Home
glasses96
Cancel

ICMP Tunneling by Python with Scapy

ICMP Tunneling์„ ํ†ตํ•ด ๋‚ด๋ถ€๋ง ๊ฐ„ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚ด๋ถ€๋ง ๊ฐ„ ping ๋ช…๋ น์–ด๊ฐ€ ๋™์ž‘์„ ํ•˜๊ฒŒ ๋  ๊ฒฝ์šฐ ICMP Tunneling์„ ์ด์šฉํ•˜์—ฌ DATA๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. What is ICMP? ICMP์— ๋Œ€ํ•˜์—ฌ ๊ฐ„๋‹จํ•˜๊ฒŒ ์•Œ์•„๋ณด๋ฉด ์ธํ„ฐ๋„ท ์ œ์–ด ๋ฉ”์‹œ์ง€ ํ”„๋กœํ† ์ฝœ์œผ๋กœ ์ผ๋ฐ˜์ ์œผ๋กœ IP ๋™์ž‘์—์„œ ์ง„๋‹จ์ด๋‚˜ ์ œ์–ด๋กœ ์‚ฌ์šฉ๋˜...

Blind SQLi With Binary Search & Python

์ด๋ฒˆ์—๋Š” Binary Search๋ฅผ ์ด์šฉํ•˜์—ฌ DB๋ฅผ ์ถ”์ถœํ•  ์ˆ˜์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ด…์‹œ๋‹ค. Binary Search Binary Search๋ž€ ์ด์ง„ํƒ์ƒ‰ ์•Œ๊ณ ๋ฆฌ์ฆ˜์ด๋ผ ํ•˜๋ฉฐ ์ •๋ ฌ๋œ ๋ฐ์ดํ„ฐ์—์„œ ๊ฒ€์ƒ‰ ๋ฒ”์œ„๋ฅผ ์ค„์—ฌ ๋‚˜๊ฐ€๋ฉด์„œ ์›ํ•˜๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ์ž…๋‹ˆ๋‹ค. Contain DB Name test๋Š” acunetix์˜ ์ทจ์•ฝํ•œ ํŽ˜์ด์ง€๋กœ ์ง„ํ–‰...

Blind SQLi With Bit operation & Burp Intruder

Bit operation์„ ์ด์šฉํ•˜์—ฌ ๋ฒ„ํ”„์Šค์œ„ํŠธ์˜ Intruder ๊ธฐ๋Šฅ์œผ๋กœ ๊ฐ„๋‹จํ•˜๊ฒŒ DB๋ฅผ ์ถ”์ถœํ•  ์ˆ˜์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ด…์‹œ๋‹ค. Bit operation ํ•ญ์ƒ Binary Search๋ฅผ ์ด์šฉํ•˜์—ฌ Blind SQLi ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋ฅผ ๋งŒ๋“ค์—ˆ๋Š”๋ฐ ๋“œ๋ฆผํ•ต ๊ฐ•์˜๋ฅผ ํ†ตํ•ด MySQL DB์—์„œ Bit operation์„ ์ด์šฉํ•ด๋„ ๋˜๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค ...

XSS Filtering bypass with JSFuck

XSS๋ฅผ ๋ฐœ๊ฒฌํ–ˆ์ง€๋งŒ alert, confirm, prompt๋“ฑ ๋ฌธ์ž์—ด์ด WAF์—์„œ ํ•„ํ„ฐ๋ง ๋˜์—ˆ์„ ๋•Œ JSFuck์„ ์ด์šฉํ•˜์—ฌ ์ด๋ฅผ ์šฐํšŒํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ด…์‹œ๋‹ค. What is JSFuck? ์œ„ํ‚ค์— ๋”ฐ๋ฅด๋ฉด JavaScript ๋ฌธ๋ฒ•์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๋ฌธ์ž ์ค‘ ๋‹จ 6๊ฐ€์ง€์ธ [,],(,),!,+ ๋งŒ์œผ๋กœ ๊ตฌํ˜„ํ•  ์ˆ˜ ์žˆ์Œ์— ์ฐฉ์•ˆํ•˜์—ฌ ๊ณ ์•ˆ๋œ ๋‚œํ•ดํ•œ ํ”„๋กœ๊ทธ๋ž˜...