Latest Posts

Fresh thoughts and recent updates from the blog

Security/Wargame

[Lord of SQLi] dragon Writeup/๋ฌธ์ œํ’€์ด

์ด๋ฒˆ ๋ฌธ์ œ๋Š” ๋‹ค๋ฅธ ๋ฌธ์ œ์™€๋Š” ๋‹ค๋ฅด๊ฒŒ ๋ณ„๋‹ค๋ฅธ ํ•„ํ„ฐ๋ง์ด ์—†์Šต๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ํฌํ•œํ•˜๊ฒŒ๋„ query๋ฌธ์— ์ฃผ์„(#)์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์–ธ๋œป๋ณด๋ฉด pw ์— ์–ด๋–ค ๊ฑธ ์ž…๋ ฅํ•ด๋„ ๋ชจ๋‘ ์ฃผ์„์ฒ˜๋ฆฌ๋˜์–ด์„œ mysql ์ฟผ๋ฆฌ ๊ฒฐ๊ณผ๋ฅผ ์กฐ์ž‘ํ•  ์ˆ˜ ์—†๋Š” ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ด๋Š”๋ฐ ๋ง์ด์ฃ . ์ •๋ง ๊ทธ๋žฌ๋‹ค๋ฉด, ๋ฌธ์ œ๋กœ ๋‚˜์˜ค์ง€๋„ ์•Š์•˜๊ฒ ์ง€๋งŒ ๋ง์ž…๋‹ˆ๋‹ค. ์‚ฌ์‹ค mysql ์—์„œ # ์ฃผ์„๋ฌธ์€ ํ•œ ์ค„ ์ฃผ์„๋ฌธ์ž…๋‹ˆ๋‹ค. ๋ง๊ทธ๋Œ€๋กœ ํ•œ ์ค„์— ๋Œ€ํ•œ ์ฃผ์„์ด๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค์Œ ์ค„์—๋Š” ํ•ด๋‹น๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. SQL ์ฟผ๋ฆฌ๋ฌธ์€ ์—ฌ๋Ÿฌ์ค„์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ์˜ˆ์‹œ๋ฅผ ๋ณด๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. mysql> select * from user -> where user='guest'; +----+-------+----------+ | id | user | pass | +----+-------+------..

By ์•Œ ์ˆ˜ ์—†๋Š” ์‚ฌ์šฉ์ž ยท 2021. 10. 25.
728x90
๋ฐ˜์‘ํ˜•
728x90
๋ฐ˜์‘ํ˜•

Visitor Trends

Daily blog stats and creator awards

โœฟ DASHBOARD
Today

Yesterday

Total

Posts

0

2023 IT Creator
2024 Food Creator
2025 News Creator
2026 News Creator