[webhacking.kr] 6번 문제 풀이[Base64]

1 분 소요

💡 Webhacking.kr challenge(old) 6번 문제에 대한 풀이입니다.

문제

소스코드

  <?php
  include "../../config.php";
  if($_GET['view_source']) view_source();
  if(!$_COOKIE['user']){
    $val_id="guest";
    $val_pw="123qwe";
    for($i=0;$i<20;$i++){
      $val_id=base64_encode($val_id);
      $val_pw=base64_encode($val_pw);
    }
    $val_id=str_replace("1","!",$val_id);
    $val_id=str_replace("2","@",$val_id);
    $val_id=str_replace("3","$",$val_id);
    $val_id=str_replace("4","^",$val_id);
    $val_id=str_replace("5","&",$val_id);
    $val_id=str_replace("6","*",$val_id);
    $val_id=str_replace("7","(",$val_id);
    $val_id=str_replace("8",")",$val_id);

    $val_pw=str_replace("1","!",$val_pw);
    $val_pw=str_replace("2","@",$val_pw);
    $val_pw=str_replace("3","$",$val_pw);
    $val_pw=str_replace("4","^",$val_pw);
    $val_pw=str_replace("5","&",$val_pw);
    $val_pw=str_replace("6","*",$val_pw);
    $val_pw=str_replace("7","(",$val_pw);
    $val_pw=str_replace("8",")",$val_pw);

    Setcookie("user",$val_id,time()+86400,"/challenge/web-06/");
    Setcookie("password",$val_pw,time()+86400,"/challenge/web-06/");
    echo("<meta http-equiv=refresh content=0>");
    exit;
  }
  ?>
  <html>
  <head>
  <title>Challenge 6</title>
  <style type="text/css">
  body { background:black; color:white; font-size:10pt; }
  </style>
  </head>
  <body>
  <?php
  $decode_id=$_COOKIE['user'];
  $decode_pw=$_COOKIE['password'];

  $decode_id=str_replace("!","1",$decode_id);
  $decode_id=str_replace("@","2",$decode_id);
  $decode_id=str_replace("$","3",$decode_id);
  $decode_id=str_replace("^","4",$decode_id);
  $decode_id=str_replace("&","5",$decode_id);
  $decode_id=str_replace("*","6",$decode_id);
  $decode_id=str_replace("(","7",$decode_id);
  $decode_id=str_replace(")","8",$decode_id);

  $decode_pw=str_replace("!","1",$decode_pw);
  $decode_pw=str_replace("@","2",$decode_pw);
  $decode_pw=str_replace("$","3",$decode_pw);
  $decode_pw=str_replace("^","4",$decode_pw);
  $decode_pw=str_replace("&","5",$decode_pw);
  $decode_pw=str_replace("*","6",$decode_pw);
  $decode_pw=str_replace("(","7",$decode_pw);
  $decode_pw=str_replace(")","8",$decode_pw);

  for($i=0;$i<20;$i++){
    $decode_id=base64_decode($decode_id);
    $decode_pw=base64_decode($decode_pw);
  }

  echo("<hr><a href=./?view_source=1 style=color:yellow;>view-source</a><br><br>");
  echo("ID : $decode_id<br>PW : $decode_pw<hr>");

  if($decode_id=="admin" && $decode_pw=="nimda"){
    solve(6);
  }
  ?>
  </body>
  </html>



풀이

사용자로부터 받은 쿠키값을 base64 디코딩 및 문자열 치환을 거쳤을 때, 결과같이 admin, nimda 면 됩니다.

 if($decode_id=="admin" && $decode_pw=="nimda"){
    solve(6);
  }

예전에는 base64 인코딩, 디코딩을 해주는 웹사이트를 이용해서 노가다로 풀었었는데, 이번에는 파이썬 코드를 짜서 풀어봤습니다.

