๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

์ „์ฒด ๊ธ€720

Flask - static ํŒŒ์ผ๋“ค ์ œ๊ณตํ•˜๊ธฐ from flask import Flask, request, send_from_directory # set the project root directory as the static folder, you can set others. app = Flask(__name__, static_url_path='') @app.route('/js/') def send_js(path): return send_from_directory('js', path) if __name__ == "__main__": app.run() ์ถœ์ฒ˜: https://stackoverflow.com/questions/20646822/how-to-serve-static-files-in-flask How to serve static files in .. 2021. 12. 8.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - ์™„์ฃผํ•˜์ง€ ๋ชปํ•œ ์„ ์ˆ˜, ํŒŒ์ด์ฌ https://programmers.co.kr/learn/courses/30/lessons/42576 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ์™„์ฃผํ•˜์ง€ ๋ชปํ•œ ์„ ์ˆ˜ ์ˆ˜๋งŽ์€ ๋งˆ๋ผํ†ค ์„ ์ˆ˜๋“ค์ด ๋งˆ๋ผํ†ค์— ์ฐธ์—ฌํ•˜์˜€์Šต๋‹ˆ๋‹ค. ๋‹จ ํ•œ ๋ช…์˜ ์„ ์ˆ˜๋ฅผ ์ œ์™ธํ•˜๊ณ ๋Š” ๋ชจ๋“  ์„ ์ˆ˜๊ฐ€ ๋งˆ๋ผํ†ค์„ ์™„์ฃผํ•˜์˜€์Šต๋‹ˆ๋‹ค. ๋งˆ๋ผํ†ค์— ์ฐธ์—ฌํ•œ ์„ ์ˆ˜๋“ค์˜ ์ด๋ฆ„์ด ๋‹ด๊ธด ๋ฐฐ์—ด participant์™€ ์™„์ฃผํ•œ ์„ ์ˆ˜ programmers.co.kr def solution(participant, completion): participant.sort() completion.sort() for i in range( len(completion) ): if participant[i] != completion[i]: return participant[i] return participant[-1] .. 2021. 12. 8.
Lord of SQLinjection - bugbear ์ด๋ฒˆ์—๋Š” ๋ฌด๋ ค ๊ณต๋ฐฑ๊ณผ OR AND๋ฅผ ์ œ์™ธํ•˜๊ณ , LIKE๋„ ํ•„ํ„ฐ๋ง์ด ๋œ๋‹ค. ๊ณต๋ฐฑ์€ %0a๋กœ ์น˜ํ™˜ํ•˜๊ณ , LIKE๋Š” IN์œผ๋กœ ๋Œ€์ฒดํ•˜๋ฉด ๋œ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์ธ์ ์…˜์„ ํ•˜๋˜ ์ค‘ ORD ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๊ณ  ํ•˜์ž OR ํ‚ค์›Œ๋“œ๊ฐ€ ํฌํ•จ์ด ๋˜์–ด์žˆ์–ด์„œ ์‚ฌ์šฉ์ด ๋ถˆ๊ฐ€๋Šฅํ–ˆ๋‹ค. ๊ทธ๋ž˜์„œ ํ•˜๋Š” ์ˆ˜ ์—†์ด ORD๋ฅผ HEX๋กœ ๋Œ€์‹  ์‚ฌ์šฉํ•˜๊ณ  ์—ฌ๊ธฐ์— CONV ํ•จ์ˆ˜๋ฅผ ๋”ํ•ด์„œ 16์ง„์ˆ˜๋ฅผ 10์ง„์ˆ˜๋กœ ๋ณ€๊ฒฝํ•ด ์ฃผ์—ˆ๋‹ค. ๊ทธ๊ฒƒ๋งŒ ์ˆ˜์ •ํ•˜๋ฉด ์ด์ „์˜ ์ž๋™ํ™” ์†Œ์Šค๋ž‘ ๋น„์Šทํ•˜๋‹ค. import requests parameter = None cookie = {'PHPSESSID':'์ž์‹ ์˜ ์ฟ ํ‚ค ๊ฐ’์„ ์ž…๋ ฅ'} result = None solve = "" for i in range(1, 8+1): for ascii in range(48, 112+1): print(ascii) par.. 2021. 12. 7.
