์ƒˆ์†Œ์‹

Game/los

Lord of sql injection [9]

  • -
๋ฐ˜์‘ํ˜•

 

[9๋ฒˆ๋ฌธ์ œ]

 

์ด ๋ฌธ์ œ๋Š” id==admin์ด๋ฉด ๋˜๋Š”๋ฐ str_replacd๋ผ๋Š” ๋ฌด์–ธ๊ฐ€๋กœ ๋ง‰๊ณ  ์žˆ๋„ค์š”

 

str_replace() ํ•จ์ˆ˜๋ž€?

๋ฌธ์ž ๋˜๋Š” ๋ฌธ์ž์—ด์„ ๋‹ค๋ฅธ๋ฌธ์ž๋กœ ์น˜ํ™˜ํ•˜๋Š” ํ•จ์ˆ˜์ด๋‹ค.

 

์ด ๋ฌธ์ œ์—์„œ๋Š” admin์ด๋ผ๋Š” ๋ฌธ์ž์—ด์ด ๋“ค์–ด์˜ค๋ฉด ๊ณต๋ฐฑ์œผ๋กœ ์น˜ํ™˜ํ•ด์ค€๋‹ค.

str_replaceํ•จ์ˆ˜๋Š” ๋Œ€์†Œ๋ฌธ์ž๋ฅผ ๊ตฌ๋ณ„ํ•˜์ง€ ์•Š๋Š”๊ฒƒ ๊ฐ™๋‹ค admin -> ADMIN ๋˜‘๊ฐ™์ด ๊ณต๋ฐฑ์œผ๋กœ ์น˜ํ™˜๋œ๋‹ค.

(์›๋ž˜๋Š” ๊ตฌ๋ถ„ํ•˜๋Š” ๊ฑธ๋กœ ์•Œ๊ณ  ์žˆ๋Š”๋ฐ, ์ „ los๋ฌธ์ œ์—์„œ๋Š” ADMIN์ด ๋จนํ˜”๋Š”๋ฐ, ํ˜„์žฌ ๋ฐ”๋€ los์—์„œ๋Š” ์น˜ํ™˜๋˜๋„ค์š”..)

 

์•„๋ž˜ ์‚ฌ์ง„์ฒ˜๋Ÿผ admi ๊นŒ์ง€๋Š” id์— ๋“ค์–ด๊ฐ€์ง€๋งŒ, admin์ด๋ผ๋Š” ๋ฌธ์ž์—ด์ด ๋“ค์–ด์˜ค๋ฉด ๋ฐ”๋กœ ๊ณต๋ฐฑ ์ฒ˜๋ฆฌ๊ฐ€ ๋œ๋‹ค.

 

 

 

 

๊ทธ๋ ‡๋‹ค๋ฉด adadminmin ์ด๋Ÿฐ์‹์œผ๋กœ ๋„ฃ์–ด์ค€๋‹ค๋ฉด ์–ด๋–ป๊ฒŒ ๋ ๊นŒ?

admin์ด๋ผ๋Š” ๋ฌธ์ž์—ด์„ ์ง€์šฐ๋‹ˆ ad min ์•ž๋’ค๊ฐ€ ์—ฐ๊ฒฐ๋˜์–ด  admin์ด๋ผ๋Š” ๋ฌธ์ž์—ด์ด ๋“ค์–ด๊ฐ€๊ฒ ์ง€!?

 

 

 

clear

 

๋ฐ˜์‘ํ˜•

'Game > los' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

Lord of sql injection [11]  (0) 2020.09.11
Lord of sql injection [10]  (0) 2020.09.11
Lord of sql injection [8]  (0) 2020.09.11
Lord of sql injection [7]  (0) 2020.09.11
Contents

ํฌ์ŠคํŒ… ์ฃผ์†Œ๋ฅผ ๋ณต์‚ฌํ–ˆ์Šต๋‹ˆ๋‹ค

์ด ๊ธ€์ด ๋„์›€์ด ๋˜์—ˆ๋‹ค๋ฉด ๊ณต๊ฐ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค.