๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

์ „์ฒด ๊ธ€720

๋„คํŠธ์›Œํฌ ํ•ดํ‚น - hydra, ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ ๋„๊ตฌ https://www.kali.org/tools/hydra/ hydra | Kali Linux Tools hydra Usage Example Attempt to login as the root user (-l root) using a password list (-P /usr/share/wordlists/metasploit/unix_passwords.txt) with 6 threads (-t 6) on the given SSH server (ssh://192.168.1.123): root@kali:~# hydra -l root -P /usr/share/word www.kali.org hydra๋Š” FTP, SSH, MS-SQL, HTTP ๋“ฑ ๋‹ค์–‘ํ•œ ํ”„๋กœํ† ์ฝœ์„ ๋Œ€์ƒ์œผ๋กœ ์•„์ด๋””, ์•”ํ˜ธ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ ๋„๊ตฌ์ด๋‹ค.. 2021. 11. 22.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - ์ตœ๋Œ“๊ฐ’๊ณผ ์ตœ์†Ÿ๊ฐ’, ํŒŒ์ด์ฌ https://programmers.co.kr/learn/courses/30/lessons/12939 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ์ตœ๋Œ“๊ฐ’๊ณผ ์ตœ์†Ÿ๊ฐ’ ๋ฌธ์ž์—ด s์—๋Š” ๊ณต๋ฐฑ์œผ๋กœ ๊ตฌ๋ถ„๋œ ์ˆซ์ž๋“ค์ด ์ €์žฅ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. str์— ๋‚˜ํƒ€๋‚˜๋Š” ์ˆซ์ž ์ค‘ ์ตœ์†Œ๊ฐ’๊ณผ ์ตœ๋Œ€๊ฐ’์„ ์ฐพ์•„ ์ด๋ฅผ "(์ตœ์†Œ๊ฐ’) (์ตœ๋Œ€๊ฐ’)"ํ˜•ํƒœ์˜ ๋ฌธ์ž์—ด์„ ๋ฐ˜ํ™˜ํ•˜๋Š” ํ•จ์ˆ˜, solution์„ ์™„์„ฑํ•˜์„ธ์š”. ์˜ˆ๋ฅผ programmers.co.kr def solution(s): answer = [ int(_) for _ in s.split(' ') ] return str( min(answer) ) + " " + str( max(answer) ) [ int(_) for _ in ๋ฌธ์ž์—ด์ด ๋‹ด๊ธด ๋ฆฌ์ŠคํŠธ] ์ด๋Ÿฐ์‹์œผ๋กœ ์“ฐ๋ฉด ๋ฌธ์ž์—ด ๋ฆฌ์ŠคํŠธ๋ฅผ ์ •์ˆ˜ํ˜• ๋ฆฌ์ŠคํŠธ๋กœ ๋ณ€ํ™˜ ์‹œํ‚ฌ ์ˆ˜ ์žˆ๋‹ค. 2021. 11. 22.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - NULL ์ฒ˜๋ฆฌํ•˜๊ธฐ, MySQL https://programmers.co.kr/learn/courses/30/lessons/59410 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - NULL ์ฒ˜๋ฆฌํ•˜๊ธฐ ANIMAL_INS ํ…Œ์ด๋ธ”์€ ๋™๋ฌผ ๋ณดํ˜ธ์†Œ์— ๋“ค์–ด์˜จ ๋™๋ฌผ์˜ ์ •๋ณด๋ฅผ ๋‹ด์€ ํ…Œ์ด๋ธ”์ž…๋‹ˆ๋‹ค. ANIMAL_INS ํ…Œ์ด๋ธ” ๊ตฌ์กฐ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์œผ๋ฉฐ, ANIMAL_ID, ANIMAL_TYPE, DATETIME, INTAKE_CONDITION, NAME, SEX_UPON_INTAKE๋Š” ๊ฐ๊ฐ ๋™๋ฌผ์˜ ์•„์ด๋”” programmers.co.kr SELECT ANIMAL_TYPE, IFNULL(NAME, "No name") as NAME, SEX_UPON_INTAKE FROM ANIMAL_INS ORDER BY ANIMAL_ID ASC IFNULL(NAME, "No name") as NAME 2021. 11. 22.
