# Reset/Forgotten Password Bypass {% hint style="success" %} Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
Support HackTricks * Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! * **Join the** πŸ’¬ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.** * **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
{% endhint %}
Join [**HackenProof Discord**](https://discord.com/invite/N3FrSbmwdy) server to communicate with experienced hackers and bug bounty hunters! **Hacking Insights**\ Engage with content that delves into the thrill and challenges of hacking **Real-Time Hack News**\ Keep up-to-date with fast-paced hacking world through real-time news and insights **Latest Announcements**\ Stay informed with the newest bug bounties launching and crucial platform updates **Join us on** [**Discord**](https://discord.com/invite/N3FrSbmwdy) and start collaborating with top hackers today! ## **λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰 유좜 via Referrer** * HTTP referer ν—€λ”λŠ” URL에 ν¬ν•¨λœ 경우 λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰을 μœ μΆœν•  수 μžˆμŠ΅λ‹ˆλ‹€. μ΄λŠ” μ‚¬μš©μžκ°€ λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ •μ„ μš”μ²­ν•œ ν›„ 제3자 μ›Ήμ‚¬μ΄νŠΈ 링크λ₯Ό 클릭할 λ•Œ λ°œμƒν•  수 μžˆμŠ΅λ‹ˆλ‹€. * **영ν–₯**: ꡐ차 μ‚¬μ΄νŠΈ μš”μ²­ μœ„μ‘°(CSRF) 곡격을 ν†΅ν•œ 계정 νƒˆμ·¨ κ°€λŠ₯μ„±. * **μ•…μš©**: referer ν—€λ”μ—μ„œ λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰이 μœ μΆœλ˜λŠ”μ§€ ν™•μΈν•˜λ €λ©΄, **λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ •μ„ μš”μ²­**ν•˜μ—¬ 이메일 μ£Όμ†Œλ‘œ **제곡된 μž¬μ„€μ • 링크λ₯Ό 클릭**ν•©λ‹ˆλ‹€. **μ¦‰μ‹œ λΉ„λ°€λ²ˆν˜Έλ₯Ό λ³€κ²½ν•˜μ§€ λ§ˆμ‹­μ‹œμ˜€**. λŒ€μ‹ , **Burp Suiteλ₯Ό μ‚¬μš©ν•˜μ—¬ μš”μ²­μ„ κ°€λ‘œμ±„λ©΄μ„œ** **제3자 μ›Ήμ‚¬μ΄νŠΈ**(예: Facebook λ˜λŠ” Twitter)둜 μ΄λ™ν•©λ‹ˆλ‹€. μš”μ²­μ„ κ²€μ‚¬ν•˜μ—¬ **referer 헀더에 λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰이 ν¬ν•¨λ˜μ–΄ μžˆλŠ”μ§€** ν™•μΈν•˜μ‹­μ‹œμ˜€. μ΄λŠ” 제3μžμ—κ²Œ λ―Όκ°ν•œ 정보λ₯Ό λ…ΈμΆœν•  수 μžˆμŠ΅λ‹ˆλ‹€. * **참고자료**: * [HackerOne Report 342693](https://hackerone.com/reports/342693) * [HackerOne Report 272379](https://hackerone.com/reports/272379) * [λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰 유좜 