Lord of SQLinjection - darkknight ์ด์ „๊นŒ์ง€๋Š” ๋ฌธ์ž์—ด ํ˜•ํƒœ์˜ id ํ˜น์€ pw๋ฅผ ๊ฐ’์„ ๋„˜๊ฒจ์ฃผ์—ˆ๋‹ค๋ฉด, ์ด๋ฒˆ์—๋Š” ์ˆซ์ž ํ˜•ํƒœ์˜ no๋ฅผ ๋„˜๊ฒจ์ฃผ์–ด์•ผ ํ•œ๋‹ค. ์ฆ‰ no์€ '๋กœ ๋‘˜๋Ÿฌ์‹ธ์—ฌ์„œ ์ฟผ๋ฆฌ๋ฅผ ์‹คํ–‰ํ•˜๋Š” ๊ฒƒ์ด ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ตณ์ด '๋ฅผ ์‚ฌ์šฉํ•ด ์šฐํšŒ๋ฅผ ํ•  ํ•„์š”๊ฐ€ ์—†๋‹ค. ์ˆ˜๊ณ ๋ฅผ ์ข€ ๋” ๋œ์–ด์ค€ ์…ˆ์ด๋‹ค. ๋งˆ์นจ ํ•„ํ„ฐ๋ง์„ ํ•˜๋Š” ๋ถ€๋ถ„๋„ '๋ฅผ ๊ธˆ์ง€ํ•˜๊ณ  ์žˆ๋‹ค. ๊ทธ๋ ‡๊ธฐ ๋•Œ๋ฌธ์— ๋ฌธ์ž๋ฅผ ์ด์šฉํ•ด Blind ์ธ์ ์…˜์„ ์‹œ๋„ํ•˜๋Š” ๊ฒƒ์€ ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค. (๋ฌธ์ž๋ฅผ ์ฃผ๊ธฐ ์œ„ํ•ด์„œ๋Š” '๋ฅผ ํฌํ•จ์„ ํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์—) ๊ทธ๋ฆฌ๊ณ  ๋˜ ์ œ์™ธ๋ฅผ ํ•˜๋Š” ํ•จ์ˆ˜๋“ค๋„ ์žˆ๋Š”๋ฐ ๊ฐ๊ฐ substr๊ณผ ascii๊ฐ€ ์žˆ๋‹ค. ์ด๋Š” ๋‹ค ๋‹ค๋ฅธ ํ•จ์ˆ˜๋กœ ๋Œ€์ฒด๊ฐ€ ๊ฐ€๋Šฅํ•จ. substr -> mid ascii -> ord =๋„ LIKE๋กœ ์น˜ํ™˜ํ•˜๋ฉด ๋œ๋‹ค. ์•„๋ž˜๋Š” ํŒŒ์ด์ฌ ์ž๋™ํ™” ๋„๊ตฌ์ด๋‹ค. import requests parameter = None .. 2021. 12. 7.
