Latest Posts

Fresh thoughts and recent updates from the blog

Security/CTF

[Web] Do you know Hashes - 2021 INCOGNITO CTF Writeup

Web ๋ฌธ์ œ ์ค‘์—์„œ ์ œ์ผ ์ ์ˆ˜๊ฐ€ ๋‚ฎ์€ ๋ฌธ์ œ๋กœ hash collision ๊ณผ php ๋น„๊ต ์—ฐ์‚ฐ์ž(php magic hash) ๊ด€๋ จ ๋ฌธ์ œ์˜€์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œ๋ฅผ ๋ณด๋ฉด ์ฒ˜์Œ์—” md5 hash ์™€ crc32 hash ๊ฐ’์ด ์„œ๋กœ ์ผ์น˜ํ•ด์•ผ ํ•˜๊ณ  ๋‘ ๋ฒˆ์งธ์—” crc32 ์™€ md4 ๊ฐ€, ์„ธ ๋ฒˆ์งธ์—” md5์™€ md4๊ฐ€ ์ผ์น˜ํ•ด์•ผ ํ•œ๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ์œ„ ๋ฌธ์ œ๋ฅผ ํ’€๊ธฐ์ „์— ์ผ๋‹จ php magic hash ๊ด€๋ จ ๋‚ด์šฉ์„ ์ฐพ์•„๋ณด์•˜์Šต๋‹ˆ๋‹ค. ์œ„ ์ฝ”๋“œ์—์„œ a์™€ b๋Š” ์„œ๋กœ ๋‹ค๋ฅธ ๊ฐ’์ด์ง€๋งŒ php ๋น„๊ต ์—ฐ์‚ฐ์ž์—์„œ๋Š” ๋‘ ๊ฐ’์ด ์ฐธ์ด ๋‚˜์˜ต๋‹ˆ๋‹ค. ์ •์ˆ˜์˜ ํ˜•ํƒœ๋กœ ๋น„๊ตํ•˜๋Š” php ๋น„๊ต ์—ฐ์‚ฐ์ž๋Š” a์˜ ๊ฐ’์„ 0 * 10^123456 ์œผ๋กœ ์ธ์‹ํ•˜์—ฌ ๊ฒฐ๊ตญ 0 ๊ฐ’์œผ๋กœ ์ธ์‚ญํ•˜๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฏ€๋กœ ๋‘ ๋ณ€์ˆ˜ ๋ชจ๋‘ 0 ๊ฐ’์ด๋ฏ€๋กœ true ๊ฐ’์ด ๋ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฐ ํ˜„์ƒ์„ ์ด์šฉํ•˜์—ฌ 0e ๋กœ ์‹œ..

By ์•Œ ์ˆ˜ ์—†๋Š” ์‚ฌ์šฉ์ž ยท 2021. 8. 31.
728x90
๋ฐ˜์‘ํ˜•
728x90
๋ฐ˜์‘ํ˜•

Visitor Trends

Daily blog stats and creator awards

โœฟ DASHBOARD
Today

Yesterday

Total

Posts

0

2023 IT Creator
2024 Food Creator
2025 News Creator
2026 News Creator