Dreamhack - ์›Œ๊ฒŒ์ž„, pathtraversal https://dreamhack.io/wargame/challenges/12/ pathtraversal ์‚ฌ์šฉ์ž์˜ ์ •๋ณด๋ฅผ ์กฐํšŒํ•˜๋Š” API ์„œ๋ฒ„์ž…๋‹ˆ๋‹ค. Path Traversal ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด /api/flag์— ์žˆ๋Š” ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”! Reference Server-side Basic dreamhack.io ๋ฌธ์ œ์—์„œ ์ œ๊ณตํ•˜๋Š” ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋จผ์ € ๋ถ„์„ ์‚ฌ์šฉ์ž๋Š” /get_info ํŽ˜์ด์ง€์—์„œ ์ž…๋ ฅ๋ž€์—๋‹ค ์œ ์ €์˜ ์ด๋ฆ„์„ ๋„ฃ์œผ๋ฉด, ์„œ๋ฒ„๊ฐ€ /api/user/{userid}๋กœ GET ์š”์ฒญ์„ ํ•˜์—ฌ, ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ JSON ํ˜•์‹์œผ๋กœ ๊ฐ€์ ธ์˜ค๋Š” ๊ฒƒ์ž„. ์ด๋•Œ userid๋Š” ์œ„์— ์ „์—ญ ๋ณ€์ˆ˜๋กœ ์ •์˜๋œ users ๋”•์…”๋„ˆ๋ฆฌ๋ฅผ ์ฐธ์กฐํ•œ๋‹ค. 0์„ ๋„ฃ์œผ๋ฉด guest์— ๋Œ€ํ•œ ์ •๋ณด ์ถœ๋ ฅ 1์„ ๋„ฃ์œผ๋ฉด admin์— ๋Œ€ํ•œ ์ •๋ณด ์ถœ๋ ฅ ๋…ธ๋ ค์•ผํ•  ๋ถ€๋ถ„์€ ๋ฐ”.. 2021. 11. 21.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - ์ „ํ™”๋ฒˆํ˜ธ ๋ชฉ๋ก, ํŒŒ์ด์ฌ & C++ https://programmers.co.kr/learn/courses/30/lessons/42577?language=cpp ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ์ „ํ™”๋ฒˆํ˜ธ ๋ชฉ๋ก ์ „ํ™”๋ฒˆํ˜ธ๋ถ€์— ์ ํžŒ ์ „ํ™”๋ฒˆํ˜ธ ์ค‘, ํ•œ ๋ฒˆํ˜ธ๊ฐ€ ๋‹ค๋ฅธ ๋ฒˆํ˜ธ์˜ ์ ‘๋‘์–ด์ธ ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๋ ค ํ•ฉ๋‹ˆ๋‹ค. ์ „ํ™”๋ฒˆํ˜ธ๊ฐ€ ๋‹ค์Œ๊ณผ ๊ฐ™์„ ๊ฒฝ์šฐ, ๊ตฌ์กฐ๋Œ€ ์ „ํ™”๋ฒˆํ˜ธ๋Š” ์˜์„์ด์˜ ์ „ํ™”๋ฒˆํ˜ธ์˜ ์ ‘๋‘์‚ฌ์ž…๋‹ˆ๋‹ค. ๊ตฌ์กฐ programmers.co.kr ํ•ด์‹œ์— ๊ด€ํ•œ ๋ฌธ์ œ์ด๋‹ค. ์ „ํ™”๋ฒˆํ˜ธ ๋ชฉ๋ก ๋ฆฌ์ŠคํŠธ์ธ (phone_book)์ด ๋‘ ๋‹จ์–ด ์ด์ƒ์˜ ์ ‘๋‘์‚ฌ๊ฐ€ ๋น„์Šทํ•œ ๊ฒฝ์šฐ๊ฒŒ false๋ฅผ ๋ฐ˜ํ™˜ํ•ด์•ผ ํ•˜๋Š” ๋ฌธ์ œ์ž„ [ํŒŒ์ด์ฌ 3] def solution(phone_book): answer = True phone_book.sort() for i in range( len(phone_book)-1 ): if p.. 2021. 11. 21.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - ๋™๋ฌผ ์ˆ˜ ๊ตฌํ•˜๊ธฐ, MySQL https://programmers.co.kr/learn/courses/30/lessons/59406 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ๋™๋ฌผ ์ˆ˜ ๊ตฌํ•˜๊ธฐ ANIMAL_INS ํ…Œ์ด๋ธ”์€ ๋™๋ฌผ ๋ณดํ˜ธ์†Œ์— ๋“ค์–ด์˜จ ๋™๋ฌผ์˜ ์ •๋ณด๋ฅผ ๋‹ด์€ ํ…Œ์ด๋ธ”์ž…๋‹ˆ๋‹ค. ANIMAL_INS ํ…Œ์ด๋ธ” ๊ตฌ์กฐ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์œผ๋ฉฐ, ANIMAL_ID, ANIMAL_TYPE, DATETIME, INTAKE_CONDITION, NAME, SEX_UPON_INTAKE๋Š” ๊ฐ๊ฐ ๋™๋ฌผ์˜ ์•„์ด๋”” programmers.co.kr SELECT COUNT(*) count FROM ANIMAL_INS 2021. 11. 21.