<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0">
  <title type="html">Coryas :: 안녕,</title>
  <id>http://coryas.com/tc/</id>
  <link rel="alternate" type="text/html" hreflang="ko" href="http://coryas.com/tc/" />
  <subtitle type="html"></subtitle>
  <updated>2008-08-26T22:36:27+09:00</updated>
  <generator>Textcube 1.7.4 : Risoluto</generator>
  <entry>
    <title type="html">Hack This Site - Basic missions 레벨 1~10 풀이</title>
    <link rel="alternate" type="text/html" href="http://coryas.com/tc/entry/Hack-This-Site-Basic-missions-%EB%A0%88%EB%B2%A8-110-%ED%92%80%EC%9D%B4" />
    <link rel="replies" type="application/atom+xml" href="http://coryas.com/tc/atom/response/4" thr:count="3"/>
    <category term="War Game" />
    <category term="Hacking" />
    <category term="HackThisSite" />
    <category term="WarGame" />
    <author>
      <name>(Coryas)</name>
    </author>
    <id>http://coryas.com/tc/entry/Hack-This-Site-Basic-missions-%EB%A0%88%EB%B2%A8-110-%ED%92%80%EC%9D%B4</id>
    <updated>2008-02-07T16:50:06+09:00</updated>
    <published>2008-01-19T00:23:54+09:00</published>
    <summary type="html">&lt;STRONG&gt;&lt;FONT size=6&gt;Level 1.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/1/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/1.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;Basic test of your skills to see if you can do any of these missions. Requirements: HTML &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/1/&quot; target=_blank&gt;Basic 1&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;Level 1(the idiot test)&lt;/STRONG&gt; &lt;br /&gt;&lt;br /&gt;This level is what we call &quot;The Idiot Test&quot;, if you can&#039;t complete it, don&#039;t give up on learning all you can, but, don&#039;t go begging to someone else for the answer, thats one way to get you hated/made fun of. Enter the password and you can continue. &lt;/BLOCKQUOTE&gt;첫 번째 문제답게 HTML만 안다면 쉽게 풀수 있습니다. HTML 코드를 사용할 수 있는지 알아보는 테스트 같네요. 주석을 유심히보세요.&lt;br /&gt;
&lt;p id=&quot;more4_0&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_0&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_0&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;img src=&quot;http://coryas.com/tc/attach/1/8772123646.jpg&quot; alt=&quot;사용자 삽입 이미지&quot; height=&quot;200&quot; width=&quot;450&quot; /&gt;&lt;/div&gt;&lt;br /&gt;그림과 같이 HTML 소스에 보면 주석으로&lt;br /&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;&amp;lt;!-- the first few levels are extremely easy: password is &lt;FONT color=#0000ff&gt;&lt;STRONG&gt;d9bc7a33&lt;/STRONG&gt;&lt;/FONT&gt; --&amp;gt;&lt;/BLOCKQUOTE&gt;친절히 알려줍니다. &lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 2.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/2/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/2.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;A slightly more difficult challenge, involving an incomplete password script. Requirements: Common sense. &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/2/&quot; target=_blank&gt;Basic 2&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 2&lt;/STRONG&gt;&lt;br /&gt;Network Security Sam set up a password protection script. He made it load the real password from an unencrypted text file and compare it to the password the user enters. However, he neglected to upload the password file...&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;패스워드를 무시하는 방법을 생각해 보세요. common sense 라는데 전 생각보다 힘들게 풀었어요.&lt;br /&gt;
&lt;p id=&quot;more4_1&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_1&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_1&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;힌트를 보고 패스워드를 무시하는 방법을 생각하다가 엔터를 쳤더니 그냥 넘어가네요. 아직은 초기 단계라... 금방 금방 넘어갑니다.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 3.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/3/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/3.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;Some intuition is needed to find the location of the hidden password file. Requirements: Basic HTML knowledge &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/3/&quot; target=_blank&gt;Basic 3&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 3&lt;/STRONG&gt; &lt;br /&gt;This time Network Security Sam remembered to upload the password file, but there were deeper problems than that.&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;이것도 HTML 코드를 사용할 수 있는지 확인하는 테스트입니다. 힌트는 form 에 있습니다.&lt;br /&gt;
&lt;p id=&quot;more4_2&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_2&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_2&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;일단 소스를 쭉욱 훓어보니&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;img src=&quot;http://coryas.com/tc/attach/1/2641337003.jpg&quot; alt=&quot;사용자 삽입 이미지&quot; height=&quot;200&quot; width=&quot;450&quot; /&gt;&lt;/div&gt;&lt;br /&gt;위 그림과 같이 히든으로 넘겨주는 값이 있습니다.&lt;br /&gt;
