๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ ๋ฉ”๋‰ด ๋ฐ”๋กœ๊ฐ€๊ธฐ
ABOUT

โ˜๏ธ Guleum LAB

los 3๋ฒˆ (1)
ํ”„๋กœํ•„์‚ฌ์ง„
๐ŸŒง:
Guluem
๊ฒ€์ƒ‰ํ•˜๊ธฐ
  • ALL (109)
    • WEB (27)
    • MOBILE (23)
    • CLOUD (1)
    • CHALLENGE (43)
    • ETC (15)
ยซ   2025/05   ยป
์ผ ์›” ํ™” ์ˆ˜ ๋ชฉ ๊ธˆ ํ† 
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Tags
  • xss ๊ณต๊ฒฉ ์˜ˆ์ œ
  • cross site scripting
  • sudo.co.il xss
  • xss ๋ž€
  • SQL INJECTION ๊ฒŒ์ž„
  • nopernik XSS
  • sql injection ๋ฌธ์ œ
  • los ๋ฌธ์ œ
  • xss ์šฐํšŒ
  • rubiya sql injection
  • xss ์‹ค์Šต
  • xss ํ…Œ์ŠคํŠธ
  • xss ๊ณต๊ฒฉ์ด๋ž€
  • lord of sql injection
  • XSS ๊ฒŒ์ž„
more
[LOS] goblin ํ’€์ด(3)

$query = "select id from prob_goblin where id='guest' and no={$_GET[no]}"; goblin ๊ฐ™์€ ๊ฒฝ์šฐ ์ „ ๊ณผ๋Š” ๋‹ค๋ฅธ ๊ฒŒ no={$_GET [no]} ์˜์—ญ์— ์ฟผ๋ฆฌ๋ฌธ์„ ์‚ฝ์ž…ํ•˜์—ฌ admin ๊ณ„์ •์œผ๋กœ ์ ‘๊ทผํ•ด์•ผ ๋ฉ๋‹ˆ๋‹ค. if(preg_match('/prob|_|\.|\(\)/i', $_GET[no])) exit("No Hack ~_~"); if(preg_match('/\'|\"|\`/i', $_GET[no])) exit("No Quotes ~_~"); ๋˜ํ•œ preg_match์˜ ์˜์—ญ์ด ํ•˜๋‚˜ ๋” ์ถ”๊ฐ€๋˜๋ฉด์„œ ์‹ฑ๊ธ€ ์ฟผํ„ฐ(')์™€ ๋”๋ธ”์ฟผํ„ฐ(") ๊ณผ ์กด์žฌํ•  ๊ฒฝ์šฐ " No Quotes " ํŽ˜์ด์ง€๋กœ ๋„˜๊น€์œผ๋กœ์จ ํ•„ํ„ฐ๋ง ์˜์—ญ์ด ์ถ”๊ฐ€๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‹ฑ๊ธ€ ์ฟผํ„ฐ๋ฅผ "..

CHALLENGE
์ด์ „ 1 ๋‹ค์Œ

  • ๊ธ€์“ฐ๊ธฐ
  • ๊ด€๋ฆฌ
  • ํƒœ๊ทธ
Contact guleum.zone@gmail.com

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”