Study/Web Hacking

[DreamHeck] Another Ping

얀 짱 2026. 9. 10. 17:28

https://dreamhack.io/wargame/challenges/2377

 

로그인 | Dreamhack

 

dreamhack.io

 

import os
import re
import subprocess
from flask import Flask, render_template, request, jsonify

app = Flask(__name__)
app.secret_key = os.urandom(32)

# 필터링 걸려있음 
FILTERED_CHARS = [' ', ';', '|', '&', '>', '<', '(', ')', '[', ']', '{', '}', '\n', '\r']

def is_valid_ip(ip):
    ip_pattern = r'^(\d{1,3}\.){3}\d{1,3}$'
    return bool(re.match(ip_pattern, ip))

def filter_input(user_input):
    for char in FILTERED_CHARS:
        if char in user_input:
            return False, f"Invalid character detected: {char}"
    return True, "OK"

@app.route('/')
def index():
    return render_template('index.html')

@app.route('/ping', methods=['POST'])
def ping():
    ip = request.form.get('ip', '').strip()
    
    if not ip:
        return jsonify({'error': 'IP address is required'}), 400
    
    is_valid, message = filter_input(ip)
    if not is_valid:
        return jsonify({'error': message}), 400
    
    try:
        cmd = f"ping -c 4 {ip}"
        result = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=10)
        
        return jsonify({
            'command': cmd,
            'stdout': result.stdout,
            'stderr': result.stderr,
            'returncode': result.returncode
        })
    
    except subprocess.TimeoutExpired:
        return jsonify({'error': 'Command timed out'}), 500
    except Exception as e:
        return jsonify({'error': str(e)}), 500


if __name__ == '__main__':
    app.run(host='0.0.0.0', port=8000, debug=False)

 

코드를 보니 필터링이 걸려있었음. 코드를 전체 다 읽어봐도 무슨 취약점인지는 잘 모르겠어서 (자꾸 죽음의 핑 밖에 안 떠올랐음..) 그냥 해당 필터링 부분을 복사해서 구글링해봄.

 

https://devopslog.tistory.com/166

 

정규식의 멀티라인 expressions 활용

멀티라인 표현식의 활용법, Dotall (Single Line) 모드, Multi Line 모드, Non-Dotall 모드의 차이점, 여러 줄을 처리하는 방법정규식의 멀티라인 표현식이란?정규식(Regular Expression, Regex)은 텍스트 패턴을 검

devopslog.tistory.com

 

그러던 중 이 포스팅을 보게 됨.

필자가 말씀해주신 다른 것들은 다 필터링으로 막혀있었음.

 

명령어 및 파일 제어 (|, &, >, <): 리눅스/유닉스 환경에서 명령어 파이프라인, 백그라운드 실행, 입출력 리다이렉션에 사용된다고 함 -> command injection 아닐까...? 하는 생각.

 

https://portswigger.net/burp/documentation/desktop/testing-workflow/vulnerabilities/input-validation/command-injection/testing

 

PortSwigger — Web security tools, training and research

We enable the world to secure the web. Burp Suite, the Web Security Academy, and world-leading research from PortSwigger — the AppSec community’s home.

portswigger.net

 

https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Command%20Injection

 

PayloadsAllTheThings/Command Injection at master · swisskyrepo/PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF - swisskyrepo/PayloadsAllTheThings

github.com

 

팀원이 준 페이로드를 참고해보자.

 

 

공백 우회는 $IFS로.

cat$IFS./flag.txt

 

이런 식...?

 

 

` 사용하기

ping -c 4 `cat$IFS./flag.txt`

 

이런 식으로..

 

 

플래그 얻음!