&lt;BLOCKQUOTE&gt;&amp;lt;input type=&quot;hidden&quot; name=&quot;file&quot; value=&quot;password.php&quot;&amp;gt;&lt;/BLOCKQUOTE&gt;그래서 &lt;A href=&quot;http://www.hackthissite.org/missions/basic/3/password.php&quot; target=_blank&gt;http://www.hackthissite.org/missions/basic/3/password.php&lt;/A&gt; 이라는 주소로 이동해봤더니 아래와 같은 패스워드가 뜹니다.&lt;br /&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;eafbe894&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 4.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/4/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/4.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;An email script has been set up, which sends the password to the administrator. Requirements: HTML knowledge, an email address &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/4/&quot; target=_blank&gt;Basic 4&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 4&lt;/STRONG&gt;&lt;br /&gt;This time Sam hardcoded the password into the script. However, the password is long and complex, and Sam is often forgetful. So he wrote a script that would email his password to him automatically in case he forgot. Here is the script:&lt;br /&gt;&lt;br /&gt;[&#039;Send password to Sam&#039; Submit Button] &lt;br /&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;&lt;br /&gt;이메일 주소가 필요하다는데 문제가&amp;nbsp; 수정되서 그런지 이메일 주소는 필요없습니다. 이것 또한 html 을 필요하는 문제입니다.&lt;br /&gt;&lt;br /&gt;데이터 전송 형식에는 GET, POST 등이 있고 제시한 2가지가 가장 많이 쓰입니다. &#039;Send password to Sam&#039; 버튼을 눌렀을때 어떤 형식으로 가는지 잘 파악 해보세요.&lt;br /&gt;
&lt;p id=&quot;more4_3&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_3&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_3&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;&#039;Send password to Sam&#039; 이라는 버튼을 누르면 쌤에게 패스워드가 날라가죠. 소스를 보면&lt;br /&gt;
&lt;BLOCKQUOTE&gt;&amp;lt;input type=&quot;hidden&quot; name=&quot;to&quot; value=&quot;webmaster@hulla-balloo.com&quot;&amp;gt;&lt;/BLOCKQUOTE&gt;라는 코드가 친절히 있네요. 쌤의 이메일 주소가 webmaster@hulla-balloo.com 인지 알았고 이메일부분에 내 메일로 수정해서 아래와 같이 입력해봤습니다.&lt;br /&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;http://www.hackthissite.org/missions/basic/4/level4.php?to=coryas@gmail.com&lt;br /&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;하지만 변화가 없군요. 서버에서 POST 형식으로 온 값만 체크하기 때문에 아래와 같은 HTML파일을 만들어서 POST 형식으로 전송해봤습니다. (단, HackThisSite에 로그인하여 쿠키를 받은 상태야 가능합니다.)&lt;br /&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;filename: &lt;div class=&quot;imageblock left&quot; style=&quot;float: left; margin-right: 10px;&quot;&gt;&lt;a class=&quot;extensionIcon&quot; href=&quot;http://coryas.com/tc/attachment/4538767669.html&quot;&gt;&lt;img src=&quot;http://coryas.com/tc/image/extension/html.gif&quot; alt=&quot;&quot; /&gt; hackthissite-basic4.html&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;center&amp;gt;&amp;lt;b&amp;gt;Level 4&amp;lt;/b&amp;gt;&amp;lt;/center&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;This time Sam hardcoded the password into the script. However, the password is long and complex, and Sam is often forgetful. So he wrote a script that would email his password to him automatically in case he forgot. Here is the script:&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;center&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;form action=&quot;http://www.hackthissite.org/missions/basic/4/level4.php&quot; method=&quot;post&quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type=&quot;hidden&quot; name=&quot;to&quot; value=&quot;coryas@gmail.com&quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type=&quot;submit&quot; value=&quot;Send password to Sam&quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;/form&amp;gt;&lt;br /&gt;&amp;lt;/center&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;center&amp;gt;&amp;lt;b&amp;gt;Password:&amp;lt;/b&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;form action=&quot;http://www.hackthissite.org/missions/basic/4/index.php&quot; method=&quot;post&quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type=&quot;password&quot; name=&quot;password&quot;&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;input type=&quot;submit&quot; value=&quot;submit&quot;&amp;gt;&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;lt;/form&amp;gt;&lt;br /&gt;&amp;lt;/center&amp;gt;&lt;/BLOCKQUOTE&gt;으흠.. 잘 되는군요.. ^^ (HackThisSite의 소스를 그대로 가저와서 약간의 수정만 한 소스입니다). 자 이제 버튼을 누르면 패스워드가 출력되는군요.&lt;br /&gt;
&lt;DIV&gt;&lt;STRONG&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;password: 6f59ecc5&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 5.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/5/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/5.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;Similar to the previous challenge, but with some extra security measures in place. Requirements: HTML knowledge, JS or FF, an email address. &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/5/&quot; target=_blank&gt;Basic 5&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 5&lt;/STRONG&gt;&lt;br /&gt;Sam has gotten wise to all the people who wrote their own forms to get the password. Rather then actually learn the password, he decided to make his email program a little more secure.&lt;br /&gt;&lt;br /&gt;[&#039;Send password to Sam&#039; Submit Button] &lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;Level4와 동일한 문제지만 한가지 추가된 보안 기능이 있습니다. 똑같은 데이터 전송형식을 받지만 &#039;Referer&#039; 체크를 합니다. &#039;Referer&#039;를 속일수 있는 방법을 생각해보세요.&lt;STRONG&gt;&lt;br /&gt;&lt;/STRONG&gt;
