐Ÿด‍โ˜ ๏ธ write-up/Lord of SQLInjection 20

giant

1. Code 2. Condition GET ํŒŒ๋ผ๋ฏธํ„ฐ shit์„ ๋ฐ›์•„์˜จ๋‹ค. ๊ณต๋ฐฑ(%20), ๊ฐœํ–‰(%0a), ์บ๋ฆฌ์ง€ ๋ฆฌํ„ด(%0d), ํƒญ(%09)์„ ํ•„ํ„ฐ๋ง ํ•œ๋‹ค. 3. Solution $query = "select 1234 from{$_GET[shit]}prob_giant where 1"; ๊ฐ„๋‹จํžˆ shit์— ๊ณต๋ฐฑ์„ ๋„ฃ์–ด์ฃผ๋ฉด ํ’€๋ฆฌ๋Š” ๋ฌธ์ œ์ด๋‹ค. img_1์† 0x0b๋ฅผ ๋ณด๋ฉด, vertical tab ์ด๋ผ ์ ํ˜€์žˆ๋‹ค. vertical tab(\v)์ด๋ž€, ํ”„๋ฆฐํŠธ์— ์‚ฌ์šฉ๋˜๋˜ Tab์˜ ํ•œ ์ข…๋ฅ˜์ด๋‹ค. ์š”์ƒˆ๋Š” ์ž˜ ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š”๋‹ค. ์‹คํ–‰ํ•ด๋ณด๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด Tab์ด ์ด๋ฃจ์–ด ์ง„๋‹ค. ๊ฒฐ๊ณผ์ ์œผ๋กœ %0b๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋œ๋‹ค. ๋ณ€์ˆ˜๋ช… ๊ฐ’ shit %0b