Security Study/Web

HTTP Method ๊ด€๋ จํ•˜์—ฌ ์•Œ์•„๊ฐ€๋Š” ๊ฒƒ

๐“›๐“พ๐“ฌ๐“ฎ๐“ฝ๐“ฎ_๐“ข๐“ฝ๐“ฎ๐“ต๐“ต๐“ช 2023. 8. 9.
728x90
๋ฐ˜์‘ํ˜•

ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ์„ ์•Œ๋ ค๋“œ๋ฆฌ๋ฉฐ, ๊ธ€์“ด์ด๋Š” ์•„๋ฌด๋Ÿฐ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ผญ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

์š”์ฆ˜ ์—…๋ฌด๋ฅผ ํ•˜๋ฉด์„œ ์ทจ์•ฝ์  ์ ๊ฒ€์„ ๋งŽ์ดํ•˜๊ณ  ์žˆ๋‹ค. ์ด๊ฒƒ์ €๊ฒƒ ํ•˜๋‹ค๋ณด๋‹ˆ ๊ทธ๋ƒฅ ๊ฐœ๋…์ •๋ฆฌ๋กœ ์ž‘์„ฑํ•œ๋‹ค.

๋ฉ”์†Œ๋“œ์—๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ GET, POST, OPTIONS, HEAD, DELETE, PUT ๊ฐ€ ์žˆ๋‹ค. ๋ญ ๊ฐ€๋” TRACE ๋„ ์‚ฌ์šฉํ• ๋•Œ๊ฐ€ ์žˆ๋‹ค.

 

์ฃผ์š”์ •๋ณดํ†ต์‹ ๊ธฐ๋ฐ˜์‹œ์„ค ๊ฐ€์ด๋“œ๋ผ์ธ๊ณผ ๊ฐ™์€ ํ•ญ๋ชฉ์—” ๋ถˆํ•„์š”ํ•œ ๋ฉ”์†Œ๋“œ๋ฅผ ์—†์• ๋ผ๊ณ  ๊ถŒ๊ณ ๋ฅผ ํ•˜๊ณ ์žˆ๋‹ค. ๊ธฐ๋ณธ์ ์œผ๋กœ GET, POST๋งŒ ์—ด์–ด๋‘๋Š” ๊ณณ์ด ๋งŽ์€๋ฐ ๊ฐ€๋” ๋ฉ”์†Œ๋“œ๊ฐ€ ๋ชจ๋‘ ์—ด๋ ค์žˆ๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. 

 

๊ฐ„๋‹จํ•˜๊ฒŒ ์„ค๋ช…์„ ํ•ด๋ณด์ž๋ฉด GET, POST๋Š” ์ƒ๋žตํ•˜๊ณ  OPTIONS์€ allow๋˜์–ด์žˆ๋Š” ๋ฉ”์†Œ๋“œ๋ฅผ ํ™•์ธํ• ์ˆ˜์žˆ๊ฒŒํ•ด์ฃผ๋Š” ๋ฉ”์†Œ๋“œ์ด๋‹ค.

curl -v -L -X OPTIONS blog.z3alous.xyz

์ด๋ ‡๊ฒŒ ํ•œ๋ฒˆ ํ•ด๋ณด๋ฉด 

์ด๋ ‡๊ฒŒ Allow๋กœ ์—ด๋ ค์žˆ๋Š” ๋ฉ”์†Œ๋“œ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

 

HEAD๋Š” ํ—ค๋” ์ •๋ณด๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ์ด๊ณ  DELETE๋Š” ์‚ญ์ œ, PUT์€ ๋ฐ€์–ด๋„ฃ๋Š” ๊ฒƒ์ด๋ผ๊ณ  ์ƒ๊ฐํ•˜๋ฉด ๋œ๋‹ค.

 

๋งŒ์•ฝ์— PUT์ด ์—ด๋ ค์žˆ๋‹ค๋ฉด ํŒŒ์ผ ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•œ๋ฐ ์ด๋Ÿฐ์‹์˜ ๊ตฌ๋ฌธ์„ ํ†ตํ•˜์—ฌ ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋‹ค.

curl -v -L -k https://victim.com/ --upload-file /home/z3alous/Desktop/payload.jsp

์ด๋Ÿฐ์‹์˜ ๊ตฌ๋ฌธ์œผ๋กœ ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋‹ค.