&lt;p id=&quot;more4_4&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_4&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_4&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;Paros 같은 프로그램을 이용하여 리퍼러만 추가 시켜 넘겨주면 됩니다.&lt;br /&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;Password: 760125e9&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 6.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/6/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/6.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;An encryption system has been set up, which uses an unknown algorithm to change the text given. Requirements: Persistence, some general cryptography knowledge. &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/6/&quot; target=_blank&gt;Basic 6&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 6&lt;/STRONG&gt;&lt;br /&gt;Network Security Sam has encrypted his password. The encryption system is publically available and can be accessed with this form:&lt;br /&gt;&lt;br /&gt;Please enter a string to have it encrypted.&lt;br /&gt;&lt;br /&gt;[Input Box]&lt;br /&gt;[&#039;encrypt&#039; Submit Button]&lt;br /&gt;&lt;br /&gt;You have recovered his encrypted password. It is:&lt;br /&gt;&lt;br /&gt;&lt;FONT color=#ff0000&gt;&lt;STRONG&gt;0:;&amp;lt;7=:@&lt;/STRONG&gt;&lt;br /&gt;&lt;/FONT&gt;&lt;br /&gt;Decrypt the password and enter it below to advance to the next level.&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;일단 암호화 되는 패턴을 파악하는게 중요합니다. 간단한 값을 입력하여 패턴을 파악해봐요~&lt;br /&gt;
&lt;p id=&quot;more4_5&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_5&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_5&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;값을 입력하면 암호화 된 값만 알려준니다. 일단 간단한 패턴일경우 쉽게 알아내기 위해 입력란에 &#039;AAAAAAAA&#039; 를 입력하면 아래와 같은 암호화 된 값이 나옵니다.&lt;br /&gt;
&lt;CENTER&gt;
&lt;BLOCKQUOTE&gt;Your encrypted string is: &#039;&lt;FONT color=#ff0000&gt;ABCDEFGH&lt;/FONT&gt;&#039;&lt;/BLOCKQUOTE&gt;&lt;/CENTER&gt;
&lt;P&gt;단번에 패턴을 파악할 수 있겠죠. 아래는 python으로 간단히 코드를 짜보았습니다.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;filename:&lt;div class=&quot;imageblock left&quot; style=&quot;float: left; margin-right: 10px;&quot;&gt;&lt;a class=&quot;extensionIcon&quot; href=&quot;http://coryas.com/tc/attachment/5604100622.py&quot;&gt;&lt;img src=&quot;http://coryas.com/tc/image/extension/unknown.gif&quot; alt=&quot;&quot; /&gt; level6-1.py&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/bin/python&lt;br /&gt;# -*- coding: cp949 -*-&lt;br /&gt;&lt;br /&gt;input=&quot;0:;&amp;lt;7=:@&quot;&lt;br /&gt;result=str()&lt;br /&gt;for i in range(len(input)):&lt;br /&gt;&amp;nbsp;result+=chr(ord(input[i])-i)&lt;br /&gt;print result&lt;br /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;디코딩한 결과값은 아래와 같은 값이 나왔네요.&lt;br /&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;09993849&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/STRONG&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;/div&gt;
&lt;P&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 7.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/7/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/7.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;The password is hidden in an unknown file, and Sam has set up a script to display a calendar. Requirements: Basic UNIX command knowledge. &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/7/&quot; target=_blank&gt;Basic 7&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 7&lt;/STRONG&gt;&lt;br /&gt;This time Network Security sam has saved the unencrypted level7 password in an obscurely named file saved in this very directory.&lt;br /&gt;&lt;br /&gt;In other unrelated news, Sam has set up a script that returns the output from the UNIX cal command. Here is the script:&lt;br /&gt;&lt;br /&gt;Enter the year you wish to view and hit &#039;view&#039;.&lt;br /&gt;&lt;br /&gt;[Input Box]&lt;br /&gt;[&#039;view&#039; Submit Button] &lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;입력란에 숫자(년도)를 입력하면 해당 년도의 달력이 출력되고 아무값도 입력하지 않으면 이번달 달력만 출력됩니다. 그리고 숫자 이외의 값을 입력하면 아무것도 출력되지 않구요.&lt;br /&gt;&lt;br /&gt;Perl에서 유닉스 명령어를 사용 할 수 있는 방법을 생각해보세요.&lt;br /&gt;
&lt;p id=&quot;more4_6&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_6&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_6&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;이동된 주소를 보면 알겠지만 perl로 제작된 스크립트로 이동합니다. &lt;br /&gt;힌트를 적절히 활용하여 아래와 같은 커맨드를 입력해보았습니다.&lt;br /&gt;&lt;br /&gt;
&lt;DIV&gt;
&lt;BLOCKQUOTE&gt;&lt;FONT color=#ff0000&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;FONT color=#ff0000&gt;;ls&lt;/FONT&gt;&lt;/DIV&gt;&lt;/FONT&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;perl에서 &#039;;&#039;(세미콜론)은 다음 문장을 입력하는 시그널입니다. 그리고 ls 명령을 친 결과를 보여주네요. 위 코드를 입력하면 아래와 같은 결과값을 얻을수 있습니다.&lt;br /&gt;
&lt;BLOCKQUOTE&gt;URL: http://www.hackthissite.org/missions/basic/7/cal.pl&lt;PRE&gt;&lt;FONT face=돋움&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; January 2008&lt;br /&gt;Mon Tue Wed Thu Fri Sat Sun&lt;br /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; 2 &amp;nbsp; 3 &amp;nbsp; 4 &amp;nbsp; 5 &amp;nbsp; 6&lt;br /&gt;&amp;nbsp; 7 &amp;nbsp; 8 &amp;nbsp; 9&amp;nbsp; 10&amp;nbsp; 11&amp;nbsp; 12&amp;nbsp; 13&lt;br /&gt;&amp;nbsp;14&amp;nbsp; 15&amp;nbsp; 16&amp;nbsp; 17&amp;nbsp; 18&amp;nbsp; 19&amp;nbsp; 20&lt;br /&gt;&amp;nbsp;21&amp;nbsp; 22&amp;nbsp; 23&amp;nbsp; 24&amp;nbsp; 25&amp;nbsp; 26&amp;nbsp; 27&lt;br /&gt;&amp;nbsp;28&amp;nbsp; 29&amp;nbsp; 30&amp;nbsp; 31&lt;/FONT&gt;&lt;FONT face=돋움&gt;&lt;br /&gt;.&lt;br /&gt;..&lt;br /&gt;.svn&lt;br /&gt;level7.php&lt;br /&gt;cal.pl&lt;br /&gt;.htaccess&lt;br /&gt;&lt;FONT color=#ff0000&gt;k1kh31b1n55h.php&lt;/FONT&gt;&lt;br /&gt;index.php&lt;/FONT&gt;&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;의심가는 파일을 패스워드 파일이 보이군요. &lt;A href=&quot;http://www.hackthissite.org/missions/basic/7/k1kh31b1n55h.php&quot; target=_blank&gt;http://www.hackthissite.org/missions/basic/7/k1kh31b1n55h.php&lt;/A&gt;&amp;nbsp;링크를 타고 가보았더니 역시 패스워드를 뱉어내네요.&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;7b4a2219&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/BLOCKQUOTE&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 8.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/8/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/8.