๐Ÿ‘ฉ๐Ÿป‍๐Ÿ’ป ๊ฐ“์ƒ ์ง์žฅ์ธ ๋‚จ๋ฐ”์˜ค
article thumbnail
Published 2023. 2. 16. 12:32
[Web] csrf-2 Wargame/Dreamhack
@app.route("/change_password")
def change_password():
pw = request.args.get("pw", "")
session_id = request.cookies.get('sessionid', None)
try:
username = session_storage[session_id]
except KeyError:
return render_template('index.html', text='please login')

ํ•„ํ„ฐ๊ฐ€ ๊ฑธ๋ ค์žˆ๋‹ค. XSS๋Š” ํ†ตํ•˜์ง€ ์•Š๋Š”๋‹ค -> vuln ํŽ˜์ด์ง€๋ฅผ ๋ณด๋ฉด script๋Š” * ๋กœ ํ•„ํ„ฐ๋งํ•œ๋‹ค๋Š” ๊ฑธ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

 

flag ํŽ˜์ด์ง€์—์„œ change_password ์ฟผ๋ฆฌ ์š”์ฒญ์ด ๊ฐ€๋Šฅํ•˜๊ธฐ ๋•Œ๋ฌธ์— pw ๋ฅผ ๋ณ€๊ฒฝํ•˜๋ฉด admin์œผ๋กœ ์ ‘์†ํ•  ์ˆ˜ ์žˆ์ง€ ์•Š์„๊นŒ?

<img src="/change_password?pw=pw">

param๊ฐ’์œผ๋กœ ์œ„์˜ payload๋ฅผ ์ „์†กํ•˜๊ณ  admin ๊ณ„์ •์œผ๋กœ ๋กœ๊ทธ์ธํ•˜๋‹ˆ ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ๋‹ค.

'Wargame > Dreamhack' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Web] Mango  (0) 2023.02.24
[Web] Proxy-1  (0) 2023.02.17
[Web] image-storage  (0) 2023.02.16
[Web] pathtraversal  (0) 2023.02.16
[Web] Mango  (0) 2023.02.16
profile

๐Ÿ‘ฉ๐Ÿป‍๐Ÿ’ป ๊ฐ“์ƒ ์ง์žฅ์ธ ๋‚จ๋ฐ”์˜ค

@๋‚จ๋ฐ”์˜ค