๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ ๋ฉ”๋‰ด ๋ฐ”๋กœ๊ฐ€๊ธฐ
ABOUT

โ˜๏ธ Guleum LAB

sql injection org ์šฐํšŒ (1)
ํ”„๋กœํ•„์‚ฌ์ง„
๐ŸŒง:
Guluem
๊ฒ€์ƒ‰ํ•˜๊ธฐ
  • ALL (109)
    • WEB (27)
    • MOBILE (23)
    • CLOUD (1)
    • CHALLENGE (43)
    • ETC (15)
ยซ   2025/05   ยป
์ผ ์›” ํ™” ์ˆ˜ ๋ชฉ ๊ธˆ ํ† 
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Tags
  • sudo.co.il xss
  • SQL INJECTION ๊ฒŒ์ž„
  • los ๋ฌธ์ œ
  • xss ์šฐํšŒ
  • xss ๊ณต๊ฒฉ ์˜ˆ์ œ
  • XSS ๊ฒŒ์ž„
  • xss ํ…Œ์ŠคํŠธ
  • sql injection ๋ฌธ์ œ
  • xss ์‹ค์Šต
  • nopernik XSS
  • rubiya sql injection
  • xss ๊ณต๊ฒฉ์ด๋ž€
  • lord of sql injection
  • xss ๋ž€
  • cross site scripting
more
[LOS] Bugbear ํ’€์ด(13)

13๋ฒˆ์งธ ๋ฌธ์ œ์ธ " bugbear "์ž…๋‹ˆ๋‹ค. bugbear์˜ ๊ฒฝ์šฐ ๊ฒ€์ฆํ•˜๋Š” ํ‚ค์›Œ๋“œ๊ฐ€ ๋งŽ์ด ๋Š˜์–ด๋‚˜ ์šฐํšŒ ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•ด์„œ ์ฟผ๋ฆฌ๋ฌธ์„ ์ž‘์„ฑํ•ด์•ผ ๋ฉ๋‹ˆ๋‹ค. if(preg_match('/prob|_|\.|\(\)/i', $_GET[no])) exit("No Hack ~_~"); if(preg_match('/\'/i', $_GET[pw])) exit("HeHe"); if(preg_match('/\'|substr|ascii|=|or|and| |like|0x/i', $_GET[no])) exit("HeHe"); ์ƒˆ๋กญ๊ฒŒ ๊ฒ€์ฆํ•˜๋Š” ํ•„ํ„ฐ๋ง์€ or ๊ตฌ๋ฌธ ๋Œ€์‹  ์‚ฌ์šฉ๋˜์—ˆ๋˜ " like " ๋ฅผ ๊ฒ€์ฆํ•˜๊ณ  hex ์ฝ”๋“œ ์‹คํ–‰ ๋ฐฉ์ง€๋ฅผ ์œ„ํ•ด "0x"๊นŒ์ง€ ๊ฒ€์ฆํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ " ascii " ์ฝ”๋“œ์‚ฌ์šฉํ•˜๋Š”๊ฒƒ๊นŒ์ง€ ๋ง‰๊ณ  ์žˆ๊ธฐ์— " ord " ๋ฅผ..

CHALLENGE
์ด์ „ 1 ๋‹ค์Œ

  • ๊ธ€์“ฐ๊ธฐ
  • ๊ด€๋ฆฌ
  • ํƒœ๊ทธ
Contact guleum.zone@gmail.com

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”