[LOS] ORGE ํ’€์ด(7)

7๋ฒˆ์งธ ๋ฌธ์ œ์ธ " orge " ๋Š” ์ „์— ํ’€์—ˆ๋˜ " orc " ๋ฌธ์ œ์™€ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค. " pw='{$_GET [pw]} " ์•ˆ์— ์ฟผ๋ฆฌ๋ฌธ์„ ์‚ฝ์ž…ํ•˜์—ฌ ์‹คํ–‰๋˜๋Š” ํ˜•ํƒœ์ด์ง€๋งŒ ๋ช‡ ๊ฐ€์ง€ ๋‹ค๋ฅธ ์ ์ด ์กด์žฌํ•ฉ๋‹ˆ๋‹ค. ๊ฒ€์ฆ๊ตฌ๋ฌธ 1. ๊ธฐ์กด admin ๊ณ„์ • ์ด์™ธ์— guest ๊ณ„์ •์ด ์ถ”๊ฐ€์ ์œผ๋กœ ์กด์žฌํ•จ 2. or , and ์—ฐ์‚ฐ์ž๋ฅผ ์ถ”๊ฐ€์ ์œผ๋กœ ๊ฒ€์ฆํ•˜๊ณ  ์žˆ์Œ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ํฌ์ธํŠธ ๋ถ€๋ถ„์€ $query = "select pw from prob_orge where id='admin' and pw='{$_GET [pw]}'"; if(($result ['pw']) && ($result['pw'] == $_GET ['pw'])) solve("orge"); ์œ„์ฒ˜๋Ÿผ 'admin' ๊ณ„์ •์œผ๋กœ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ์ถ”๊ฐ€์ ์œผ๋กœ ์„ ์–ธํ•ด์ค˜์•ผ ํ•˜๋ฉฐ, ์ž…๋ ฅ๋œ p..

CHALLENGE
[LOS] darkelf ํ’€์ด(6)

6๋ฒˆ์งธ ๋ฌธ์ œ " darkelf "์ž…๋‹ˆ๋‹ค. ORC ๋ ˆ๋ฒจ์—์„œ ์‹œ๊ฐ„์ด ์ข€ ์†Œ์š”๋˜์—ˆ์ง€๋งŒ ๊ทธ ์ดํ›„๋ฌธ์ œ๋Š” ๊ธˆ๋ฐฉ ํ•ด๊ฒฐ๋˜๋Š” ๋ฌธ์ œ๋“ค์ด ๋งŽ์Šต๋‹ˆ๋‹ค.ํ˜„์žฌ ์†Œ์Šค๋ฅผํ™•์ธํ•ด๋ณด๋ฉด ์ฟผ๋ฆฌ๋ฌธ์„ ๋ฐ›์•„ ์‹คํ–‰๋˜๋Š” ์ฝ”๋“œ๋Š” " $_GET [pw] ์ž…๋‹ˆ๋‹ค. if(preg_match('/prob|_|\.|\(\)/i', $_GET[pw$_GET [pw])) exit("No Hack ~_~"); if(preg_match('/or|and/i', $_GET[pw$_GET [pw])) exit("HeHe"); ๋‘ ๋ฒˆ์งธ ํ•„ํ„ฐ๋ง ๊ฒ€์ฆ์„ ๋ณด์‹œ๋ฉด ๋ฌธ์ž์—ด " or " ์™€ " and " ๊ตฌ๋ฌธ์„ ๊ฒ€์ฆํ•˜๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด์•ผ ๋ฉ๋‹ˆ๋‹ค. if($result ['id']'admin') solve("darkelf"); ๋˜ํ•œ ํ•ด๋‹น๋ถ€๋ถ„์„ ๋ณด์‹œ๋ฉด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜..

CHALLENGE