우선 파이썬에서는 base64라이브러리를 이용해서 base64 인코딩, 디코딩을 쉽게 할 수 있습니다.

base64 인코딩 예시

  import base64

  name = 'myoungseok'          # 1. 문자열
  name_bytes = name .encode('ascii')  # 2. bytes형 변환
  name_base64 = base64.b64encode(name_bytes)  #3. base64인코딩
  name_base64_str = name_base64.decode('ascii')   # 결과값 문자열로 만들기

  print(name)
  print(name_bytes)
  print(name_base64)
  print(name_base64_str)

실행 결과

  myoungseok
  b'myoungseok'
  b'bXlvdW5nc2Vvaw=='
  bXlvdW5nc2Vvaw==

따라서 base64 인코딩은 반복문을 이용해서 다음과 같이 할 수 있습니다.

  string = 'guest'
  string_bytes = string.encode('ascii')
  string_base64 = string_bytes

  for i in range(20):
      string_base64 = base64.b64encode(string_base64)

  string_base64_20_str = string_base64.decode('ascii')

그다음은 문자열을 주어진 조건에 맞춰서 치환하는 과정이 필요합니다. 다음과 같이 replace를 이용해서 했습니다.

  replace_str = string_base64_20_str
  replace_str = replace_str.replace("1","!")
  replace_str = replace_str.replace("2","@")
  replace_str = replace_str.replace("3","$")
  replace_str = replace_str.replace("4","^")
  replace_str = replace_str.replace("5","&")
  replace_str = replace_str.replace("6","*")
  replace_str = replace_str.replace("7","(")
  replace_str = replace_str.replace("8",")")

이렇게 해서 나온 결과값을 현재 페이지의 쿠키값과 비교해보니 결과가 똑같았습니다. 이제 인코딩 하는 값을 guest가 아닌 admin,nimda를 해주고 해당 값을 쿠키 값으로 넣어주면 문제가 풀릴 것입니다.

위의 인코딩 과정을 함수로 구현하여, 인자값에 따라서 결과를 반환하도록 구현했습니다.

  def base64_encode_20(string):
      string_bytes = string.encode('ascii')
      string_base64 = string_bytes

      for i in range(20):
          string_base64 = base64.b64encode(string_base64)
          print(string_base64)

      string_base64_20_str = string_base64.decode('ascii')

      replace_str = string_base64_20_str
      replace_str = replace_str.replace("1","!")
      replace_str = replace_str.replace("2","@")
      replace_str = replace_str.replace("3","$")
      replace_str = replace_str.replace("4","^")
      replace_str = replace_str.replace("5","&")
      replace_str = replace_str.replace("6","*")
      replace_str = replace_str.replace("7","(")
      replace_str = replace_str.replace("8",")")