기사](https://medium.com/@rubiojhayz1234/toyotas-password-reset-token-and-email-address-leak-via-referer-header-b0ede6507c6a) ## **λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 쀑독** * κ³΅κ²©μžλŠ” λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • μš”μ²­ 쀑 Host 헀더λ₯Ό μ‘°μž‘ν•˜μ—¬ μž¬μ„€μ • 링크λ₯Ό μ•…μ„± μ‚¬μ΄νŠΈλ‘œ μœ λ„ν•  수 μžˆμŠ΅λ‹ˆλ‹€. * **영ν–₯**: μž¬μ„€μ • 토큰이 κ³΅κ²©μžμ—κ²Œ μœ μΆœλ˜μ–΄ 계정 νƒˆμ·¨ κ°€λŠ₯μ„±. * **μ™„ν™” 쑰치**: * ν—ˆμš©λœ λ„λ©”μΈμ˜ ν™”μ΄νŠΈλ¦¬μŠ€νŠΈμ— λŒ€ν•΄ Host 헀더λ₯Ό κ²€μ¦ν•©λ‹ˆλ‹€. * μ ˆλŒ€ URL을 μƒμ„±ν•˜κΈ° μœ„ν•΄ μ•ˆμ „ν•œ μ„œλ²„ μΈ‘ 방법을 μ‚¬μš©ν•©λ‹ˆλ‹€. * **패치**: `$_SERVER['HTTP_HOST']` λŒ€μ‹  `$_SERVER['SERVER_NAME']`을 μ‚¬μš©ν•˜μ—¬ λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • URL을 κ΅¬μ„±ν•©λ‹ˆλ‹€. * **참고자료**: * [λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 쀑독에 λŒ€ν•œ Acunetix 기사](https://www.acunetix.com/blog/articles/password-reset-poisoning/) ## **이메일 λ§€κ°œλ³€μˆ˜ μ‘°μž‘μ„ ν†΅ν•œ λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ •** κ³΅κ²©μžλŠ” μΆ”κ°€ 이메일 λ§€κ°œλ³€μˆ˜λ₯Ό μΆ”κ°€ν•˜μ—¬ λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • μš”μ²­μ„ μ‘°μž‘ν•  수 μžˆμŠ΅λ‹ˆλ‹€. * 곡격자 이메일을 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ μΆ”κ°€ν•˜μ—¬ & ```php POST /resetPassword [...] email=victim@email.com&email=attacker@email.com ``` * 곡격자 이메일을 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ %20을 μ‚¬μš©ν•˜μ—¬ μΆ”κ°€ν•©λ‹ˆλ‹€. ```php POST /resetPassword [...] email=victim@email.com%20email=attacker@email.com ``` * 곡격자 이메일을 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ μΆ”κ°€ν•˜μ—¬ | ```php POST /resetPassword [...] email=victim@email.com|email=attacker@email.com ``` * ccλ₯Ό μ‚¬μš©ν•˜μ—¬ 곡격자 이메일을 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ μΆ”κ°€ν•©λ‹ˆλ‹€. ```php POST /resetPassword [...] email="victim@mail.tld%0a%0dcc:attacker@mail.tld" ``` * bccλ₯Ό μ‚¬μš©ν•˜μ—¬ 곡격자 이메일을 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ μΆ”κ°€ν•©λ‹ˆλ‹€. ```php POST /resetPassword [...] email="victim@mail.tld%0a%0dbcc:attacker@mail.tld" ``` * 곡격자 이메일을 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ μΆ”κ°€ν•˜μ—¬ , ```php POST /resetPassword [...] email="victim@mail.tld",email="attacker@mail.tld" ``` * 곡격자 이메일을 JSON