wargame ๐Ÿด‍โ˜ ๏ธ write-up 39

darkelf

query : {$query}"; $result = @mysqli_fetch_array(mysqli_query($db,$query)); if($result['id']) echo "Hello {$result[id]}"; if($result['id'] == 'admin') solve("darkelf"); highlight_file(__FILE__); ?> or๊ณผ and๋ฅผ ์ถ”๊ฐ€๋กœ ํ•„ํ„ฐ๋ง ํ•œ๋‹ค.||, &&๋กœ ๋ฐ”๊พธ์–ด ์šฐํšŒํ•ด๋ณด์ž. ?pw=1'||id='admin ๊ฒฐ๊ณผ๋Š” ์„ฑ๊ณต..!

wolfman

query : {$query}"; $result = @mysqli_fetch_array(mysqli_query($db,$query)); if($result['id']) echo "Hello {$result[id]}"; if($result['id'] == 'admin') solve("wolfman"); highlight_file(__FILE__); ?> ์ฝ”๋“œ๋ฅผ ๋ณด๋ฉด, ๊ณต๋ฐฑ์„ ํ•„ํ„ฐ๋งํ•˜๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ๊ณต๋ฐฑ์„ ์šฐํšŒํ•˜๋Š” ๋ฐฉ๋ฒ•์€ (), /**/, %0a๋“ฑ ์—ฌ๋Ÿฌ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์ด ์žˆ๋Š”๋ฐ()๊ฐ€ ํ•„ํ„ฐ๋ง๋œ ๊ด€๊ณ„๋กœ, /**/์„ ์‚ฌ์šฉํ•˜์—ฌ ํ’€๊ฒƒ์ด๋‹ค. ?pw=1'or/**/id='admin ํ•ด๊ฒฐ๐Ÿ˜Ž

goblin

query : {$query}"; $result = @mysqli_fetch_array(mysqli_query($db,$query)); if($result['id']) echo "Hello {$result[id]}"; if($result['id'] == 'admin') solve("goblin"); highlight_file(__FILE__); ?>no ๊ฐ’์— ์—ฌ๋Ÿฌ ์ˆซ์ž๋ฅผ ๋„ฃ์–ด๋ดค๋”๋‹ˆ guest : 1 ์ž„์ด ํ™•์ธ๋ฌ๋‹ค.no ๊ฐ’์— ์•„๋ฌด๋Ÿฐ ๋”ฐ์˜ดํ‘œ๊ฐ€ ์—†์œผ๋ฏ€๋กœ, ํŽธํ•˜๊ฒŒ ๋’ท ๋ฌธ์žฅ์„ ๋งŒ๋“ค์–ด๊ฐˆ ์ˆ˜ ์žˆ๋‹ค.*์ฐธ๊ณ ๋กœ and๋กœ ๋ฌถ์ธ ์กฐ๊ฑด์ด ๊ฑฐ์ง“์ด ๋˜์–ด์•ผ ํ•˜๋‹ˆ 1์ด ์•„๋‹Œ ์•„๋ฌด ์ˆซ์ž๋ฅผ ๋„ฃ๊ณ  ๋งŒ๋“ค์–ด๊ฐ€์ž ํ•˜์ง€๋งŒ ์ž‘์€ ๋”ฐ์˜ดํ‘œ๋ฅผ ํ•„ํ„ฐ๋ง ํ•˜๊ณ ์žˆ์–ด, id='admin'๊ณผ ๊ฐ™์€ ๊ฐ’์€ ๋ณด๋‚ด์ง€ ๋ชปํ•œ๋‹ค.๊ทธ๋ ‡๋‹ค๋ฉด ๋” ๊ฐ„๋‹จํ•œ ๋ฐฉ๋ฒ•. no๋ฅผ ..

cobolt

query : {$query}"; $result = @mysqli_fetch_array(mysqli_query($db,$query)); if($result['id'] == 'admin') solve("cobolt"); elseif($result['id']) echo "Hello {$result['id']}You are not admin :("; highlight_file(__FILE__); ?> gremlin ๋ฌธ์ œ์ฒ˜๋Ÿผ ์ฃผ์„์„ ์ด์šฉํ•˜์—ฌ pwํ™•์ธ ๋ถ€๋ถ„์„ ๋ฌด์‹œํ•  ์ˆ˜๋„ ์žˆ๊ฒ ์ง€๋งŒ๋‚ญ๋งŒ์žˆ๊ฒŒ ๊ด„ํ˜ธ๋ฅผ ๋”ฐ๋ผ ๋‹ซ์•„๋ณด์ž pw ๋ถ€๋ถ„ ๊ด„ํ˜ธ๋ฅผ ์ฒ˜๋ฆฌํ•ด์ฃผ๊ณ , or id=admin์œผ๋กœ ์ธ์ฆํ•  ์ƒ๊ฐ์ด๋‹ค.?id=admin&pw=') or (id='admin ํด๋ฆฌ์—‰

gremlin

query : {$query}"; $result = @mysqli_fetch_array(mysqli_query($db,$query)); if($result['id']) solve("gremlin"); highlight_file(__FILE__);?> preg_match๋ฅผ ๋ณด๋ฉด ํ•„ํ„ฐ๋ง ๋˜๊ณ ์žˆ๋Š” ๋ฌธ์ž๋“ค์ด ์žˆ๋‹ค.query์˜ id๋ถ€๋ถ„ ์ž‘์€ ๋”ฐ์˜ดํ‘œ๋ฅผ ๋‹ซ๊ณ , ๋’ค์˜ and pw๋ถ€๋ถ„์€ ์ฃผ์„์ฒ˜๋ฆฌํ•ด๋ณด๋ฉด   ํ’€๋ฆฐ๋‹ค.sql์˜ ์ฃผ์„์€ ์—ฌ๋Ÿฌ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์ด ์žˆ๋Š”๋ฐ#;%00-- -/* */์ƒํ™ฉ์— ๋งž๋Š” ๋ฐฉ์‹์„ ํƒํ•˜๋ฉด ๋œ๋‹ค.

1. fd

http://pwnable.kr/# http://pwnable.kr/ there are flag files corresponding to each challenges (similar to CTF), you need to read it and submit to pwnable.kr to get the corresponding point. in order to read the flag file, you need some skills regarding programming, reverse-engineering, bu pwnable.kr ์ฒซ ๋ฒˆ์งธ ๋ฌธ์ œ fd *.* ์—„๋งˆ๋ฅผ ์ฐพ๋Š” ํ•œ ์•„์ด๊ฐ€ ๋งํ•˜๋„ค์š” "ํŒŒ์ผ ๋””์Šคํฌ๋ฆฝํ„ฐ๊ฐ€ ๋ญ์•ผ?? ๋€จ>