aestera

Stored Procedure SQL Injection

0x1. Intro ํ”„๋กœ์‹œ์ €(procedure)์˜ ์‚ฌ์ „์  ์˜๋ฏธ๋Š” โ€˜์–ด๋–ค ์ผ์„ ํ•˜๋Š” ๊ณต์‹์ ์ด๊ฑฐ๋‚˜ ์ธ์ •๋œ ๋ฐฉ์‹์ธ ์ผ๋ จ์˜ ํ–‰๋™โ€™ ์ด๋‹ค. ์ด ํฌ์ŠคํŒ…์—์„œ๋Š” DB์„œ๋ฒ„์— ์ €์žฅ๋œ ํ”„๋กœ์‹œ์ €์ธ Stored Procedure์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ณ  ์ด์˜ SQL Injection ๊ฐ€๋Šฅ์„ฑ์— ๋Œ€ํ•ด ์‚ดํŽด๋ณด๊ฒ ๋‹ค. 0x2. Stored Procedure๋ž€? ์—ฌ๋Ÿฌ SQL์„ ์‚ฌ์šฉํ•˜๊ธฐ...

[RSA - 3] RSA ์•”ํ˜ธํ™”

RSA 3๋‹จ๊ณ„ ์ค‘ ๋งˆ์ง€๋ง‰์œผ๋กœ RSA ์•”ํ˜ธํ™”์— ๋Œ€ํ•ด ๊ฐ„๋‹จํ•˜๊ฒŒ ์•Œ์•„๋ณด์ž RSA๋ฅผ ์ดํ•ดํ•˜๊ธฐ ์œ„ํ•ด ์•Œ์•„์•ผ ํ•  ํ•„์ˆ˜ ์ง€์‹๋“ค์„ ์ด์ „ ๋‘ ๋‹จ๊ณ„๋ฅผ ํ†ตํ•ด ์•Œ์•„๋ดค๋‹ค RSA ์•”ํ˜ธํ™”๋Š” ๊ณต๊ฐœ ํ‚ค ์•”ํ˜ธํ™” ๋ฐฉ์‹ ์ค‘ ํ•˜๋‚˜์ด๋‹ค. 1. ๊ณต๊ฐœ ํ‚ค ์•”ํ˜ธํ™” - ํ‚ค(key)๋ž€? โ€œ์•”ํ˜ธํ™”โ€์˜ ๋ชฉ์ ์€ ํ•ด์‹œํ•จ์ˆ˜์™€ ๋‹ค๋ฅด๊ฒŒ โ€œ๋ณตํ˜ธํ™”โ€์ด๋‹ค. ํž˜๋“ค๊ฒŒ ์•”ํ˜ธํ™”๋ฅผ ํ•ด์„œ ์ˆ˜์‹ ์ž์—๊ฒŒ ๋ณด๋ƒˆ๋Š”๋ฐ ์†ก์‹ ์ž๊ฐ€...

[RSA - 2] ํ™•์žฅ ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ• (Extended Euclidean Algorithm)

์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ• (Euclidean Algorithm) ์ง€๋‚œ ํฌ์ŠคํŒ…์—์„œ๋Š” ๋ชจ๋“ˆ๋Ÿฌ ์—ฐ์‚ฐ๊ณผ ๋ชจ๋“ˆ๋Ÿฌ ์—ญ์›์— ๋Œ€ํ•ด ์•Œ์•„๋ดค๋‹ค. ์ด๋ฒˆ ํฌ์ŠคํŒ…์—์„œ๋Š” ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ•๊ณผ ์ด๋ฅผ ํ™•์žฅ์‹œํ‚จ ํ™•์žฅ ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์ž. - ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ•์ด๋ž€? ํ™•์žฅ ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ธฐ ์ „ ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์ž. ์œ ํด๋ฆฌ๋“œ ํ˜ธ์ œ๋ฒ•์€ ์ž์—ฐ์ˆ˜ $ a $, ...

[RSA - 1] ๋ชจ๋“ˆ๋กœ ์—ฐ์‚ฐ (Modulo)

๋ชจ๋“ˆ๋กœ ์—ฐ์‚ฐ (Modulo) ์•”ํ˜ธํ•™์„ ๊ณต๋ถ€ํ•˜๋‹ค ๋ณด๋ฉด ๋น ์ง€์ง€ ์•Š๊ณ  ๋‚˜ํƒ€๋‚˜๋Š” ์—ฐ์‚ฐ์ด ์žˆ๋‹ค. ๋ฐ”๋กœ ๋ชจ๋“ˆ๋กœ ์—ฐ์‚ฐ์ด๋‹ค. RSA์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ธฐ ์ „ ์•Œ์•„์•ผ ํ•  ๊ธฐ๋ณธ ๊ฐœ๋…๋“ค๋ถ€ํ„ฐ ์•Œ์•„๋ณด์ž. ์ฒ˜์Œ์—” ์ด๋Ÿฐ ๋‚ด์šฉ์„ ๊ตณ์ด ์™œ ์•Œ์•„์•ผ ํ•˜์ง€? ๋ผ๋Š” ์ƒ๊ฐ์ด ๋“ค๊ฒ ์ง€๋งŒ ๋ฏธ๋ฆฌ ์•Œ์•„๋‘๋ฉด RSA๋ฅผ ์ดํ•ดํ•˜๋Š”๋ฐ ๋„์›€์ด ๋  ๊ฒƒ์ด๋‹ค. - ๋ชจ๋“ˆ๋กœ ์—ฐ์‚ฐ์ด๋ž€? ๋ชจ๋“ˆ๋กœ ์—ฐ์‚ฐ์€ ๋‚˜๋จธ์ง€๋ฅผ ๊ตฌํ•˜๋Š” ...

