Notice
Recent Posts
Recent Comments
Link
«   2025/05   »
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Archives
Today
Total
관리 메뉴

9시 24분

IXPLOIT 웹해킹 스터디 9주차 (2) Wargame 본문

스터디/웹해킹

IXPLOIT 웹해킹 스터디 9주차 (2) Wargame

leeeee.yeon 2021. 2. 12. 15:08

1 Command injection

www.root-me.org/en/Challenges/Web-Server/PHP-Command-injection

 

Challenges/Web - Server : PHP - Command injection [Root Me : Hacking and Information Security learning platform]

 

www.root-me.org

 

Find a vulnerabilty in this service and exploit it. The flag is on the index.php file.

Meta 문자를 이용하여 리눅스 명령어를 사용해보자.


2 File Vulnerability (1)

www.root-me.org/en/Challenges/Web-Server/File-upload-Double-extensions

 

Challenges/Web - Server : File upload - Double extensions [Root Me : Hacking and Information Security learning platform]

 

www.root-me.org

Your goal is to hack this photo galery by uploading PHP code. Retrieve the validation password in the file .passwd at the root of the application.


3 File Vulnerability (2)

www.root-me.org/en/Challenges/Web-Server/File-upload-MIME-type

 

Challenges/Web - Server : File upload - MIME type [Root Me : Hacking and Information Security learning platform]

 

www.root-me.org