Lord of SQLinjection - golem ์ด๋ฒˆ์—๋„ orge ๋ฌธ์ œ์ฒ˜๋Ÿผ ์ฟผ๋ฆฌ๋ฌธ์„ ๋‘ ๋ฒˆ ์‹คํ–‰์‹œํ‚ค๋Š” ๊ฒƒ์„ ๋ณด๋‹ˆ, ๋ธ”๋ผ์ธ๋“œ ์ธ์ ์…˜์„ ์‹œ๋„ํ•ด์•ผ ํ•˜๋Š” ๋ฌธ์ œ๋ผ๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ ๋๋‹ค. ๊ทผ๋ฐ ์ด์ „ ๋ฌธ์ œ์™€ ๋‹ค๋ฅด๊ฒŒ "="์™€ substr์„ ์‚ฌ์šฉํ•˜์ง€ ๋ชปํ•˜๋„๋ก ํ•„ํ„ฐ๋ง์„ ๊ฑฐ์น˜๊ฒŒ ๋œ๋‹ค. ํ•˜์ง€๋งŒ ์œ„๋ฅผ ๋Œ€์ฒดํ•  ํ‘œํ˜„์‹๋“ค์ด ์ด๋ฏธ ์กด์žฌํ•œ๋‹ค. "="๋Š” "LIKE"๋กœ ๋ฐ”๊พธ๊ณ  "substr"์€ "substring"์œผ๋กœ ๋ฐ”๊ฟ”์ฃผ๋ฉด ๋์ด๋‹ค. ์•„๋ž˜๋Š” ์ž๋™ํ™” ๋„๊ตฌ์ด๋‹ค. orge์—์„œ ์‚ฌ์šฉํ•˜๋˜๊ฑฐ๋ฅผ "="๋ฅผ "LIKE"๋กœ ๋ณ€๊ฒฝํ•˜๊ณ , "substr"์„ "substring"์œผ๋กœ ๋ณ€๊ฒฝํ•ด์ค€ ๊ฒƒ ๋ฐ–์— ์—†๋‹ค. import requests parameter = None cookie = {'PHPSESSID':'์—ฌ๊ธฐ๋‹ค ์ž์‹ ์˜ ์ฟ ํ‚ค ๊ฐ’์„ ์ž…๋ ฅ'} result = None solve = "" for i in range(1.. 2021. 12. 7.
Lord of SQLinjection - skeleton ์ด๋ฒˆ์—๋Š” ๋ญ๋“  ์ž…๋ ฅํ•ด๋„(์‹ฌ์ง€์–ด ์ผ์น˜ํ•˜๋Š” ํŒจ์Šค์›Œ๋“œ๋ฅผ ๋„ฃ์–ด๋„) ์ฟผ๋ฆฌ๋ฌธ ๋งจ ๋’ค์— and 1=0 ๋•Œ๋ฌธ์— ๋ฌด์กฐ๊ฑด ์‹คํŒจ๊ฐ€ ๋œจ๊ฒŒ ๋œ๋‹ค. ์ด๋Ÿฐ ์˜๋ฏธ ์—†๋Š” ์ฟผ๋ฆฌ๋ฌธ์„ ๋ณด๊ณ  ๋”ฑ ๋ด๋„ ์ฃผ์„์„ ์ด์šฉํ•œ ๋ฌธ์ œ๋ผ๋Š” ๊ฒƒ์ด ๋– ์˜ฌ๋ž๋‹ค. (๋’ค์— ์žˆ๋Š” and 1=0์„ ๋ฌด๋ ฅํ™” ์‹œ์ผœ์ฃผ๊ธฐ ์œ„ํ•ด์„œ) ์ •๋ง ์ฃผ์„ #๋ฅผ ๋„ฃ์–ด์„œ ๋ฌธ์ œ๋ฅผ ํ†ต๊ณผํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ–ˆ๋‹ค. ํ•˜์ง€๋งŒ ;%00๋ผ๋Š” ๋ฐฉ๋ฒ•๋„ ์กด์žฌ ํ–ˆ๋‹ค. ์–˜๋Š” ์„ธ๋ฏธ์ฝœ๋ก (;)๊ณผ NULL(%00)์„ ์ด์šฉํ•œ ์ฃผ์„์ฒ˜๋ฆฌ์ด๋‹ค. 2021. 12. 7.
