๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ ๋ฉ”๋‰ด ๋ฐ”๋กœ๊ฐ€๊ธฐ
ABOUT

โ˜๏ธ Guleum LAB

SQL INJECTION = ์šฐํšŒ (1)
ํ”„๋กœํ•„์‚ฌ์ง„
๐ŸŒง:
Guluem
๊ฒ€์ƒ‰ํ•˜๊ธฐ
  • ALL (109)
    • WEB (27)
    • MOBILE (23)
    • CLOUD (1)
    • CHALLENGE (43)
    • ETC (15)
ยซ   2025/05   ยป
์ผ ์›” ํ™” ์ˆ˜ ๋ชฉ ๊ธˆ ํ† 
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Tags
  • sql injection ๋ฌธ์ œ
  • nopernik XSS
  • SQL INJECTION ๊ฒŒ์ž„
  • sudo.co.il xss
  • xss ๊ณต๊ฒฉ์ด๋ž€
  • XSS ๊ฒŒ์ž„
  • xss ๊ณต๊ฒฉ ์˜ˆ์ œ
  • los ๋ฌธ์ œ
  • xss ์šฐํšŒ
  • lord of sql injection
  • xss ๋ž€
  • xss ํ…Œ์ŠคํŠธ
  • xss ์‹ค์Šต
  • rubiya sql injection
  • cross site scripting
more
[LOS] Darkknight ํ’€์ด(12)

12๋ฒˆ์งธ ๋ฌธ์ œ์ธ "darkknight"๋ฅผ ๋ณด์‹œ๋ฉด preg_match ํ•จ์ˆ˜๋ฅผ ์‚ฌ์šฉํ•œ ๋‹ค์–‘ํ•œ ํ•„ํ„ฐ๋ง ๊ฒ€์ฆ์ด ์ถ”๊ฐ€๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. if(preg_match('/prob|_|\.|\(\)/i', $_GET [no])) exit("No Hack ~_~"); if(preg_match('/\'/i', $_GET[pw])) exit("HeHe"); if(preg_match('/\'|substr|ascii|=/i', $_GET [no])) exit("HeHe"); ๋น„๊ต ์—ฐ์‚ฐ์ž์ธ or ๋‚˜ and ๋Š” ๊ฒ€์ฆ์„ ํ•˜์ง€ ์•Š๊ณ  ์žˆ์ง€๋งŒ ์ „ ๋‹จ๊ณ„๋“ค๊ณผ ๋‹ค๋ฅด๊ฒŒ ์‹ฑ๊ธ€ ์ฟผํ„ฐ( ' )๋ฅผ ์ฐจ๋‹จํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— " ์‹ฑ๊ธ€ ์ฟผํ„ฐ "๋ฅผ ๋Œ€์‹ ํ•  ๋ฐฉ๋ฒ•์„ ์ฐพ์•„์•ผ ํ•  ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ํ•„ํ„ฐ๋ง ์šฐํšŒ = --> like ๋˜๋Š” between์„ ์‚ฌ์šฉ subs..

CHALLENGE
์ด์ „ 1 ๋‹ค์Œ

  • ๊ธ€์“ฐ๊ธฐ
  • ๊ด€๋ฆฌ
  • ํƒœ๊ทธ
Contact guleum.zone@gmail.com

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”