๊ธ€ ์ž‘์„ฑ์ž: heogi

apache htaccess ์„ค์ • ๊ด€๋ จ ์ทจ์•ฝ์  ๋ฌธ์ œ์ด๋‹ค.

 

๋ฉ”์ธ ํŽ˜์ด์ง€์—๋Š” ์•„๋ž˜ ์ฒ˜๋Ÿผ ํŒŒ์ผ์„ ์—…๋กœ๋“œ ํ•  ์ˆ˜ ์žˆ๋Š” ๊ธฐ๋Šฅ์ด์žˆ๋‹ค.

 

์†Œ์Šค์ฝ”๋“œ์—์„œ๋Š” php ๊ด€๋ จ ํ™•์žฅ์ž๋“ค์„ ์ œํ•œํ•˜๊ณ ์žˆ๋‹ค.

<?php
$deniedExts = array("php", "php3", "php4", "php5", "pht", "phtml");
.
.
.
 $temp = explode(".", $name);
        $extension = end($temp);
       
        if(in_array($extension, $deniedExts)){
            die($extension . " extension file is not allowed to upload ! ");
            
.
.
.

 

์†Œ์Šค์— ํฌํ•จ๋œ apache ์„ค์ • ํŒŒ์ผ์ธ 000-default.conf ํŒŒ์ผ์„ ์‚ดํŽด๋ณด๋ฉด AllowOverride ์˜ต์…˜์ด All๋กœ ์„ค์ •๋˜์–ด์žˆ๋‹ค.

   <Directory /var/www/html/>
     AllowOverride All
     Require all granted
   </Directory>

AllowOverride ์˜ต์…˜์€ ๋””๋ ‰ํ† ๋ฆฌ์˜ ์„ค์ • ๋‚ด์šฉ์„ ๋ณ„๋„์˜ ์™ธ๋ถ€ํŒŒ์ผ(.htaccess)์—์„œ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋Š”์ง€๋ฅผ ์—ฌ๋ถ€๋ฅผ ๊ฒฐ์ •ํ•˜๋Š” ์˜ต์…˜์ด๋‹ค.

AllowOverride ์˜ต์…˜์ด All๋กœ ์„ค์ •๋˜์–ด์žˆ์–ด, ํŒŒ์ผ์ด ์—…๋กœ๋“œ๋˜๋Š” /upload ๊ฒฝ๋กœ์— .htaccess ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•˜์—ฌ .txt ํ™•์žฅ์ž๊ฐ€ php ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์ธ์‹ํ•˜๊ฒŒ ๋งŒ๋“ค ์ˆ˜ ์žˆ๋‹ค.

 

 

.txt ํ™•์žฅ์ž๋ฅผ php ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์ธ์‹ํ•˜๊ฒŒ ๋งŒ๋“ค์–ด php์˜ system ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ฝ”๋“œ๋ฅผ ๋ณด๋‚ด์–ด ์‹คํ–‰ ๊ถŒํ•œ๋งŒ ์„ค์ •๋œ /flag ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ flag๋ฅผ ํš๋“ํ•œ๋‹ค.

'๐Ÿ›ก๏ธCTF > DreamHack' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

rev-basic-3  (0) 2023.09.19
[BOB CTF 8th] - FileStroage  (0) 2022.09.13
[BOB CTF 8th] - Summer Fan  (0) 2022.09.13
read_flag  (0) 2022.01.23
crawling  (0) 2022.01.23