> For the complete documentation index, see [llms.txt](https://docs.cooku222.kr/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cooku222.kr/security/web-hacking/webhacking.kr/webhacking.kr-old-3.md).

# \[webhacking.kr] old-3

<figure><img src="https://blog.kakaocdn.net/dna/pDCIk/btsOvWnxikM/AAAAAAAAAAAAAAAAAAAAAEYIvHLpetElaIYvTgDvteaJ4HfO4JRzxj8tQSGDVrUN/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=ZOA9IEqTarYeXgvL5exK6w%2FsuZI%3D" alt="" height="812" width="902"><figcaption></figcaption></figure>

아 참고로 솔브드 누르면 no 뜨고 화면 바로 롤백됨\
노노 그램의 의미를 떠올리면서 5\*5위치 누르면 화면에 변화가 일어난다.

<https://en.wikipedia.org/wiki/Nonogram>

[ Nonogram - WikipediaFrom Wikipedia, the free encyclopedia Logic puzzle forming a picture in a grid This article is about the puzzle. For the star polygon, see Nonagram. For the calculating device, see Nomogram. A completed nonogram of the letter "W" from the Wikipedia logo Noen.wikipedia.org](https://en.wikipedia.org/wiki/Nonogram)

<figure><img src="https://blog.kakaocdn.net/dna/4wbW3/btsOuQO0qbL/AAAAAAAAAAAAAAAAAAAAAEah0LvRUpzvq6sG_doEEfZvi2SMSPvzdrgNtUv66e5z/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=rHaP5ZT3oY2651fGzk2Y4A4%2Bm9Y%3D" alt="" height="752" width="757"><figcaption></figcaption></figure>

여기서 솔브드를 누르면 다음으로 넘어간다.

<figure><img src="https://blog.kakaocdn.net/dna/ZBYIh/btsOu9OfBcR/AAAAAAAAAAAAAAAAAAAAAGK6sWmyveImg3VNCkXtjVKN4eo4g568dY0GY3IxClI-/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=p%2Fe8pafsZjwCmMETI1ns6d6Q0EM%3D" alt="" height="206" width="892"><figcaption></figcaption></figure>

커맨드창에 내 아이디 입력해준다.

<figure><img src="https://blog.kakaocdn.net/dna/bpfcy9/btsOwrUUpDp/AAAAAAAAAAAAAAAAAAAAAGQLSD4AcMb5oFdenoIjmL59mE3I5c9slWwlb2RGCev3/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=RMZhwoqE88vo87FuF63eLL0aoTk%3D" alt="" height="248" width="922"><figcaption></figcaption></figure>

<figure><img src="https://blog.kakaocdn.net/dna/mwA2M/btsOuY7vxlC/AAAAAAAAAAAAAAAAAAAAAC8D0iLpV-QyW2iA8Z5grmXsXfYT28dFeO1Vyuk-Y94r/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=emHEUUu%2BNAmqcpYUvbmqbXf03Xk%3D" alt="" height="235" width="926"><figcaption></figcaption></figure>

해당 커맨드 창에 blind injection 시도하면 이런거 뜸

<figure><img src="https://blog.kakaocdn.net/dna/bwE0tj/btsOwj3O7Cn/AAAAAAAAAAAAAAAAAAAAANiSHw4AjlqgV5FLvEz_wQEMpP6xDA1c2u8ItXeKEc6A/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=yKcPfrq%2BrUeFDyTBk9bXpvSFSK0%3D" alt="" height="131" width="550"><figcaption><p>1=1은 언제나 성립하니까</p></figcaption></figure>

<figure><img src="https://blog.kakaocdn.net/dna/dlgCV2/btsOujqZb8j/AAAAAAAAAAAAAAAAAAAAAGfRB8l35iFgCgz1mtTb5Pi83LIDCKpJoNubRB8pzrUi/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=wDqkz7%2FDbfSPvIoQekqULK4rd3U%3D" alt="" height="127" width="791"><figcaption></figcaption></figure>

여기에서 php 코드를 좀 수정해준다. 내 아이디를 넣어서 얻은 value에 blind injection을 넣어서 코드를 수정해준다.

<figure><img src="https://blog.kakaocdn.net/dna/dbLKDX/btsOuCRah4G/AAAAAAAAAAAAAAAAAAAAAL3r9cXonZbuIuWIw_usEB_d5cYbFfoDXgTDPaqZg0NQ/img.png?credential=yqXZFxpELC7KVnFOS48ylbz2pIh7yKj8&#x26;expires=1782831599&#x26;allow_ip=&#x26;allow_referer=&#x26;signature=oAo%2BfWXIsSkxj%2Fe31S20ho29Geo%3D" alt="" height="252" width="757"><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.cooku222.kr/security/web-hacking/webhacking.kr/webhacking.kr-old-3.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
