Home
glasses96
Cancel

Hack The Box - Precious

Hack the Box Precious ๋ฌธ์ œ๋ฅผ ํ’€์–ด ๋ด…์‹œ๋‹ค. Port Scanning nmap ์Šค์บ๋‹ ๊ฒฐ๊ณผ๋ฅผ ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค. ssh ์„œ๋น„์Šค์™€ http ์„œ๋น„์Šค๊ฐ€ ์—ด๋ ค์žˆ์Šต๋‹ˆ๋‹ค. ssh์˜ ๊ณ„์ • ์ •๋ณด๋Š” ๋ชจ๋ฅด๊ธฐ ๋•Œ๋ฌธ์— http ์„œ๋น„์Šค์— ์ ‘์†ํ•ด ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. hosts ํŒŒ์ผ์— precious.htb๋ฅผ ๋“ฑ๋กํ•˜๋ฉด ์›น ํŽ˜์ด์ง€์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ...

Reversing Dreamhack Helloworld

๋“œ๋ฆผํ•ต ๊ฐ•์˜๋ฅผ ํ†ตํ•ด Helloworld.exe๋ฅผ ๋ถ„์„์„ ํ•ด๋ด…์‹œ๋‹ค. Helloworld Code ๊ฐ„๋‹จํ•œ ์˜ˆ์ œ์ธ HelloWorld.exe๋ฅผ ๋ถ„์„ํ•ด๋ณด์ž ์†Œ์Šค ์ฝ”๋“œ๋Š” 1์ดˆ๋ฅผ ๋Œ€๊ธฐํ•˜๊ณ  Hello, world!๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ž…๋‹ˆ๋‹ค. #include <Windows.h> #include <stdio.h> char* st...

Hack The Box - Photobomb vulnerability analysis

Photobomb ๋ฌธ์ œ๋ฅผ ํ’€๋ฉด์„œ ๋‚˜์™”๋˜ ์ทจ์•ฝ์ ์„ ๋ถ„์„์„ ํ•ด๋ด…์‹œ๋‹ค. Flag๋ฅผ ์ฐพ๋Š” ๊ฒƒ๋„ ์ค‘์š”ํ•˜์ง€๋งŒ ์™œ ์ทจ์•ฝ์ ์ด ํ„ฐ์ง€๋Š”์ง€ ์›์ธ์„ ์•„๋Š” ๊ฒƒ์ด ๊ต‰์žฅํžˆ ์ค‘์š”ํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.โ—๏ธโ—๏ธโ—๏ธ. Basic Authentication ์ฒซ๋ฒˆ์งธ๋กœ ๋ฐœ๊ฒฌ๋œ ์ทจ์•ฝ์ ์€ Baisc Authentication ์ •๋ณด๊ฐ€ ๋…ธ์ถœ๋˜์—ˆ๋˜ ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. What is Basic...

Hack The Box - Photobomb

Hack the Box์˜ Photobomb์„ ํ’€์–ด๋ด…์‹œ๋‹ค. Port Scanning ์ œ์ผ ๋จผ์ € nmap์„ ์ด์šฉํ•˜์—ฌ ํฌํŠธ์Šค์บ”์„ ๋Œ๋ ธ์„ ๋•Œ ๋‚˜์˜ค๋Š” ๊ฒฐ๊ณผ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ํฌํŠธ๊ฐ€ ์—ด๋ ค์žˆ์œผ๋ฉฐ ssh ์—ฐ๊ฒฐ์€ ID์™€ ํŒจ์Šค์›Œ๋“œ๋ฅผ ๋ชจ๋ฅด๋‹ˆ http ๋ถ€ํ„ฐ ์ ‘๊ทผ์„ ์‹œ๋„ํ–ˆ๋‹ค. ssh http HTTP Service ๊ทธ๋ƒฅ ์ ‘๊ทผํ•˜๋ฉด ...