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;The password is yet again hidden in an unknown file. Sam&#039;s daughter has begun learning PHP, and has a small script to demonstrate her knowledge. Requirements: Knowledge of SSI (dynamic html executed by the server, rather than the browser) &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/8/&quot; target=_blank&gt;Basic 8&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 8&lt;/STRONG&gt;&lt;br /&gt;Sam remains confident that an obscured password file is still the best idea, but he screwed up with the calendar program. Sam has saved the unencrypted password file in /var/www/hackthissite.org/html/missions/basic/8/&lt;br /&gt;&lt;br /&gt;However, Sam&#039;s young daughter Stephanie has just learned to program in PHP. She&#039;s talented for her age, but she knows nothing about security. She recently learned about saving files, and she wrote an script to demonstrate her ability.&lt;br /&gt;&lt;br /&gt;Enter your name: &lt;br /&gt;&lt;br /&gt;[Input Box]&lt;br /&gt;[&#039;submit&#039; Submit Button]&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;힌트에 나와 있듯이 약간의 &lt;A href=&quot;http://en.wikipedia.org/wiki/Server_side_include&quot; target=_blank&gt;SSI(S&lt;FONT size=2&gt;erver Side Include)&lt;/FONT&gt;&lt;/A&gt;에 대한 지식이 필요합니다. HTML주석을 사용하여 include, exec, echo 등을 사용할 수 있구요. 자세한 내용은 위 링크로 따라가 확인하길 바랍니다.&lt;br /&gt;
&lt;p id=&quot;more4_7&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_7&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_7&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;
&lt;BLOCKQUOTE style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;FONT color=#ff0000&gt;&amp;lt;!--#exec cmd=&quot;ls ..&quot;--&amp;gt;&lt;/FONT&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;위와 같이 입력을 하면 아래와 같은 결과 값을 얻을 수 있습니다. &lt;br /&gt;
&lt;BLOCKQUOTE&gt;Hi, &lt;FONT color=#ff0000&gt;au12ha39vc.php&lt;/FONT&gt; index.php level8.php tmp!&lt;br /&gt;Your name contains 39 characters.&lt;/BLOCKQUOTE&gt;&lt;br /&gt;패스워드 파일로 추측되는 파일을 찾았습니다.&lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/8/au12ha39vc.php&quot;&gt;http://www.hackthissite.org/missions/basic/8/au12ha39vc.php&lt;/A&gt;&lt;br /&gt;링크를 타고 가보니 패스워드가 출력되는군요.&lt;br /&gt;&lt;br /&gt;
&lt;BLOCKQUOTE style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;1847871a&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/BLOCKQUOTE&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 9.&lt;/FONT&gt;&lt;/STRONG&gt; 
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/9/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/9.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;The password is again hidden in an unknown file. However, the script that was previously used to find it has some limitations. Requirements: Knowledge of SSI, unix directory structure. &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/9/&quot; target=_blank&gt;Basic 9&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 9&lt;/STRONG&gt;&lt;br /&gt;Network Security Sam is going down with the ship - he&#039;s determined to keep obscuring the password file, no matter how many times people manage to recover it. This time the file is saved in /var/www/hackthissite.org/html/missions/basic/9/.&lt;br /&gt;&lt;br /&gt;In the last level, however, in my attempt to limit people to using server side includes to display the directory listing to level 8 only, I have mistakenly screwed up somewhere.. there is a way to get the obscured level 9 password. See if you can figure out how...&lt;br /&gt;&lt;br /&gt;This level seems a lot trickier then it actually is, and it helps to have an understanding of how the script validates the user&#039;s input. The script finds the first occurance of &#039;&amp;lt;--&#039;, and looks to see what follows directly after it. If it matches &quot;#exec cmd=&quot;ls&quot;--&amp;gt;&quot; or &quot;#exec cmd=&quot;ls /home/xec96/public_html/missions/basic/8/&quot;--&amp;gt;&quot; it accepts it. If it does not match any of the situations above, then it kicks the user out.&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;Level 8과 동일한 유형의 문제입니다. 똑같은 방법을 사용하여 /var/www/hackthissite.org/html/missions/basic/9/ 디렉토리에 접근 하면 됩니다.&lt;br /&gt;
&lt;p id=&quot;more4_8&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_8&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_8&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;&lt;br /&gt;여기서 중요한점은 상대경로를 이용하고 /var/www/hackthissite.org/html/missions/basic/ 에 접근 권한이 없습니다.&lt;br /&gt;이 점을 유의하여 아래와 같이 입력하면 끝!&lt;br /&gt;&lt;br /&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;
&lt;BLOCKQUOTE&gt;&lt;FONT color=#ff0000&gt;&amp;lt;!--#exec cmd=&quot;ls ../../9&quot;--&amp;gt;&lt;/FONT&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;
&lt;BLOCKQUOTE&gt;&lt;PRE&gt;Hi, index.php &lt;FONT color=#ff0000&gt;p91e283zc3.php&lt;/FONT&gt;!
Your name contains 24 characters.&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;
&lt;BLOCKQUOTE&gt;&lt;STRONG&gt;&lt;FONT color=#0000ff&gt;cccbd6ad&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/BLOCKQUOTE&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;STRONG&gt;&lt;FONT size=6&gt;Level 10.&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/10/&quot; target=_blank&gt;&lt;IMG src=&quot;http://www.hackthissite.org/missions/basic/imgs/10.gif&quot;&gt;&lt;/A&gt;&lt;br /&gt;This time, the password is encoded straight into the script. Whether the user is allowed in or not is determined by cookies; small pieces of information stored by the browser about the webpage that is being visited. Requirements: Javascript knowledge. &lt;br /&gt;&lt;A href=&quot;http://www.hackthissite.org/missions/basic/10/&quot; target=_blank&gt;Basic 10&lt;/A&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;STRONG&gt;Level 10&lt;/STRONG&gt;&lt;br /&gt;Please enter a password to gain access to level 10&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;이제 드디어 Basic 마지막 레벨이군요. 이번 문제는 Cookie 관련 문제입니다. 푸는 방법은 여러가지지만 Javascript 를 이용하는 방법이 가장 간단하겠네요.&lt;br /&gt;
