2026. 3. 6. 17:44ㆍ보안/Web security Academy
Lab: Blind SQL injection with time delays and information retrieval
This lab contains a blind SQL injection vulnerability. The application uses a tracking cookie for analytics, and performs a SQL query containing the value of the submitted cookie.
The results of the SQL query are not returned, and the application does not respond any differently based on whether the query returns any rows or causes an error. However, since the query is executed synchronously, it is possible to trigger conditional time delays to infer information.
The database contains a different table called users, with columns called username and password. You need to exploit the blind SQL injection vulnerability to find out the password of the administrator user.
To solve the lab, log in as the administrator user.
( 이 랩에는 블라인드 SQL 주입 취약점이 포함되어 있습니다. 애플리케이션은 분석을 위해 추적 쿠키를 사용하며, 제출된 쿠키의 값을 포함하는 SQL 쿼리를 수행합니다.
SQL 쿼리의 결과는 반환되지 않으며, 쿼리가 행을 반환하거나 오류를 유발하는지 여부에 따라 애플리케이션이 다르게 응답하지 않습니다. 그러나 쿼리가 동기화되어 실행되므로 조건부 시간 지연을 유발하여 정보를 추론할 수 있습니다.
데이터베이스에는 사용자 이름과 비밀번호라는 열이 있는 사용자라는 다른 테이블이 있습니다. 관리자의 비밀번호를 알아내려면 블라인드 SQL 주입 취약점을 악용해야 합니다.
실험실을 해결하려면 관리자로 로그인하세요. )
1. 데이터베이스 종류 확인하기

현재 lab에서는 blind sql이기 떄문에 쿼리의 결과를 반환하지 않기 떄문에 sleep을 사용해서 어떠한 데이터베이스를 사용하는지 확인합니다 pg_sleep(10)을 사용했더니 10초에 지연이 있는것을 확인했습니다 따라서 postgresql을 사용한다는것을 알수있습니다
2. 목표는 관리자 계정에 로그인이기 때문에 intruder를 사용해서 비밀번호 자리수 및 비밀번호를 찾아보도록 하겠습니다 (id는 adminstrator입니다)

'|| (SELECT CASE WHEN (LENGTH(password)=$1$) THEN pg_sleep(10) ELSE pg_sleep(0) END FROM users WHERE username='administrator' LIMIT 1)-- 구문을 사용합니다
payload에서 type은 number 1~30까지 지정해주고

20번째에서 10초 지연이 있는것을 확인했습니다 따라서 비밀번호는 20자리 입니다
3. 이제 이를 바탕으로 비밀번호를 찾도록 하겠습니다
'|| (SELECT CASE WHEN (SUBSTR((SELECT password FROM users WHERE username='administrator'),$1$,1)='$a$') THEN pg_sleep(5) ELSE pg_sleep(0) END)--

cluster bomb attack으로 번경하고 $1$에 payload는 1~20까지 number로 지정하고

$a$에 payload는 silmple list에서 0~9 ,a~z까지 지정합니다
이제 돌리면 되는데 한번에 하면 720번이 걸리기 때문에 저는 5자리씩 나눠서 진행했습니다

그렇게 나온 비밀번호는 z54d4yv7k0bu3sckaowl로

로그인 성공을 했습니다 이상입니다
'보안 > Web security Academy' 카테고리의 다른 글
| web security academy 16 (1) | 2026.03.10 |
|---|---|
| web security academy 15 (0) | 2026.03.09 |
| web security academy 13 (0) | 2026.03.05 |
| web security academy 12 (0) | 2026.03.03 |
| web security academy 11 (0) | 2026.02.24 |