Security Study/Web

webhacking

๐“›๐“พ๐“ฌ๐“ฎ๐“ฝ๐“ฎ_๐“ข๐“ฝ๐“ฎ๐“ต๐“ต๐“ช 2015. 10. 16.
728x90
๋ฐ˜์‘ํ˜•


 

web hacking - 1) ์„œ๋ฒ„์— ์žˆ๋Š” ๊ฐœ์ธ์ •๋ณด ํƒˆ์ทจ

                        2)  ์‹œ์Šคํ…œํ•ดํ‚น์„ ์œ„ํ•œ ๋ฐœํŒ

 

XSS(ํฌ๋กœ์Šค ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŠธ) - ๊ณต๊ฒฉ์ž๊ฐ€ ์„œ๋ฒ„๋ฅผ ํ†ตํ•ด ์‚ฌ์šฉ์ž๋ฅผ ๊ณต๊ฒฉ           

๋‹ค๋ฅธ ์‚ฌ์šฉ์ž์ฟ ํ‚ค๋‚˜ ์„ธ์…˜์•„์ด๋””๋ฅผ ํƒˆ์ทจํ•ด์„œ ์‚ฌ์šฉ์ž์˜ ๊ถŒํ•œ์„ ์Šต๋“

sotored - ์ €์žฅ๋˜์žˆ๋Š” ๊ฒƒ

 

(์ด๋ฒคํŠธ ํ•ธ๋“ค๋Ÿฌ) โ€“ ์ด์šฉ ex)<script>alert(1);</script>

< img src=x onerror=alert(123)>

                                                bob"onmouseover="alert(1)"

                                               

๋ฐ‘์˜ ๋‘์ค„์ด ํ•œ์Šคํฌ๋ฆฝํŠธ

โ€˜โ€a=โ€™

                                                โ€˜onerror=alert(1);>

 

 

reflected โ€“ ์ฟ ๊ธฐ, ์‚ฌ์šฉ์ž์˜ ๊ฐ’์„ ์„œ๋ฒ„์— ๋‚ ๋ ธ์„ ๋•Œ ๋ฆฌํ„ด๊ฐ’์œผ๋กœ

 

โ€˜);alert(โ€˜1

%0aalert(1);/* -> %0a ๊ฐœํ–‰๋ฌธ์ž ์ด์šฉ

 

๋‹ค์šด๋กœ๋“œ ์ทจ์•ฝ์ 

../../target -> ์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์˜ฌ๋ผ๊ฐ

../target%00 -> NULL

.\./target

index.php

inext.p<p

index.p>p

 

728x90
๋ฐ˜์‘ํ˜•

'Security Study > Web' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

๊ตฌ๊ธ€ ํ•ดํ‚น  (0) 2015.11.21
web 2์ผ์ฐจ  (0) 2015.10.23
XSS(ํฌ๋กœ์Šค ์‚ฌ์ดํŠธ ์Šคํฌ๋ฆฝํŠธ)?  (0) 2015.09.03
What Is A Man In The Middle Attack? ์›๋ณธ  (0) 2015.09.03
What Is A Man In The Middle Attack?  (0) 2015.09.03

๋Œ“๊ธ€