&lt;p id=&quot;more4_9&quot; class=&quot;moreless_fold&quot;&gt;&lt;span style=&quot;cursor: pointer;&quot; onclick=&quot;toggleMoreLess(this, &#039;4_9&#039;,&#039; Click to show spoiler... &#039;,&#039; Click to hide spoiler... &#039;); return false;&quot;&gt; Click to show spoiler... &lt;/span&gt;&lt;/p&gt;&lt;div id=&quot;content4_9&quot; class=&quot;moreless_content&quot; style=&quot;display: none;&quot;&gt;http header를 보면&lt;br /&gt;
&lt;BLOCKQUOTE&gt;GET /missions/basic/10/ HTTP/1.1&lt;br /&gt;Accept: */*&lt;br /&gt;Referer: http://www.hackthissite.org/missions/basic/&lt;br /&gt;Accept-Language: ko&lt;br /&gt;Accept-Encoding: gzip, deflate&lt;br /&gt;User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)&lt;br /&gt;Host: www.hackthissite.org&lt;br /&gt;Connection: Keep-Alive&lt;br /&gt;&lt;FONT color=#ff0000&gt;Cookie: level10_authorized=no;&lt;/FONT&gt;&lt;br /&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;level10_authorized 라는 쿠키값이 no로 설정되어 있다. 이 부분을 yes로 수정한다면 Basic missions는 이제 끝납니다... 간단히 브라우저에서 자바스크립트를 이용하여 쿠키값을 수정하기 위해 주소장에 다음과 같이 입력하면 됩니다.&lt;br /&gt;&lt;br /&gt;&lt;FONT color=#ff0000&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;FONT color=#ff0000&gt;
&lt;BLOCKQUOTE&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;FONT color=#ff0000&gt;javascript:document.cookie=&quot;level10_authorized=yes&quot;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/FONT&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;이로써 HackThisSite ( &lt;A href=&quot;http://www.hackthissite.org/&quot; target=_blank&gt;http://www.hackthissite.org&lt;/A&gt; ) - Basic Missions 풀이를 모두 풀어보았습니다.. 수정 및 질문은 coryas(at)gmail.com 메일로 받습니다. (모두 읽는다고 수고했어요~)&lt;br /&gt;&lt;br /&gt;</summary>
  </entry>
  <entry>
    <title type="html">Binary to Text (ASCII) Conversion</title>
    <link rel="alternate" type="text/html" href="http://coryas.com/tc/entry/Binary-to-Text-ASCII-Conversion" />
    <link rel="replies" type="application/atom+xml" href="http://coryas.com/tc/atom/response/3" thr:count="0"/>
    <category term="Crypto" />
    <category term="Binary to Text" />
    <category term="Binary2Text" />
    <category term="Convert" />
    <category term="Crypt" />
    <author>
      <name>(Coryas)</name>
    </author>
    <id>http://coryas.com/tc/entry/Binary-to-Text-ASCII-Conversion</id>
    <updated>2008-01-19T00:25:33+09:00</updated>
    <published>2008-01-17T15:08:48+09:00</published>
    <summary type="html">&lt;P&gt;바이너리 2 텍스트 변환기다.&lt;/P&gt;
&lt;P&gt;010000100110010100100000011100110111010101110010011001&lt;br /&gt;010010000001110100011011110010000001100100011100100110&lt;br /&gt;100101101110011010110010000001111001011011110111010101&lt;br /&gt;110010001000000100111101110110011000010110110001110100&lt;br /&gt;01101001011011100110010100101110&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;라는 바이너리를 넣으면&lt;/P&gt;
&lt;P&gt;Be sure to drink your Ovaltine.&lt;/P&gt;
&lt;P&gt;라는 텍스트가 나온다..&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;아래 링크에 가서 변환해보자!&lt;/P&gt;
&lt;P&gt;Binary to Text (ASCII) Conversion&lt;br /&gt;&lt;A href=&quot;http://www.roubaixinteractive.com/PlayGround/Binary_Conversion/Binary_to_Text.asp&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://www.roubaixinteractive.com/PlayGround/Binary_Conversion/Binary_to_Text.asp&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;</summary>
  </entry>
  <entry>
    <title type="html">HTTP Header for PHP</title>
    <link rel="alternate" type="text/html" href="http://coryas.com/tc/entry/HTTP-Header" />
    <link rel="replies" type="application/atom+xml" href="http://coryas.com/tc/atom/response/2" thr:count="0"/>
    <category term="Trash" />
    <category term="HTTP Header" />
    <category term="PHP" />
    <author>
      <name>(Coryas)</name>
    </author>
    <id>http://coryas.com/tc/entry/HTTP-Header</id>
    <updated>2008-01-19T00:26:05+09:00</updated>
    <published>2008-01-17T15:06:02+09:00</published>
    <summary type="html">HTTP Header 보기&lt;br /&gt;&lt;br /&gt;&lt;A href=&quot;http://validator.w3.org/p3p/20020128/header.pl?mode=header&amp;amp;uri=http://www.google.co.kr&quot; target=_blank&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://validator.w3.org/p3p/20020128/header.pl?mode=header&amp;amp;uri=http://www.google.co.kr&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;HTTP Header 보내기&lt;br /&gt;&lt;br /&gt;&lt;A href=&quot;http://web-sniffer.net/&quot; target=_blank&gt;&lt;FONT color=#0000ff&gt;&lt;U&gt;http://web-sniffer.net/&lt;/U&gt;&lt;/FONT&gt;&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;A href=&quot;http://webtools.live2support.com/header.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://webtools.live2support.com/header.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;간단히 만들어본 HTTP Header 날리기 php 소스&lt;br /&gt;&lt;br /&gt;