      return replace_str

함수 실행 결과

 base64_encode_20("admin")
 Vm0wd@QyUXlVWGxWV0d^V!YwZDRWMVl$WkRSV0!WbDNXa!JTVjAxV@JETlhhMUpUVmpBeFYySkVUbGhoTVVwVVZtcEJlRll&U@tWVWJHaG9UVlZ$VlZadGNFSmxSbGw!VTJ0V!ZXSkhhRzlVVmxaM!ZsWmFjVkZ0UmxSTmJFcEpWbTEwYTFkSFNrZGpSVGxhVmpOU!IxcFZXbUZrUjA!R!UyMTRVMkpIZHpGV!ZFb$dWakZhV0ZOcmFHaFNlbXhXVm!wT!QwMHhjRlpYYlVaclVqQTFSMWRyV@&kV0!ERkZVbFJHVjFaRmIzZFdha!poVjBaT@NtRkhhRk&sYlhoWFZtMXdUMVF$TUhoalJscFlZbGhTV0ZSV@FFTlNiRnBZWlVaT!ZXSlZXVEpWYkZKRFZqQXhkVlZ!V@xaaGExcFlXa!ZhVDJOc@NFZGhSMnhUVFcxb@IxWXhaREJaVmxsM!RVaG9hbEpzY0ZsWmJGWmhZMnhXY!ZGVVJsTk&WMUo!VmpKNFQxWlhTbFpYVkVwV!lrWktTRlpxUm!GU@JVbDZXa!prYUdFeGNHOVdha0poVkRKT@RGSnJhR@hTYXpWeldXeG9iMWRHV@&STldHUlZUVlpHTTFSVmFHOWhiRXB*WTBac!dtSkdXbWhaTVZwaFpFZFNTRkpyTlZOaVJtOTNWMnhXWVZReFdsaFRiRnBZVmtWd!YxbHJXa$RUUmxweFVtMUdVMkpWYkRaWGExcHJZVWRGZUdOSE9WZGhhMHBvVmtSS!QyUkdTbkpoUjJoVFlYcFdlbGRYZUc&aU!XUkhWMjVTVGxOSGFGQlZiVEUwVmpGU!ZtRkhPVmhTTUhCNVZHeGFjMWR0U@tkWGJXaGFUVzVvV0ZreFdrZFdWa$B*VkdzMVYySkdhM@hXYTFwaFZURlZlRmR!U@s!WFJYQnhWVzB^YjFZeFVsaE9WazVPVFZad@VGVXlkREJXTVZweVkwWndXR0V^Y0ROV@FrWkxWakpPU!dKR!pGZFNWWEJ@Vm!0U!MxUXlUWGxVYTFwb!VqTkNWRmxZY0ZkWFZscFlZMFU!YVUxcmJEUldNalZUVkd^a!NGVnNXbFZXYkhCWVZHdGFWbVZIUmtoUFYyaHBVbGhDTmxkVVFtRmpNV!IwVTJ0a!dHSlhhR0ZVVnpWdlYwWnJlRmRyWkZkV@EzQjZWa@R*TVZZd0!WWmlla!pYWWxoQ!RGUnJXbEpsUm!SellVWlNhVkp!UW&oV!YzaHJWVEZzVjFWc!dsaGlWVnBQVkZaYWQyVkdWWGxrUkVKWFRWWndlVmt$V@&kWFIwVjRZMFJPV@!FeVVrZGFWM@hIWTIxS!IxcEhiRmhTVlhCS!ZtMTBVMU!^VlhoWFdHaFlZbXhhVjFsc!pHOVdSbXhaWTBaa@JHSkhVbGxhVldNMVlWVXhXRlZyYUZkTmFsWlVWa@Q0YTFOR!ZuTlhiRlpYWWtoQ!NWWkdVa@RWTVZwMFVtdG9VRll&YUhCVmJHaERUbXhrVlZGdFJtcE&WMUl$VlRKMGExZEhTbGhoUjBaVlZucFdkbFl$V@&OT@JFcHpXa@R$YVZORlNrbFdNblJyWXpGVmVWTnVTbFJpVlZwWVZGYzFiMWRHWkZkWGJFcHNVbTFTZWxsVldsTmhWa$AxVVd^d!YySllVbGhhUkVaYVpVZEtTVk&zYUdoTk!VcFZWbGN^TkdReVZrZFdiR!JvVW&wc@IxUldXbmRsYkZsNVkwVmtWMDFFUmpGWlZXaExWMnhhV0ZWclpHRldNMmhJV!RJeFMxSXhjRWhpUm!oVFZsaENTMVp0TVRCVk!VMTRWbGhvV0ZkSGFGbFpiWGhoVm!