Lord of SQLinjection - vampire ์ด๋ฒˆ์—๋Š” troll ๋ฌธ์ œ์™€ ๋‹ค๋ฅด๊ฒŒ ๋ชจ๋“  ๋Œ€๋ฌธ์ž๋ฅผ ์†Œ๋ฌธ์ž๋กœ ๋ณ€๊ฒฝ์„ ์‹œํ‚ค๋ฉฐ, str_replaceํ•จ์ˆ˜๋ฅผ ์ด์šฉํ•ด admin ํ‚ค์›Œ๋“œ๋ฅผ ๊ณต๋ฐฑ์œผ๋กœ ๋ณ€๊ฒฝ์‹œํ‚ค๊ณ  ์žˆ๋‹ค. admin ํ‚ค์›Œ๋“œ๋ฅผ ๊ณต๋ฐฑ์œผ๋กœ ๋ณ€๊ฒฝ์‹œํ‚ค๊ณ  ์žˆ๋‹ค. admin์„ ""์œผ๋กœ ๋ฐ”๊พผ๋‹ค. ๊ทธ๋Ÿฌ๋ฉด adadminmin์„ ๋„ฃ์œผ๋ฉด ์–ด๋–ป๊ฒŒ ๋ ๊นŒ? adadminmin ์ค‘๊ฐ„์— admin ์ง€์›Œ์ง€๊ณ , admin์ด ๋‚จ๊ฒŒ ๋˜์–ด ์ฟผ๋ฆฌ๋ฅผ ์ž˜ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋œ๋‹ค. ๋ฌธ์ž์—ด ๋ณ€๊ฒฝ ํ•จ์ˆ˜์˜ ์ทจ์•ฝ์ ์€ ์ด๋ฏธ ๊ฝค ์œ ๋ช…ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ € ํ•จ์ˆ˜ ๋ณด์ž๋งˆ์ž ๋ฐ”๋กœ ๋– ์˜ฌ๋ž๋‹ค. 2021. 12. 7.
Lord of SQLinjection - troll ์ด๋ฌธ์ œ์—์„œ admin์„ ํ•„ํ„ฐ๋งํ•˜๋Š” ์ € ๋ถ€๋ถ„ "/admin/", id๋กœ admin์„ ๋„˜๊ฒจ์ฃผ๋ฉด HeHe๊ฐ€ ๋œจ๊ฒŒ ๋จ ํ•˜์ง€๋งŒ admin์ด ์•„๋‹ˆ๋ผ Admin์„ ๋ณด๋‚ด์ฃผ๋ฉด? ํด๋ฆฌ์–ด๊ฐ€ ๋จ ์–ด์งธ์„œ admin์€ ์•ˆ๋˜๊ณ  Admin์€ ๊ฐ€๋Šฅํ•œ ๊ฑธ๊นŒ ์šฐ์„  "/admin/" ํ•„ํ„ฐ๋ง์„ ์šฐํšŒํ•  ์ˆ˜ ์žˆ์—ˆ๋˜ ์ด์œ ๋Š” ๋ฐ”๋กœ ์†Œ๋ฌธ์ž๊ฐ€ ์•„๋‹Œ ๋Œ€๋ฌธ์ž๋กœ ์ž…๋ ฅ์„ ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ฐ€๋ณ๊ฒŒ ํŒจ์Šค๊ฐ€ ๊ฐ€๋Šฅํ•œ ๊ฒƒ์ด๋ฉฐ, ๋งŒ์•ฝ ๋Œ€์†Œ๋ฌธ์ž๋ฅผ ๋ฌด์‹œํ•˜๊ณ  ์‹ถ๋‹ค๋ฉด ๋’ค์— i๋ฅผ ๋ถ™์ด๋ฉด ๋œ๋‹ค. '/admin/i' 2021. 12. 7.