&lt;BLOCKQUOTE&gt;// send_httpheader.php&lt;br /&gt;// powered by coryas [http://coryas.tistory.com]&lt;br /&gt;// 최소한의 기능 구현을 위해 만든 간단한 php 소스 입니다.&lt;br /&gt;&lt;br /&gt;&amp;lt;form action=&amp;lt;?echo $_SERVER[&quot;PHP_SELF&quot;];?&amp;gt; method=&quot;get&quot;&amp;gt;&lt;br /&gt;&amp;lt;strong&amp;gt;host ip : &amp;lt;/strong&amp;gt; &amp;lt;input type=text name=hostip value=&amp;lt;?echo $hostip?&amp;gt;&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;strong&amp;gt;host port : &amp;lt;/strong&amp;gt; &amp;lt;input type=text name=hostport value=&amp;lt;?echo $hostport?&amp;gt;&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;strong&amp;gt;http header : &amp;lt;/strong&amp;gt; &amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;textarea name=&quot;httpheader&quot; cols=&quot;97&quot; rows=&quot;12&quot; style=&quot;font-size:11px;&quot;&amp;gt;&amp;lt;?echo $httpheader?&amp;gt;&amp;lt;/textarea&amp;gt;&lt;br /&gt;&amp;lt;input type=&quot;submit&quot; name=&quot;submit&quot; value=&quot;Submit&quot; /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;/form&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;a href=&#039;http://coryas.tistory.com&#039; target=&#039;_blank&#039;&amp;gt;powered by coryas&amp;lt;/a&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;&amp;lt;?&lt;br /&gt;if (!$httpheader==NULL)&lt;br /&gt;{&lt;br /&gt;&amp;nbsp;$fp = fsockopen($hostip,$hostport);&lt;br /&gt;&amp;nbsp;fputs($fp, $httpheader);&lt;br /&gt;&amp;nbsp;while(!feof($fp)) {&lt;br /&gt;&amp;nbsp; $result .= fgets($fp, 128);&lt;br /&gt;&amp;nbsp;}&lt;br /&gt;&amp;nbsp; echo $result;&lt;br /&gt;&amp;nbsp;fclose($fp);&lt;br /&gt;}&lt;br /&gt;?&amp;gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;</summary>
  </entry>
  <entry>
    <title type="html">제6회 HUST 해킹 페스티발 레벨 1~3 풀이 (6th H.U.S.T Hacking Festival Management)</title>
    <link rel="alternate" type="text/html" href="http://coryas.com/tc/entry/%EC%A0%9C6%ED%9A%8C-HUST-%ED%95%B4%ED%82%B9-%ED%8E%98%EC%8A%A4%ED%8B%B0%EB%B0%9C-%EB%A0%88%EB%B2%A8-13-%ED%92%80%EC%9D%B4-6th-HUST-Hacking-Festival-Management" />
    <link rel="replies" type="application/atom+xml" href="http://coryas.com/tc/atom/response/1" thr:count="0"/>
    <category term="War Game" />
    <category term="H.U.S.T Hacking Festival" />
    <category term="Hacking" />
    <category term="WarGame" />
    <author>
      <name>(Coryas)</name>
    </author>
    <id>http://coryas.com/tc/entry/%EC%A0%9C6%ED%9A%8C-HUST-%ED%95%B4%ED%82%B9-%ED%8E%98%EC%8A%A4%ED%8B%B0%EB%B0%9C-%EB%A0%88%EB%B2%A8-13-%ED%92%80%EC%9D%B4-6th-HUST-Hacking-Festival-Management</id>
    <updated>2008-01-19T00:26:31+09:00</updated>
    <published>2008-01-17T15:04:40+09:00</published>
    <summary type="html">&lt;DIV align=left&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;오늘(2007년 5월 17일) 오후 6시까지 한다...&lt;/P&gt;
&lt;P&gt;아래 링크를 이용하면 된다...&lt;/P&gt;
&lt;P&gt;2007 H.U.S.T HackFestival&lt;br /&gt;&lt;A href=&quot;http://hackfestival.org/&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://hackfestival.org/&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;&lt;br /&gt;
&lt;P&gt;&lt;br /&gt;더 풀고 싶었지만...&lt;/P&gt;
&lt;P&gt;사정상 레벨 1~3 까지만 풀었다..&lt;/P&gt;
&lt;P&gt;나의 풀이다..&lt;/P&gt;
&lt;P&gt;level1&lt;br /&gt;&lt;A href=&quot;http://220.95.158.11/~dhclub20/index.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~dhclub20/index.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;hint&lt;/P&gt;
&lt;P&gt;1. 보물은 HUST에 있다.&lt;br /&gt;2. 플라 파일&lt;br /&gt;3. 디컴파일러&lt;br /&gt;4. 다른 보물은 작다.&lt;br /&gt;5. 보물들은 정수다.&lt;br /&gt;6. 두 보물을 조합하여 관리자에게 가라.&lt;br /&gt;7. 패스워드는 관리자에게 있다.&lt;br /&gt;8. 관리자는 관리자실에서 기다리고 있다.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;br /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://220.95.158.11/~dhclub20/board/list.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~dhclub20/board/list.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;까지 접속하면 게시판이 뜬다.&lt;/P&gt;
&lt;P&gt;게시판 위에 보면&lt;br /&gt;&lt;/P&gt;
&lt;P&gt;hust에 있는 플래쉬파일&lt;br /&gt;&lt;OBJECT codeBase=http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=7,0,0,0 height=&quot;70&quot; width=&quot;250&quot; classid=clsid:d27cdb6e-ae6d-11cf-96b8-444553540000&gt;&lt;PARAM NAME=&quot;_cx&quot; VALUE=&quot;6615&quot;&gt;&lt;PARAM NAME=&quot;_cy&quot; VALUE=&quot;1852&quot;&gt;&lt;PARAM NAME=&quot;FlashVars&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;Movie&quot; VALUE=&quot;http://xc8oa.com/attachment/ck12.swf&quot;&gt;&lt;PARAM NAME=&quot;Src&quot; VALUE=&quot;http://xc8oa.com/attachment/ck12.swf&quot;&gt;&lt;PARAM NAME=&quot;WMode&quot; VALUE=&quot;Transparent&quot;&gt;&lt;PARAM NAME=&quot;Play&quot; VALUE=&quot;-1&quot;&gt;&lt;PARAM NAME=&quot;Loop&quot; VALUE=&quot;-1&quot;&gt;&lt;PARAM NAME=&quot;Quality&quot; VALUE=&quot;High&quot;&gt;&lt;PARAM NAME=&quot;SAlign&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;Menu&quot; VALUE=&quot;-1&quot;&gt;&lt;PARAM NAME=&quot;Base&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;AllowScriptAccess&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;Scale&quot; VALUE=&quot;ShowAll&quot;&gt;&lt;PARAM NAME=&quot;DeviceFont&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;EmbedMovie&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;BGColor&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;SWRemote&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;MovieData&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;SeamlessTabbing&quot; VALUE=&quot;1&quot;&gt;&lt;PARAM NAME=&quot;Profile&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;ProfileAddress&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;ProfilePort&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;AllowNetworking&quot; VALUE=&quot;all&quot;&gt;&lt;PARAM NAME=&quot;AllowFullScreen&quot; VALUE=&quot;false&quot;&gt;&lt;!--[if !IE]&gt; &lt;--&gt;&lt;object type=&quot;application/x-shockwave-flash&quot; wmode=&quot;transparent&quot; data=&quot;http://xc8oa.com/attachment/ck12.swf&quot; width=&quot;250&quot; height=&quot;70&quot;&gt;&lt;p&gt;&lt;a href=&quot;http://xc8oa.com/attachment/ck12.swf&quot;&gt;[Flash] http://xc8oa.com/attachment/ck12.swf&lt;/a&gt;&lt;/p&gt;&lt;/object&gt;&lt;!--&gt; &lt;![endif]--&gt;&lt;/OBJECT&gt;&lt;br /&gt;&lt;br /&gt;내가 저장해둔 플래쉬파일&lt;br /&gt;