Hack The Box - Fawn

Hack the box ๊ธฐ์ดˆ์ค‘ Fawn์„ ํ’€์–ด๋ด…์‹œ๋‹ค Fawn Quiz ํ˜•์‹์˜ ๋ฌธ์ œ๋ฅผ ๋ณด๋ฉด FTP ๊ด€๋ จ ๋ฌธ์ œ๋“ค์ด๋‹ค. Nmap์„ ํ†ตํ•ด FTP ์„œ๋น„์Šค๊ฐ€ ์—ด๋ ค์žˆ๋Š” ๊ฒƒ์„ ํŒŒ์•…ํ•˜๊ณ  FTP ๋ฒ„์ „์ด๋ผ๋˜์ง€ ์ต๋ช…(Anonymous)FTP๋กœ ์ ‘๊ทผํ•˜์—ฌ Flag๋ฅผ ์ฐพ๋„๋ก ๋˜์–ด ์žˆ๋‹ค. Anonymous๋กœ FTP๋ฅผ ์ ‘๊ทผํ•˜์—ฌ flag.txt๋ฅผ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์„ ์ˆ˜ ์žˆ๋‹ค...

How to Extract Dynamic DEX Loading

์ตœ๊ทผ ๋ชจ๋ฐ”์ผ ์ง„๋‹จ ์ค‘ ๋ฃจํŒ…ํƒ์ง€๋ฅผ ํ•˜๊ณ  ์žˆ์ง€๋งŒ ์–ด๋””์„œ ํ˜ธ์ถœํ•˜๋Š”์ง€๋ฅผ ์ฐพ์„ ์ˆ˜๊ฐ€ ์—†์—ˆ๋Š”๋ฐ ์–ด์ฐŒ์ €์ฐŒ ํ•˜๋‹ค๊ฐ€ Dynamic Dex Loading์ด ์ ์šฉ๋œ ๊ฒƒ์„ ๋ฐœ๊ฒฌ ํ•˜์˜€์Šต๋‹ˆ๋‹ค. Dynamic Dex Loading์„ ํ•˜๋Š” App์—์„œ DEX๋ฅผ ์ถ”์ถœํ•˜๋Š” ๋ฐฉ๋ฒ•๋“ค์— ๋Œ€ํ•ด์„œ ์•Œ์•„๋ด…์‹œ๋‹ค. Dynamic Dex Loading ๐Ÿ”ตโšช๏ธ๐Ÿ”ด Dynamic Dex Loa...

Frida TCP Hooking

TCP ํ†ต์‹ ์„ MITM Relay๊ฐ€ ์•„๋‹Œ Frida ํ›„ํ‚น์„ ํ†ตํ•ด ํŒจํ‚ท์„ ์žก์•„๋ด…์‹œ๋‹ค. ๊ฐœ์š” ์†Œ์ผ“ ํ†ต์‹ ์—์„œ C/C++ ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์€ ๋ฐ์ดํ„ฐ ์†ก์ˆ˜์‹  ํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค. send(), recv() sendto(), rectfrom() ํ•จ์ˆ˜ ์›ํ˜• ํ•จ์ˆ˜ ์›ํ˜•์€ ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค. send(int sockfd, co...

Error Based & Error based Blind SQL Injection

DreamHack ๊ฐ•์˜๋ฅผ ํ†ตํ•ด Error Based SQL Injection๊ณผ Error Based Blind SQL Injection์— ๋Œ€ํ•ด์„œ ์•Œ์•„๋ด…์‹œ๋‹ค. Error Based SQL Injection Dreamhack ๊ฐ•์˜๋ฅผ ํ†ตํ•ด Error Based SQL Injection์ด ๋ฌด์—‡์ธ์ง€ ์•Œ์•„๋ด…์‹œ๋‹ค. Error Based SQL I...