Lord of SQLinjection - orge ํŒŒ์ด์ฌ3 ์ž๋™ํ™” ๋„๊ตฌ https://los.rubiya.kr/chall/orge_bad2f25db233a7542be75844e314e9f3.php https://los.rubiya.kr/chall/orge_bad2f25db233a7542be75844e314e9f3.php los.rubiya.kr import requests parameter = None cookie = {'PHPSESSID':'์—ฌ๊ธฐ๋‹ค ์ž์‹ ์˜ ์ฟ ํ‚ค ๊ฐ’์„ ๋„ฃ์Œ'} result = None solve = "" for i in range(1, 8+1): for ascii in range(48, 112+1): print(ascii) parameter = "?pw='|| id='admin'%26%26 ascii(substr(pw,{},1))={}%23".format(i.. 2021. 12. 7.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - ์ˆซ์ž ๋ฌธ์ž์—ด๊ณผ ์˜๋‹จ์–ด, ํŒŒ์ด์ฌ https://programmers.co.kr/learn/courses/30/lessons/81301?language=python3 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ์ˆซ์ž ๋ฌธ์ž์—ด๊ณผ ์˜๋‹จ์–ด ๋„ค์˜ค์™€ ํ”„๋กœ๋„๊ฐ€ ์ˆซ์ž๋†€์ด๋ฅผ ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋„ค์˜ค๊ฐ€ ํ”„๋กœ๋„์—๊ฒŒ ์ˆซ์ž๋ฅผ ๊ฑด๋„ฌ ๋•Œ ์ผ๋ถ€ ์ž๋ฆฟ์ˆ˜๋ฅผ ์˜๋‹จ์–ด๋กœ ๋ฐ”๊พผ ์นด๋“œ๋ฅผ ๊ฑด๋„ค์ฃผ๋ฉด ํ”„๋กœ๋„๋Š” ์›๋ž˜ ์ˆซ์ž๋ฅผ ์ฐพ๋Š” ๊ฒŒ์ž„์ž…๋‹ˆ๋‹ค. ๋‹ค์Œ์€ ์ˆซ์ž์˜ ์ผ๋ถ€ ์ž programmers.co.kr def solution(s): numbers = {'zero':'0', 'one':'1', 'two':'2', 'three':'3', 'four':'4', 'five':'5', 'six':'6', 'seven':'7', 'eight':'8', 'nine':'9'} for i in numbers: s = s.replace(.. 2021. 12. 7.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - [์นด์นด์˜ค ์ธํ„ด] ํ‚คํŒจ๋“œ ๋ˆ„๋ฅด๊ธฐ, ํŒŒ์ด์ฌ https://programmers.co.kr/learn/courses/30/lessons/67256 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ํ‚คํŒจ๋“œ ๋ˆ„๋ฅด๊ธฐ [1, 3, 4, 5, 8, 2, 1, 4, 5, 9, 5] "right" "LRLLLRLLRRL" [7, 0, 8, 2, 8, 3, 1, 5, 7, 6, 2] "left" "LRLLRRLLLRR" [1, 2, 3, 4, 5, 6, 7, 8, 9, 0] "right" "LLRLLRLLRL" programmers.co.kr pad_map = { 1:[0,0], 2:[0,1], 3:[0,2], 4:[1,0], 5:[1,1], 6:[1,2], 7:[2,0], 8:[2,1], 9:[2,2], '*':[3,0], 0:[3,1], '#':[3,2] } # ์™ผ์†๊ณผ ์˜ค๋ฅธ์†์ด ๋ˆŒ๋Ÿฌ์•ผํ•  .. 2021. 12. 6.
๋ฐฑ์ค€ - ์†Œ์ˆ˜ ๊ตฌํ•˜๊ธฐ, ํŒŒ์ด์ฌ https://www.acmicpc.net/problem/1929 1929๋ฒˆ: ์†Œ์ˆ˜ ๊ตฌํ•˜๊ธฐ ์ฒซ์งธ ์ค„์— ์ž์—ฐ์ˆ˜ M๊ณผ N์ด ๋นˆ ์นธ์„ ์‚ฌ์ด์— ๋‘๊ณ  ์ฃผ์–ด์ง„๋‹ค. (1 ≤ M ≤ N ≤ 1,000,000) M์ด์ƒ N์ดํ•˜์˜ ์†Œ์ˆ˜๊ฐ€ ํ•˜๋‚˜ ์ด์ƒ ์žˆ๋Š” ์ž…๋ ฅ๋งŒ ์ฃผ์–ด์ง„๋‹ค. www.acmicpc.net import math def is_prime_num(n): if n == 1: return False else: for i in range(2, int(math.sqrt(n))+1): if n % i == 0: return False return True M, N = map(int, input().split()) for i in range(M, N+1): if is_prime_num(i): print(i) ์†Œ์ˆ˜๋ฅผ ๊ตฌํ•  ๋•Œ๋Š” ์†Œ์ˆ˜.. 2021. 12. 6.
728x90