&lt;OBJECT codeBase=http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=7,0,0,0 height=70 width=250 classid=clsid:d27cdb6e-ae6d-11cf-96b8-444553540000&gt;&lt;PARAM NAME=&quot;_cx&quot; VALUE=&quot;6615&quot;&gt;&lt;PARAM NAME=&quot;_cy&quot; VALUE=&quot;1852&quot;&gt;&lt;PARAM NAME=&quot;FlashVars&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;Movie&quot; VALUE=&quot;http://coryas.tistory.com/attachment/ck1.swf&quot;&gt;&lt;PARAM NAME=&quot;Src&quot; VALUE=&quot;http://coryas.tistory.com/attachment/ck1.swf&quot;&gt;&lt;PARAM NAME=&quot;WMode&quot; VALUE=&quot;Transparent&quot;&gt;&lt;PARAM NAME=&quot;Play&quot; VALUE=&quot;-1&quot;&gt;&lt;PARAM NAME=&quot;Loop&quot; VALUE=&quot;-1&quot;&gt;&lt;PARAM NAME=&quot;Quality&quot; VALUE=&quot;High&quot;&gt;&lt;PARAM NAME=&quot;SAlign&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;Menu&quot; VALUE=&quot;-1&quot;&gt;&lt;PARAM NAME=&quot;Base&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;AllowScriptAccess&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;Scale&quot; VALUE=&quot;ShowAll&quot;&gt;&lt;PARAM NAME=&quot;DeviceFont&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;EmbedMovie&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;BGColor&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;SWRemote&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;MovieData&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;SeamlessTabbing&quot; VALUE=&quot;1&quot;&gt;&lt;PARAM NAME=&quot;Profile&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;ProfileAddress&quot; VALUE=&quot;&quot;&gt;&lt;PARAM NAME=&quot;ProfilePort&quot; VALUE=&quot;0&quot;&gt;&lt;PARAM NAME=&quot;AllowNetworking&quot; VALUE=&quot;all&quot;&gt;&lt;PARAM NAME=&quot;AllowFullScreen&quot; VALUE=&quot;false&quot;&gt;
&lt;!--[if !IE]&gt; &lt;--&gt;&lt;object type=&quot;application/x-shockwave-flash&quot; wmode=&quot;transparent&quot; data=&quot;http://coryas.tistory.com/attachment/ck1.swf&quot; width=&quot;250&quot; height=&quot;70&quot;&gt;&lt;p&gt;&lt;a href=&quot;http://coryas.tistory.com/attachment/ck1.swf&quot;&gt;[Flash] http://coryas.tistory.com/attachment/ck1.swf&lt;/a&gt;&lt;/p&gt;&lt;/object&gt;&lt;!--&gt; &lt;![endif]--&gt;&lt;/OBJECT&gt;&lt;/P&gt;
&lt;P&gt;이런 플래쉬가 떠있다.&lt;/P&gt;
&lt;P&gt;플래쉬 위치는&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://220.95.158.11/~dhclub20/long1.swf&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~dhclub20/long1.swf&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;이다...&lt;/P&gt;
&lt;P&gt;자! 이플래쉬를 Sothink SWF Decompiler 으로&lt;/P&gt;
&lt;P&gt;열어보자!&lt;/P&gt;
&lt;P&gt;첫번째 보물인&lt;/P&gt;
&lt;P&gt;---------------------------------------&lt;br /&gt;Private_key = 77&lt;br /&gt;modulus = 119&lt;br /&gt;---------------------------------------&lt;/P&gt;
&lt;P&gt;을 찾았다.&lt;/P&gt;
&lt;P&gt;두번째 보물을 찾아보자!&lt;/P&gt;
&lt;P&gt;---------------------------------------&lt;br /&gt;4. 다른 보물은 작다.&lt;br /&gt;---------------------------------------&lt;/P&gt;
&lt;P&gt;작단다... 0아니면 1정도?&lt;/P&gt;
&lt;P&gt;생각했다...&lt;/P&gt;
&lt;P&gt;이 문제는 RSA 알고리즘 문제 이므로&lt;/P&gt;
&lt;P&gt;---------------------------------------&lt;br /&gt;1 ^ 77 Mod 119 = 32&lt;br /&gt;---------------------------------------&lt;/P&gt;
&lt;P&gt;으로 찍었다..&lt;/P&gt;
&lt;P&gt;자 이제 관리자에가 가보자...&lt;/P&gt;
&lt;P&gt;---------------------------------------&lt;br /&gt;6. 두 보물을 조합하여 관리자에게 가라.&lt;br /&gt;7. 패스워드는 관리자에게 있다.&lt;br /&gt;8. 관리자는 관리자실에서 기다리고 있다.&lt;br /&gt;---------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://220.95.158.11/~dhclub20/admin.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~dhclub20/admin.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;찍었다..&lt;/P&gt;
&lt;P&gt;들어가진다...&lt;/P&gt;
&lt;P&gt;32를 썼더니&lt;/P&gt;
&lt;P&gt;---------------------------------------&lt;br /&gt;축하합니다. 다음 레벨로 가세요~ &lt;/P&gt;
&lt;P&gt;The FORMula of SucCess &lt;br /&gt;---------------------------------------&lt;/P&gt;
&lt;P&gt;가 떴다..&lt;/P&gt;&lt;br /&gt;
&lt;P&gt;&lt;br /&gt;level2&lt;br /&gt;&lt;A href=&quot;http://220.95.158.11/~Redy/hust2007/thechange/hack/festival/level2/level2/level2start.html&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~Redy/hust2007/thechange/hack/festival/level2/level2/level2start.html&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;인트로 페이지에 소스보면&lt;/P&gt;
&lt;P&gt;login.js&lt;/P&gt;
&lt;P&gt;가 있다.. 열어보자&lt;/P&gt;
&lt;P&gt;level2&lt;br /&gt;hust&lt;/P&gt;
&lt;P&gt;으로 접속했다..&lt;/P&gt;
&lt;P&gt;들어가자마자 NICK 을 묻는다...&lt;/P&gt;
&lt;P&gt;일단 html 파일을 다운 받았다...&lt;/P&gt;
&lt;P&gt;hiew 로 열어서&lt;/P&gt;
&lt;P&gt;0xBC 부분을 0x31로 고쳐줬다..&lt;/P&gt;
&lt;P&gt;html 태그를 시작하는&lt;/P&gt;
&lt;P&gt;&quot;&amp;lt;&quot; 부분이 &quot;1&quot;로 바뀌면서&lt;/P&gt;