^c@NscEhPV$BTYkhCNFZrY$dOVll^V@&OalJXaFlWa!UxZGxsV!ZYaFhSbFp&WVVaa!RtRnNXbFZXYTJRMFdWWktjMVJ!VG!oU@JGcFlXV$hhUm!ReFduRlJiVVphVm0xU!NWWlhkRzloTVVwMFlVWlNWVlpXY0dGVVZscGhZekZ$UlZWdGNFNVdNVWwzVmxSS0!HRXhaRWhUYkdob!VqQmFWbFp0ZUhkTk!WcHlWMjFHYWxacmNEQmFSV!F$VmpKS@NsTnJhRmRTTTJob!ZrUktSMVl^VG&WVmJFSlhVbFJXV!ZaR!l*RmlNV!JIWWtaV!VsZEhhRlJVVm!SVFpXeHNWbGRzVG!oU!ZFWjZWVEkxYjFZeFdYcFZiR@hZVm!^d!lWcFZXbXRrVmtwelZtMXNWMUl*YURWV0!XUXdXVmRSZVZaclpGZGliRXB&Vld0V!MySXhiRmxqUldSc!ZteEtlbFp0TURWWFIwcEhZMFpvV@sxSGFFeFdNbmhoVjBaV@NscEhSbGROTW!oSlYxUkplRk!^U!hoalJXUmhVbXMxV0ZZd!ZrdE&iRnAwWTBWa!dsWXdWalJXYkdodlYwWmtTR0ZHV@xwaVdHaG9WbTE0YzJOc!pISmtSM0JUWWtad0&GWlhNVEJOUmxsNFYyNU9hbEpYYUZoV@FrNVRWRVpzVlZGWWFGTldhM0I@VmtkNFlWVXlTa!pYV0hCWFZsWndSMVF^V@tOVmJFSlZUVVF$UFE9PQ==
 base64_encode_20("nimda")
 Vm0wd@QyUXlVWGxWV0d^V!YwZDRWMVl$WkRSV0!WbDNXa!JTVjAxV@JETlhhMUpUVmpBeFYySkVUbGhoTVVwVVZtcEJlRll&U@tWVWJHaG9UVlZ$VlZacVFtRlRNbEpJVm!0a!dHSkdjRTlaVjNSR!pVWmFkR0&GU@!^U@JHdzFWVEowVjFaWFNraGhSemxWVmpOT00xcFZXbUZrUjA!R!drWndWMDFFUlRGV!ZFb$dWakZhV0ZOcmFHaFNlbXhXVm0xNFlVMHhXbk&YYlVaclVqQTFSMWRyV@xOVWJVcEdZMFZ$VjJKVVJYZFdha!pYWkVaT@MxZHNhR@xTTW!oWlYxZDRiMkl&Vm&OVmJGWlRZbFZhY@xWcVFURlNNVlY!VFZSU!ZrMXJjRWxhU0hCSFZqRmFSbUl*WkZkaGExcG9WakJhVDJOdFJraGhSazVzWWxob!dGWnRNSGhPUm!^V!RVaG9XR0pyTlZsWmJGWmhZMVphZEdSSFJrNVNiRm9$V@xWYVQxWlhTbFpqUldSYVRVWmFNMVpxU@t0V!ZrcFpXa!p$VjFKV@NIbFdWRUpoVkRKT@MyTkZhR$BTYXpWWVZXcE9iMkl^V@&STldHUlZUVlpXTkZVeGFHOWhiRXB*WTBac!dtSkdXbWhaTW&oWFkxWkdWVkpzVGs!WFJVcElWbXBLTkZReFdsaFRhMlJxVW0xNGFGVXdhRU&UUmxweFVtMUdVMkpWYkRaWGExcHJZVWRGZUdOSE9WZGhhMHBvVmtSS!QyUkdTbkpoUjJoVFlYcFdlbGRYZUc&aU!XUkhWMjVTVGxOSGFGQlZiVEUwVmpGU!ZtRkhPVmhTTUhCNVZHeGFjMWR0U@tkWGJXaGFUVzVvV0ZreFdrZFdWa$B*VkdzMVYySkdhM@hXYTFwaFZURlZlRmR!U@s!WFJYQnhWVzB^YjFZeFVsaE9WazVPVFZad@VGVXlkREJXTVZweVkwWndXR0V^Y0ROV@FrWkxWakpPU!dKR!pGZFNWWEJ@Vm!0U!MxUXlUWGxVYTFwb!VqTkNWRmxZY0ZkWFZscFlZMFU!YVUxcmJEUldNV@h@V!ZaS!IxTnNaRlZXYkZwNlZHeGFZVmRGTlZaUFZtaFRUVWhDU@xac!pEUmpNV!IwVTJ0b@FGSnNTbGhVVlZwM!ZrWmFjVk&yWkZOaVJrcDZWa@N^YzFVeVNuSlRiVVpYVFc!b!dGbHFTa!psUm!SWldrVTFWMVpzY0ZWWFZsSkhaREZaZUdKSVNsaGhNMUpVVlcxNGQyVkdWbGRoUnpsb!RWWndlbFl&Y0VkV0!ERjFZVWhLV@xaWFVrZGFWM@hIWTIxS!IyRkdhRlJTVlhCS!ZtMTBVMU!^VlhoWFdHaFlZbXhhVjFsc!pHOVdSbXhaWTBaa@JHSkhVbGxhVldNMVlWVXhXRlZyYUZkTmFsWlVWa@Q0YTFOR!ZuTlhiRlpYWWtoQ!NWWkdVa@RWTVZwMFVtdG9VRll&YUhCVmJHaERUbXhrVlZGdFJtcE&WMUl$VlRKMGExZEhTbGhoUjBaVlZucFdkbFl$V@&KbFJtUnlXa!prVjJFelFqWldhMlI@VFZaWmQwMVdXbWxsYTFwWVdXeG9RMVJHVW&KWGJFcHNVbTFTZWxsVldsTmhWa$AxVVd^d!YySllVbGhhUkVaYVpVZEtTVk&zYUdoTk!VcFdWbGN^TkdReVZrZFdXR$hyVWpCYWNGVnRlSGRsYkZsNVpVaGtXRkl$VmpSWk!GSlBWMjFGZVZWclpHRldNMmhJV!RJeFMxSXhjRWhpUm!oVFZsaENTMVp0TVRCVk!VMTRWbGhvV0ZkSGFGbFpiWGhoVm!^c@NscEhPV$BTYkhCNFZrY$dOVll^V@&OalJXaFlWa!UxZGxsV!ZYaFhSbFp&WVVaa!RtRnNXbFZXYTJRMFdWWktjMVJ!VG!oU@JGcFlXV$hhUm!ReFduRlJiVVphVm0xU!NWWlhkRzloTVVwMFlVWlNWVlpXY0dGVVZscGhZekZ$UlZWdGNFNVdNVWwzVmxSS0!HRXhaRWhUYkdob!VqQmFWbFp0ZUhkTk!WcHlWMjFHYWxacmNEQmFSV!F$VmpKS@NsTnJhRmRTTTJob!ZrUktSMVl^VG&WVmJFSlhVbFJXV!ZaR!l*RmlNV!JIWWtaV!VsZEhhRlJVVm!SVFpXeHNWbGRzVG!oU!ZFWjZWVEkxYjFZeFdYcFZiR@hZVm!^d!lWcFZXbXRrVmtwelZtMXNWMUl*YURWV0!XUXdXVmRSZVZaclpGZGliRXB&Vld0V!MySXhiRmxqUldSc!ZteEtlbFp0TURWWFIwcEhZMFpvV@sxSGFFeFdNbmhoVjBaV@NscEhSbGROTW!oSlYxUkplRk!^U!hoalJXUmhVbXMxV0ZZd!ZrdE&iRnAwWTBWa!dsWXdWalJXYkdodlYwWmtTR0ZHV@xwaVdHaG9WbTE0YzJOc!pISmtSM0JUWWtad0&GWlhNVEJOUmxsNFYyNU9hbEpYYUZoV@FrNVRWRVpzVlZGWWFGTldhM0I@VmtkNFlWVXlTa!pYV0hCWFZsWndSMVF^V@tOVmJFSlZUVVF$UFE9PQ==

위의 값들을 쿠키에 넣어주면 됩니다.

image

문제 해결!

image

제가 쓴 문제 풀이 코드는 깃허브에 올려 놓을테니 참고 하셔도 됩니다.

댓글남기기