[WaniCTF 2023]

[WaniCTF 2023] ์˜ค๋žœ๋งŒ์— CTF์™€ ๋‹น์ง ํƒ€์ด๋ฐ์ด ๋งž์•„์„œ ๋ช‡๋ฌธ์ œ ํ’€์–ด๋ดค๋‹ค. ๋‹ค์‹œ ๊ฐ ์žก๊ธฐ์— ์ข‹์•˜๋˜ ๊ฒƒ ๊ฐ™๋‹ค. WEB IndexedDB ๋ฌธ์ œ ์ œ๋ชฉ์„ ๋ณด๋ฉด ์•Œ ์ˆ˜ ์žˆ๋“ฏ์ด browser ์ œ๊ณต DB์ธ IndexedDB์— FLAG๊ฐ€ ์žˆ๋‹ค. FLAG{y0u_c4n_u3e_db_1n_br0wser} Extract Service 1 .do...

[SekaiCTF 2022] Bottle Poem

Bottle Poem SekaiCTF์˜ ์ฒซ๋ฒˆ์งธ Web๋ฌธ์ œ์ด์ž 1๋‹จ๊ณ„ ๋ฌธ์ œ์˜€์ง€๋งŒ.. ์—„์ฒญ๋‚˜๊ฒŒ ์‚ฝ์งˆํ–ˆ๋‹ค ๋ฌธ์ œ์˜ ๋ฉ”์ธ ํŽ˜์ด์ง€์ด๋‹ค. ํ•˜์ดํผ๋งํฌ๋ฅผ ํด๋ฆญํ•ด๋ณด๋ฉด ์ด๋ ‡๊ฒŒ ์‹œ๊ฐ€ ๋ณด์ธ๋‹ค. URL์˜ id๋ผ๋Š” ์ธ์ž๋กœ /etc/passwd๋ฅผ ์–ป๋Š”๋ฐ ์„ฑ๊ณตํ–ˆ์ง€๋งŒ FLAG๋Š” ์—†์—ˆ๋‹ค. ๋ฌธ์ œ ์„ค๋ช…์„ ๋‹ค์‹œ ๋ณด๋ฉด FLAG๋Š” ์„œ๋ฒ„์— ์‹คํ–‰ ํŒŒ์ผ๋กœ ์กด์žฌํ•œ๋‹ค๊ณ  ์ ํ˜€์žˆ๋‹ค. ์ฆ‰ ...

[corCTF 2022] whack-a-frog

whack-a-frog ๋‚˜๋ฆ„ ์žฌ๋ฏธ์žˆ์—ˆ๋˜ forensic ๋ฌธ์ œ์˜€๋‹ค. ๋ฌธ์ œ ํŽ˜์ด์ง€๋ฅผ ๋ณด๋ฉด ๋ฌด์ˆ˜ํ•œ ์šฐ๋ฌผ์•ˆ ๊ฐœ๊ตฌ๋ฆฌ๋“ค์ด ๋‹ค๋ฅผ ๋ฐ˜๊ฒจ์ค€๋‹ค. ํด๋ฆญํ•œ ์ƒํƒœ๊ณ  ๋“œ๋ž˜๊ทธํ•˜๋ฉด ๊ทธ ๊ฒฝ๋กœ์— ์žˆ๋Š” ๊ฐœ๊ตฌ๋ฆฌ๋“ค์ด ์šฐ๋ฌผ ์†์œผ๋กœ ์ˆจ๋Š”๋‹ค. ์ด๊ฒƒ๋งŒ ๋ด์„œ๋Š” ๋ฌด์Šจ ๋ฌธ์ œ์ธ์ง€ ๋ชจ๋ฅด๊ฒ ๋‹ค. .pcap ํ™•์žฅ์ž๋ผ wireshark๋กœ ํŒŒ์ผ์„ ์—ด์–ด HTTPํ•„ํ„ฐ๋ฅผ ๊ฑธ์—ˆ๋”๋‹ˆ x, y, event ...

[TFC CTF 2022] TUBEINC

TUBEINC ๋Œ€ํšŒ ์ค‘์—๋Š” ํ’€์ง€ ๋ชปํ–ˆ๋˜ ๋ฌธ์ œ์ธ๋ฐ Writeup์„ ๋ณด๋‹ˆ ์žฌ๋ฐŒ์–ด์„œ ์ •๋ฆฌํ•ด๋ณธ๋‹ค. ๋ฌธ์ œ ํŽ˜์ด์ง€์˜ ๋ชจ์Šต์ด๋‹ค ํฌ๊ฒŒ ์–ป์„ ๊ฒƒ์€ ์—†์ง€๋งŒ ํŽ˜์ด์ง€ ํ•˜๋‹จ์— ๋ณด๋ฉด <footer> <p>For the complete functionality of the page add the following entries to your D...