&lt;P&gt;소스를 다 볼수 있었다..&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;br /&gt;1!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&amp;gt; 1HTML&amp;gt; 1HEAD&amp;gt; 1TITLE&amp;gt; HUST 6th Hacking Festival!!! The Change.. 1/TITLE&amp;gt; 1META NAME=&quot;Generator&quot; CONTENT=&quot;EditPlus&quot;&amp;gt; 1META NAME=&quot;Author&quot; CONTENT=&quot;&quot;&amp;gt; 1META NAME=&quot;Keywords&quot; CONTENT=&quot;&quot;&amp;gt; 1META NAME=&quot;Description&quot; CONTENT=&quot;&quot;&amp;gt; 1/HEAD&amp;gt; 1BODY&amp;gt; 1script language = JScript.Encode&amp;gt; 1!-- document.write(unescape(&quot;%3Cbody%20bgcolor%3D%22%23ffffff%22%20oncontextmenu%3D%22return%20false%22%20ondragstart%3D%22return%20false%22%20onselectstart%3D%22return%20false%22%3E%0D%0A%3Cscript%20language%3D%22JavaScript%22%3E%0D%0A%3C%21--%0D%0Apswd%28%29%0D%0Afunction%20pswd%28%29%20%7B%0D%0A%09var%20password%20%3D%20prompt%28%22%uC81C%20nick%uC744%20%uC54C%uACE0%20%uACC4%uC2E0%uAC00%uC694%3F%22%2C%22%22%29%0D%0A%09if%20%28password%20%3D%3D%20%22%52%65%64%79%22%29%20%7B%0D%0A%09myWin%20%3D%20window.close%28%22%2E%2E%2FRedylevel2%2Fauth.php%22%29%3B%20%20%20%20%20myWin.close%28%29%3B%0D%0A%09%7D%0D%0A%09else%20%7B%0D%0A%09window.alert%28%27%uC74C..%uAE00%uC384%uC694..%uC12D%uC12D%uD574%uC694%2E%2E%27%29%3Bself.opener%3Dself%3B%20self.close%28%29%3B%7D%09%7D//--%3E%0D%0A%3C/script%3E&quot;)); //--&amp;gt; 1/script&amp;gt; 1/BODY&amp;gt; 1/HTML&amp;gt;&lt;br /&gt;------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;1script language = JScript.Encode&lt;/P&gt;
&lt;P&gt;JScriptEncode인줄 알았다..&lt;br /&gt;&lt;/P&gt;
&lt;P&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a class=&quot;extensionIcon&quot; href=&quot;http://coryas.com/tc/attachment/8337277031.html&quot;&gt;&lt;img src=&quot;http://coryas.com/tc/image/extension/html.gif&quot; alt=&quot;&quot; /&gt; JScriptEncode.html&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;암호화 부분만 복호화 시켰다..&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://220.95.158.11/~Redy/hust2007/thechange/hack/festival/level2/Redylevel2/auth.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~Redy/hust2007/thechange/hack/festival/level2/Redylevel2/auth.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;으로 가란다...&lt;/P&gt;
&lt;P&gt;로그인하라네...&lt;/P&gt;
&lt;P&gt;아까전에 &lt;/P&gt;
&lt;P&gt;level2&lt;br /&gt;hust&lt;/P&gt;
&lt;P&gt;이걸로 로그인했다...&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://220.95.158.11/~Redy/hust2007/thechange/hack/festival/level2/auth21ev213/closeset.html&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~Redy/hust2007/thechange/hack/festival/level2/auth21ev213/closeset.html&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;검정색이다...&lt;/P&gt;
&lt;P&gt;컨트롤 + A&lt;/P&gt;
&lt;P&gt;누르니깐 굿잡이란다..&lt;/P&gt;
&lt;P&gt;소스봤다...&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;br /&gt;&amp;lt;!--Q29uZ3JhdHVsYXRpb25zISBVIHBhc3NlZCBMZXZlbDIuLi4gTkVYVCBMZXZlbCBBdXRoZW50aWNhdGlvbiBQYXNzd29yZCBpcyAiRmluZGVycyBrZWVwZXIsIGxvc2VyIHdlZXBlcnMi--&amp;gt;&lt;br /&gt;------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;암호화 부분이 있다...&lt;/P&gt;
&lt;P&gt;무슨 알고리즘인지 한참 고민했다..&lt;/P&gt;
&lt;P&gt;작년 hust 문제들은 검색했더니..&lt;/P&gt;
&lt;P&gt;base64를 사용한 문제가 있었는데..&lt;/P&gt;
&lt;P&gt;저거랑 비슷했다...&lt;/P&gt;&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a class=&quot;extensionIcon&quot; href=&quot;http://coryas.com/tc/attachment/7635800793.html&quot;&gt;&lt;img src=&quot;http://coryas.com/tc/image/extension/html.gif&quot; alt=&quot;&quot; /&gt; base64-goldbly.html&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;
&lt;P&gt;복호화 해봤다...&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;------------------------------------------------------------------------------&lt;br /&gt;Congratulations! U passed Level2... NEXT Level Authentication Password is &quot;Finders keeper, loser weepers&quot;&lt;br /&gt;------------------------------------------------------------------------------&lt;/P&gt;&lt;br /&gt;&lt;br /&gt;
&lt;P&gt;level3&lt;br /&gt;&lt;A href=&quot;http://220.95.158.11/~level3/main.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~level3/main.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;힌트를 보면&lt;/P&gt;
&lt;P&gt;---------------------------------------&lt;br /&gt;total, flag&lt;br /&gt;---------------------------------------&lt;/P&gt;
&lt;P&gt;이거다...&lt;/P&gt;
&lt;P&gt;get으로 계속 보냈는데..&lt;/P&gt;
&lt;P&gt;안되길래...&lt;/P&gt;
&lt;P&gt;패킷 캡쳐 하는 프로그램으로..&lt;/P&gt;
&lt;P&gt;해봤다..&lt;/P&gt;
&lt;P&gt;패킷 캡쳐해서&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;br /&gt;&lt;A href=&quot;http://220.95.158.11/~level3/confirm.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~level3/confirm.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;number=3&amp;amp;name=HUST+T-Shirt%2Fcheapest+price%21%2FLast+chance&amp;amp;total=0&amp;amp;flag=0&amp;amp;x=35&amp;amp;y=10&lt;br /&gt;------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;으로 보냈더니&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://220.95.158.11/~level3/dicision.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~level3/dicision.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;으로 갔다...&lt;/P&gt;
&lt;P&gt;좋아!&lt;/P&gt;
&lt;P&gt;그림을 클릭하던가...&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;br /&gt;&lt;A href=&quot;http://220.95.158.11/~level3/lk.php&quot;&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;http://220.95.158.11/~level3/lk.php&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;success=1&lt;br /&gt;------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;위 처럼 패킷을 보내면&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------&lt;br /&gt;축하합니다.다음 레벨로 가는 암호는 BoNe To bE a HaCKeR 입니다. &lt;br /&gt;------------------------------------------------------------------------------&lt;/P&gt;&lt;br /&gt;
&lt;P&gt;더 하고 싶었는데..&lt;/P&gt;
&lt;P&gt;이런 저런 사정때문에... 여기서 그만뒀다...&lt;/P&gt;
&lt;P&gt;아쉽다..&lt;/P&gt;
&lt;P&gt;더 풀고 싶었는데...&lt;/P&gt;
&lt;P&gt;다음 대회를 기다려야겠다...&lt;/P&gt;</summary>
  </entry>
</feed>

