Latest Posts

Fresh thoughts and recent updates from the blog

์นดํ…Œ๊ณ ๋ฆฌ ์—†์Œ

[2022๋…„ ์ •๋ณด์ฒ˜๋ฆฌ๊ธฐ์‚ฌ ํ•„๊ธฐ] 2. ์†Œํ”„ํŠธ์›จ์–ด๊ฐœ๋ฐœ: Cp1. ๋ฐ์ดํ„ฐ์ž…์ถœ๋ ฅ ๊ตฌํ˜„2

2022๋…„ ์ •๋ณด์ฒ˜๋ฆฌ๊ธฐ์‚ฌ ํ•„๊ธฐ (์ˆ˜์ œ๋น„ 2021๋…„ ํ•„๊ธฐ์ฑ… ๋ณด๊ณ  ๊ณต๋ถ€ํ•˜๋ฉฐ ์š”์•ฝํ•œ ๋‚ด์šฉ์ž…๋‹ˆ๋‹ค.) http://www.yes24.com/Product/Goods/96051171 2. ์†Œํ”„ํŠธ์›จ์–ด ๊ฐœ๋ฐœ Cp1. ๋ฐ์ดํ„ฐ ์ž…์ถœ๋ ฅ ๊ตฌํ˜„2 1. ํ”„๋กœ์‹œ์ € : ์ฟผ๋ฆฌ๋“ค์„ ํ•˜๋‚˜์˜ ํ•จ์ˆ˜์ฒ˜๋Ÿผ ์‹คํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ์ฟผ๋ฆฌ์˜ ์ง‘ํ•ฉ : DB ๋‚ด๋ถ€์— ์ €์žฅ๋˜๊ณ  ์ผ์ • ์กฐ๊ฑด์ด ๋˜๋ฉด ์ž๋™ ์ˆ˜ํ–‰๋จ 1-1. ์ ˆ์ฐจํ˜• ๋ฐ์ดํ„ฐ ์กฐ์ž‘ ํ”„๋กœ์‹œ์ € : Oracle PL/SQL 1) ์ปดํŒŒ์ผ ๋ถˆํ•„์š”: ์Šคํฌ๋ฆฝํŠธ ์ƒ์„ฑ ๋ฐ ๋ณ€๊ฒฝ ํ›„ ์‹คํ–‰๊ฐ€๋Šฅ 2) ๋ชจ๋“ˆํ™” ๊ฐ€๋Šฅ: ๋ธ”๋ก ๋‚ด ๋…ผ๋ฆฌ์ ์œผ๋กœ ๊ด€๋ จ๋œ ๋ฌธ์žฅ ๊ทธ๋ฃนํ™” ๊ฐ€๋Šฅ, ๋ชจ๋“ˆ ์ง‘ํ•ฉ์œผ๋กœ ๊ตฌ์„ฑ 3) ์ ˆ์ฐจ์  ์–ธ์–ด ์‚ฌ์šฉ: DBํ…Œ์ด๋ธ” ๊ณผ ๋ ˆ์ฝ”๋“œ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋Š” ๋™์ ๋ณ€์ˆ˜ ์„ ์–ธ ๊ฐ€๋Šฅ. ๋‹จ์ผํ˜•/๋ณตํ•ฉ๋ณ‘ ๋ฐ์ดํ„ฐ ํƒ€์ž… ์„ ์–ธ ๊ฐ€๋Šฅ 4) ์—๋Ÿฌ์ฒ˜๋ฆฌ: ์˜ˆ์™ธ์ฒ˜๋ฆฌ ๋ฃจํ‹ด์„ ์ด..

By domdomi ยท 2022. 2. 27.