ICMP Tunneling by Python with Scapy

ICMP Tunneling์„ ํ†ตํ•ด ๋‚ด๋ถ€๋ง ๊ฐ„ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚ด๋ถ€๋ง ๊ฐ„ ping ๋ช…๋ น์–ด๊ฐ€ ๋™์ž‘์„ ํ•˜๊ฒŒ ๋  ๊ฒฝ์šฐ ICMP Tunneling์„ ์ด์šฉํ•˜์—ฌ DATA๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. What is ICMP? ICMP์— ๋Œ€ํ•˜์—ฌ ๊ฐ„๋‹จํ•˜๊ฒŒ ์•Œ์•„๋ณด๋ฉด ์ธํ„ฐ๋„ท ์ œ์–ด ๋ฉ”์‹œ์ง€ ํ”„๋กœํ† ์ฝœ์œผ๋กœ ์ผ๋ฐ˜์ ์œผ๋กœ IP ๋™์ž‘์—์„œ ์ง„๋‹จ์ด๋‚˜ ์ œ์–ด๋กœ ์‚ฌ์šฉ๋˜...

Blind SQLi With Binary Search & Python

์ด๋ฒˆ์—๋Š” Binary Search๋ฅผ ์ด์šฉํ•˜์—ฌ DB๋ฅผ ์ถ”์ถœํ•  ์ˆ˜์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ด…์‹œ๋‹ค. Binary Search Binary Search๋ž€ ์ด์ง„ํƒ์ƒ‰ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋ผ ํ•˜๋ฉฐ ์ •๋ ฌ๋œ ๋ฐ์ดํ„ฐ์—์„œ ๊ฒ€์ƒ‰ ๋ฒ”์œ„๋ฅผ ์ค„์—ฌ ๋‚˜๊ฐ€๋ฉด์„œ ์›ํ•˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์ž…๋‹ˆ๋‹ค. Contain DB Name test๋Š” acunetix์˜ ์ทจ์•ฝํ•œ ํŽ˜์ด์ง€๋กœ ์ง„ํ–‰...

Blind SQLi With Bit operation & Burp Intruder

Bit operation์„ ์ด์šฉํ•˜์—ฌ ๋ฒ„ํ”„์Šค์œ„ํŠธ์˜ Intruder ๊ธฐ๋Šฅ์œผ๋กœ ๊ฐ„๋‹จํ•˜๊ฒŒ DB๋ฅผ ์ถ”์ถœํ•  ์ˆ˜์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ด…์‹œ๋‹ค. Bit operation ํ•ญ์ƒ Binary Search๋ฅผ ์ด์šฉํ•˜์—ฌ Blind SQLi ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋ฅผ ๋งŒ๋“ค์—ˆ๋Š”๋ฐ ๋“œ๋ฆผํ•ต ๊ฐ•์˜๋ฅผ ํ†ตํ•ด MySQL DB์—์„œ Bit operation์„ ์ด์šฉํ•ด๋„ ๋˜๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค ...

XSS Filtering bypass with JSFuck

XSS๋ฅผ ๋ฐœ๊ฒฌํ–ˆ์ง€๋งŒ alert, confirm, prompt๋“ฑ ๋ฌธ์ž์—ด์ด WAF์—์„œ ํ•„ํ„ฐ๋ง ๋˜์—ˆ์„ ๋•Œ JSFuck์„ ์ด์šฉํ•˜์—ฌ ์ด๋ฅผ ์šฐํšŒํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ด…์‹œ๋‹ค. What is JSFuck? ์œ„ํ‚ค์— ๋”ฐ๋ฅด๋ฉด JavaScript ๋ฌธ๋ฒ•์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๋ฌธ์ž ์ค‘ ๋‹จ 6๊ฐ€์ง€์ธ [,],(,),!,+ ๋งŒ์œผ๋กœ ๊ตฌํ˜„ํ•  ์ˆ˜ ์žˆ์Œ์— ์ฐฉ์•ˆํ•˜์—ฌ ๊ณ ์•ˆ๋œ ๋‚œํ•ดํ•œ ํ”„๋กœ๊ทธ๋ž˜...