์ €๋ ‡๊ฒŒ ํ•˜๋ฉด ๊ฒฐ๊ณผ๋Š” ์ด๋Ÿฐ์‹์œผ๋กœ ๋œจ๊ฒŒ ๋˜๋Š”๋ฐ...

> PUT /test.jsp HTTP/1.1
> Host: victim.com
> User-Agent: curl/7.88.1
> Accept: */*
> Content-Length: 34
> Expect: 100-continue
> 
< HTTP/1.1 100 Continue
* We are completely uploaded and fine
< HTTP/1.1 404 Not Found
< Server: Apache
< Cache-Control: private
< Expires: Thu, 01 Jan 1970 09:00:00 KST
< Set-Cookie: JSESSIONID=; Path=/; Secure; HttpOnly
< Content-Type: text/html;charset=UTF-8
< Content-Length: 1098
< Date: Tue, 08 Aug 2023 06:43:29 GMT
< Connection: close

์‘๋‹ต์ฝ”๋“œ 100 Continue๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด์„œ We are completely uploaded and fine์ด๋ผ๋Š” ๊ตฌ๋ฌธ์„ ๋ณด์—ฌ์ค€๋‹ค.

๊ทผ๋ฐ 404๊ฐ€ ์—ฐ๋‹ฌ์•„ ๋œจ๋ฉด์„œ ํŒŒ์ผ์€ not found๊ฐ€ ๋œ๋‹ค.... ์ด ๋ถ€๋ถ„์€ ์ดํ•ด๊ฐ€ ์ž˜์•ˆ๊ฐ€๋Š”๋ฐ 404์—๋Ÿฌ๋ฅผ ์žก์œผ๋ฉด 403 ๊ถŒํ•œ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š”๋ฐ  ์›๋ž˜๋Š” put์„ ์ด์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—…๋กœ๋“œ ํ•˜๊ฒŒ๋˜๋ฉด 201 ์‘๋‹ต์ฝ”๋“œ๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด์„œ ์ •์ƒ์ ์œผ๋กœ ์—…๋กœ๋“œ๊ฐ€๋œ๋‹ค. 

 

403๊ณผ 404์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ์›์ธ์€ ํ…Œ์ŠคํŠธ๋ฅผ ์ข€ํ•ด๋ด์•ผํ•  ๊ฒƒ๊ฐ™๋‹ค. ํ˜น์—ฌ๋‚˜ ์•„๋Š” ์‚ฌ๋žŒ์žˆ์œผ๋ฉด ๋Œ“๊ธ€๋กœ ์•Œ๋ ค์ฃผ๋ฉด ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.!!! 

 

ํ• ํŠผ put๋ฉ”์†Œ๋“œ๋ฅผ ์ด์šฉํ•˜์—ฌ ํŒŒ์ผ์—…๋กœ๋“œ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋ฉฐ ์•…์šฉ์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

์„œ๋ฒ„๋ฅผ ๋‹ด๋‹นํ•˜๊ฑฐ๋‚˜ ๊ด€๋ฆฌ๋ฅผ ํ•˜๋Š” ์ž…์žฅ์—์„  ๋ฉ”์†Œ๋“œ๊ฐ€ ๋ณ„๊ฒƒ์ด ์•„๋‹Œ๊ฒƒ๊ฐ™์ง€๋งŒ ํฌ๋ฆฌํ‹ฐ์ปฌํ•œ ์ทจ์•ฝ์ ์œผ๋กœ ๋‹ค๊ฐ€์˜ฌ์ˆ˜ ์žˆ์Œ์„ ์•Œ๊ณ ์žˆ์–ด์•ผํ•  ๊ฒƒ๊ฐ™๋‹ค.

 

728x90
๋ฐ˜์‘ํ˜•

๋Œ“๊ธ€