Security/Wargame

[Lord of SQLi] dragon Writeup/๋ฌธ์ œํ’€์ด

์ด๋ฒˆ ๋ฌธ์ œ๋Š” ๋‹ค๋ฅธ ๋ฌธ์ œ์™€๋Š” ๋‹ค๋ฅด๊ฒŒ ๋ณ„๋‹ค๋ฅธ ํ•„ํ„ฐ๋ง์ด ์—†์Šต๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ํฌํ•œํ•˜๊ฒŒ๋„ query๋ฌธ์— ์ฃผ์„(#)์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์–ธ๋œป๋ณด๋ฉด pw ์— ์–ด๋–ค ๊ฑธ ์ž…๋ ฅํ•ด๋„ ๋ชจ๋‘ ์ฃผ์„์ฒ˜๋ฆฌ๋˜์–ด์„œ mysql ์ฟผ๋ฆฌ ๊ฒฐ๊ณผ๋ฅผ ์กฐ์ž‘ํ•  ์ˆ˜ ์—†๋Š” ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ด๋Š”๋ฐ ๋ง์ด์ฃ . ์ •๋ง ๊ทธ๋žฌ๋‹ค๋ฉด, ๋ฌธ์ œ๋กœ ๋‚˜์˜ค์ง€๋„ ์•Š์•˜๊ฒ ์ง€๋งŒ ๋ง์ž…๋‹ˆ๋‹ค. ์‚ฌ์‹ค mysql ์—์„œ # ์ฃผ์„๋ฌธ์€ ํ•œ ์ค„ ์ฃผ์„๋ฌธ์ž…๋‹ˆ๋‹ค. ๋ง๊ทธ๋Œ€๋กœ ํ•œ ์ค„์— ๋Œ€ํ•œ ์ฃผ์„์ด๊ธฐ ๋•Œ๋ฌธ์— ๋‹ค์Œ ์ค„์—๋Š” ํ•ด๋‹น๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. SQL ์ฟผ๋ฆฌ๋ฌธ์€ ์—ฌ๋Ÿฌ์ค„์„ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ์˜ˆ์‹œ๋ฅผ ๋ณด๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. mysql> select * from user -> where user='guest'; +----+-------+----------+ | id | user | pass | +----+-------+------..

By ์•Œ ์ˆ˜ ์—†๋Š” ์‚ฌ์šฉ์ž ยท 2021. 10. 25.

Tools/Etc

[2021 ์ •๋ณด์ฒ˜๋ฆฌ๊ธฐ์‚ฌ ์‹ค๊ธฐ] 10. SQL ์‘์šฉ

๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ธฐ๋ณธ ํŠธ๋žœ์žญ์…˜ : ๋น„์ธ๊ฐ€์ž๋กœ๋ถ€ํ„ฐ ๋ฐ์ดํ„ฐ ๋ณด์žฅ์œ„ํ•ด DBMS๊ฐ€ ๊ฐ€์ง€๋Š” ํŠน์„ฑ, DBMS์—์„œ ํ•˜๋‚˜์˜ ๋…ผ๋ฆฌ์  ๊ธฐ๋Šฅ์„ ์ •์ƒ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ์ž‘์—…์˜ ๊ธฐ๋ณธ๋‹จ์œ„. ํŠน์„ฑ ์„ค๋ช… ์ฃผ์š”๊ธฐ๋ฒ• ์›์ž์„ฑ -๋ถ„ํ•ด๋ถˆ๊ฐ€ํ•œ ์ž‘์—…์˜ ์ตœ์†Œ๋‹จ์œ„ -์—ฐ์‚ฐ์ „์ฒด๊ฐ€ ์„ฑ๊ณต๋˜๋Š”์‹คํŒจ (ํ•˜๋‚˜๋ผ๋„ ์‹คํŒจ๋˜๋ฉด ์ „์ฒด์ทจ์†Œ๋จ.) commit rollback ํšŒ๋ณต์„ฑ ๋ณด์žฅ ์ผ๊ด€์„ฑ ํŠธ์žญ ์‹คํ–‰์„ฑ๊ณตํ›„ ํ•ญ์ƒ ์ผ๊ด€๋œ DB์ƒํƒœ ๋ณด์กดํ•ด์•ผํ•จ ๋ฌด๊ฒฐ์„ฑ์ œ์•ฝ์กฐ๊ฑด ๋™์‹œ์„ฑ ์ œ์–ด ๊ฒฉ๋ฆฌ์„ฑ ํŠธ์žญ ์‹คํ–‰์ค‘ ์ƒ์„ฑํ•˜๋Š” ์—ฐ์‚ฐ ์ค‘๊ฐ„๊ฒฐ๊ณผ๋ฅผ ๋‹ค๋ฅธ ํŠธ์žญ์ด ์ ‘๊ทผ๋ถˆ๊ฐ€ Read Uncommited Read Commited Repeatable Read Serializeble ์˜์†์„ฑ ์„ฑ๊ณต์™„๋ฃŒ๋œ ํŠธ์žญ๊ฒฐ๊ณผ๋Š” ์˜์†์ ์œผ๋กœ DB์— ์ €์žฅ๋จ ํšŒ๋ณต๊ธฐ๋ฒ• *read uncommited: ํ•œ ํŠธ์žญ์—์„œ ์—ฐ์‚ฐ ์ค‘์ธ ๋ฐ์ดํ„ฐ๋ฅผ ๋‹ค๋ฅธ ํŠธ์žญ์ด ์ฝ๋Š” ๊ฒƒ..

By domdomi ยท 2021. 7. 5.
728x90
๋ฐ˜์‘ํ˜•
728x90
๋ฐ˜์‘ํ˜•

Visitor Trends

Daily blog stats and creator awards

โœฟ DASHBOARD
Today

Yesterday

Total

Posts

0

2023 IT Creator
2024 Food Creator
2025 News Creator
2026 News Creator