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - x๋งŒํผ ๊ฐ„๊ฒฉ์ด ์žˆ๋Š” n๊ฐœ์˜ ์ˆซ์ž, C++ https://programmers.co.kr/learn/courses/30/lessons/12954 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - x๋งŒํผ ๊ฐ„๊ฒฉ์ด ์žˆ๋Š” n๊ฐœ์˜ ์ˆซ์ž ํ•จ์ˆ˜ solution์€ ์ •์ˆ˜ x์™€ ์ž์—ฐ์ˆ˜ n์„ ์ž…๋ ฅ ๋ฐ›์•„, x๋ถ€ํ„ฐ ์‹œ์ž‘ํ•ด x์”ฉ ์ฆ๊ฐ€ํ•˜๋Š” ์ˆซ์ž๋ฅผ n๊ฐœ ์ง€๋‹ˆ๋Š” ๋ฆฌ์ŠคํŠธ๋ฅผ ๋ฆฌํ„ดํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ์ œํ•œ ์กฐ๊ฑด์„ ๋ณด๊ณ , ์กฐ๊ฑด์„ ๋งŒ์กฑํ•˜๋Š” ํ•จ์ˆ˜, solution์„ ์™„์„ฑํ•ด์ฃผ์„ธ์š”. programmers.co.kr #include #include using namespace std; vector solution(int x, int n) { vector answer; int count = 0; for(int i=x; count 2021. 11. 21.
Dreamhack - ์›Œ๊ฒŒ์ž„, csrf-1 https://dreamhack.io/wargame/challenges/26/ csrf-1 ์—ฌ๋Ÿฌ ๊ธฐ๋Šฅ๊ณผ ์ž…๋ ฅ๋ฐ›์€ URL์„ ํ™•์ธํ•˜๋Š” ๋ด‡์ด ๊ตฌํ˜„๋œ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. CSRF ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. Reference Client-side Basic dreamhack.io ์•„๋ž˜์— ๋ฐ”๋กœ ํ’€์ด ๋ฐฉ๋ฒ• ๊ณต๊ฐœ ๋ฐฉ๋ฒ•: flag ํŽ˜์ด์ง€์˜ input์—๋‹ค๊ฐ€ ์ž…๋ ฅ ์ •๋‹ต: ์›๋ฆฌ: ์†Œ์Šค ์ค‘ check_csrf ํ•จ์ˆ˜๊ฐ€ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋ฐ›์•„ ๋‹ค์‹œ read_url ํ•จ์ˆ˜๋กœ ๋ณด๋‚ด๋Š”๋ฐ ์ด read_url์€ ์ž…๋ ฅ ๋ฐ›์€ url์„ ํฌ๋กฌ ๋“œ๋ผ์ด๋ธŒ(์ž์‹ ์˜ ๋ธŒ๋ผ์šฐ์ €)๋กœ /vuln์œผ๋กœ ์ ‘์†ํ•ด ํŒŒ๋ผ๋ฏธํ„ฐ์˜ ๋‚ด์šฉ์„ ์‹คํ–‰์‹œํ‚ด ๊ฑฐ๊ธฐ์„œ ํŒŒ๋ผ๋ฏธํ„ฐ๊ฐ€ ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š”์ง€ ์—†๋Š”์ง€๋ฅผ ํŒ๋‹จ ์ด ๊ณผ์ •์—์„œ ์„œ๋ฒ„๋Š” ์ž์‹ ์˜ ๋กœ์ปฌ ์•„์ดํ”ผ๋กœ ์ด ๊ณผ์ •์„ ์‹คํ–‰ํ•œ๋‹ค๋Š” ๊ฒƒ์ด ์ทจ์•ฝํ•œ ์  ํŒŒ๋ผ๋ฏธํ„ฐ.. 2021. 11. 21.
Dreamhack - ์›Œ๊ฒŒ์ž„, php-1 https://dreamhack.io/wargame/challenges/46/ php-1 php๋กœ ์ž‘์„ฑ๋œ Back Office ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. LFI ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” /var/www/uploads/flag.php์— ์žˆ์Šต๋‹ˆ๋‹ค. Reference Server-side Basic dreamhack.io php๋กœ ์ž‘์„ฑ๋œ Back Office ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. LFI ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ๋Š” /var/www/uploads/flag.php์— ์žˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์ดํŠธ์— ์ ‘์†์„ ํ•˜๋ฉด, uploads ํด๋” ์•ˆ์— ํŒŒ์ผ๋“ค์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” List ํŽ˜์ด์ง€์™€ ๊ทธ ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ๋“ค์—ฌ๋‹ค๋ณผ ์ˆ˜ ์žˆ๋Š” View ํŽ˜์ด์ง€๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. List ํŽ˜์ด์ง€์—์„œ hello.json ํŒŒ์ผ์„ ํด๋ฆญํ•˜๊ฒŒ ๋˜๋ฉด ์ด๋Ÿฐ.. 2021. 11. 21.
Dreamhack - ์›Œ๊ฒŒ์ž„, cookie https://dreamhack.io/wargame/challenges/6/ cookie ์ฟ ํ‚ค๋กœ ์ธ์ฆ ์ƒํƒœ๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋กœ๊ทธ์ธ ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค. admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Reference Introduction of Webhacking dreamhack.io admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•˜๋ฉด ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฌธ์ œ์ด๋‹ค. ๋ฌธ์ œ์—์„œ ์ œ๊ณตํ•˜๋Š” ์‚ฌ์ดํŠธ์˜ ์ดˆ๊ธฐํ™”๋ฉด์€ ๋„ค๋น„ ์™ธ์—๋Š” ๋ณ„๋กœ ํŠน์ดํ•œ ์ ์€ ์—†๋‹ค. ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€๊ฐ€ ์žˆ๊ธฐ๋Š” ํ•œ๋ฐ ํ˜„์žฌ ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ •์€ ์—†๋‹ค. ๊ณ„์ • ์ •๋ณด๋Š” ๋˜ ๋ฌธ์ œ์—์„œ ์ œ๊ณตํ•˜๋Š” ์‚ฌ์ดํŠธ์˜ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ณด๋ฉด ์•Œ ์ˆ˜ ์žˆ๋Š”๋ฐ, username์ด "guest"์ด๋ฉฐ, ํŒจ์Šค์›Œ๋“œ ๋˜ํ•œ "guest"์ธ ๊ฒฝ์šฐ์— ๋กœ๊ทธ์ธ์ด ๊ฐ€๋Šฅํ•œ ๊ฒƒ์ธ๊ฐ€ ๋ณด๋‹ค. ์ •๋ง guest๋กœ ๋กœ.. 2021. 11. 21.
ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค - ์ œ์ผ ์ž‘์€ ์ˆ˜ ์ œ๊ฑฐํ•˜๊ธฐ, C++ https://programmers.co.kr/learn/courses/30/lessons/12935 ์ฝ”๋”ฉํ…Œ์ŠคํŠธ ์—ฐ์Šต - ์ œ์ผ ์ž‘์€ ์ˆ˜ ์ œ๊ฑฐํ•˜๊ธฐ ์ •์ˆ˜๋ฅผ ์ €์žฅํ•œ ๋ฐฐ์—ด, arr ์—์„œ ๊ฐ€์žฅ ์ž‘์€ ์ˆ˜๋ฅผ ์ œ๊ฑฐํ•œ ๋ฐฐ์—ด์„ ๋ฆฌํ„ดํ•˜๋Š” ํ•จ์ˆ˜, solution์„ ์™„์„ฑํ•ด์ฃผ์„ธ์š”. ๋‹จ, ๋ฆฌํ„ดํ•˜๋ ค๋Š” ๋ฐฐ์—ด์ด ๋นˆ ๋ฐฐ์—ด์ธ ๊ฒฝ์šฐ์—” ๋ฐฐ์—ด์— -1์„ ์ฑ„์›Œ ๋ฆฌํ„ดํ•˜์„ธ์š”. ์˜ˆ๋ฅผ๋“ค์–ด arr์ด [4,3,2,1 programmers.co.kr #include #include using namespace std; vector solution(vector arr) { int min = 999; int idx = -1; for(int i=0; i arr[i] ){ min = arr[i]; idx = i; } } if( arr.size() == 1 ){ arr.. 2021. 11. 21.
SSH ๋กœ๊ทธ์ธ ์ ‘์†์‹œ ํผ๋ฏธ์…˜ ๋ฌธ์ œ ํ‚ค ํŒŒ์ผ์˜ ์†Œ์œ ์ž ์™ธ์—๋„ ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๋“ค์ด ํŒŒ์ผ์— ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ด์„œ ์ƒ๊ธฐ๋Š” ๊ฒฝ๊ณ ๋กœ ์ธํ•œ ์˜ค๋ฅ˜์ž„ [ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•] chmod 600 ~/.ssh/your-key.pem ์ถœ์ฒ˜: https://github.com/rangyu/TIL/blob/master/ubuntu/SSH-%EB%A1%9C%EA%B7%B8%EC%9D%B8-%EC%A0%91%EC%86%8D-%EC%8B%9C-%ED%8D%BC%EB%AF%B8%EC%85%98-%EB%AC%B8%EC%A0%9C-UNPROTECTED-PRIVATE-KEY-FILE.md 2021. 11. 20.
728x90