λ°°μ—΄μ˜ 두 번째 λ§€κ°œλ³€μˆ˜λ‘œ μΆ”κ°€ν•˜μ‹­μ‹œμ˜€. ```php POST /resetPassword [...] {"email":["victim@mail.tld","atracker@mail.tld"]} ``` * **μ™„ν™” 단계**: * 이메일 λ§€κ°œλ³€μˆ˜λ₯Ό μ„œλ²„ μΈ‘μ—μ„œ 적절히 νŒŒμ‹±ν•˜κ³  κ²€μ¦ν•©λ‹ˆλ‹€. * μ£Όμž… 곡격을 λ°©μ§€ν•˜κΈ° μœ„ν•΄ μ€€λΉ„λœ λ¬Έμ΄λ‚˜ λ§€κ°œλ³€μˆ˜ν™”λœ 쿼리λ₯Ό μ‚¬μš©ν•©λ‹ˆλ‹€. * **μ°Έμ‘°**: * [https://medium.com/@0xankush/readme-com-account-takeover-bugbounty-fulldisclosure-a36ddbe915be](https://medium.com/@0xankush/readme-com-account-takeover-bugbounty-fulldisclosure-a36ddbe915be) * [https://ninadmathpati.com/2019/08/17/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty/](https://ninadmathpati.com/2019/08/17/how-i-was-able-to-earn-1000-with-just-10-minutes-of-bug-bounty/) * [https://twitter.com/HusseiN98D/status/1254888748216655872](https://twitter.com/HusseiN98D/status/1254888748216655872) ## **API λ§€κ°œλ³€μˆ˜λ₯Ό ν†΅ν•œ μ‚¬μš©μž 이메일 및 λΉ„λ°€λ²ˆν˜Έ λ³€κ²½** * κ³΅κ²©μžλŠ” API μš”μ²­μ—μ„œ 이메일 및 λΉ„λ°€λ²ˆν˜Έ λ§€κ°œλ³€μˆ˜λ₯Ό μˆ˜μ •ν•˜μ—¬ 계정 자격 증λͺ…을 λ³€κ²½ν•  수 μžˆμŠ΅λ‹ˆλ‹€. ```php POST /api/changepass [...] ("form": {"email":"victim@email.tld","password":"12345678"}) ``` * **μ™„ν™” 단계**: * μ—„κ²©ν•œ λ§€κ°œλ³€μˆ˜ 검증 및 인증 검사λ₯Ό 보μž₯ν•©λ‹ˆλ‹€. * μ˜μ‹¬μŠ€λŸ¬μš΄ ν™œλ™μ„ κ°μ§€ν•˜κ³  λŒ€μ‘ν•˜κΈ° μœ„ν•΄ κ°•λ ₯ν•œ λ‘œκΉ… 및 λͺ¨λ‹ˆν„°λ§μ„ κ΅¬ν˜„ν•©λ‹ˆλ‹€. * **μ°Έμ‘°**: * [API λ§€κ°œλ³€μˆ˜ μ‘°μž‘μ„ ν†΅ν•œ 전체 계정 νƒˆμ·¨](https://medium.com/@adeshkolte/full-account-takeover-changing-email-and-password-of-any-user-through-api-parameters-3d527ab27240) ## **λΉ„μœ¨ μ œν•œ μ—†μŒ: 이메일 폭탄 곡격** * λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • μš”μ²­μ— λŒ€ν•œ λΉ„μœ¨ μ œν•œμ΄ μ—†μœΌλ©΄ 이메일 폭탄 곡격이 λ°œμƒν•˜μ—¬ μ‚¬μš©μžκ°€ μž¬μ„€μ • μ΄λ©”μΌλ‘œ 압도될 수 μžˆμŠ΅λ‹ˆλ‹€. * **μ™„ν™” 단계**: * IP μ£Όμ†Œ λ˜λŠ” μ‚¬μš©μž 계정을 기반으둜 λΉ„μœ¨ μ œν•œμ„ κ΅¬ν˜„ν•©λ‹ˆλ‹€. * μžλ™ν™”λœ λ‚¨μš©μ„ λ°©μ§€ν•˜κΈ° μœ„ν•΄ CAPTCHA μ±Œλ¦°μ§€λ₯Ό μ‚¬μš©ν•©λ‹ˆλ‹€. * **μ°Έμ‘°**: * [HackerOne λ³΄κ³ μ„œ 280534](https://hackerone.com/reports/280534) ## **λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰 생성 방법 μ•Œμ•„λ‚΄κΈ°** * 토큰 μƒμ„±μ˜ νŒ¨ν„΄μ΄λ‚˜ 방법을 μ΄ν•΄ν•˜λ©΄ 토큰을 μ˜ˆμΈ‘ν•˜κ±°λ‚˜ 무차별 λŒ€μž…ν•  수 μžˆμŠ΅λ‹ˆλ‹€. λͺ‡ 가지 μ˜΅μ…˜: * νƒ€μž„μŠ€νƒ¬ν”„ 기반 * μ‚¬μš©μž ID 기반 * μ‚¬μš©μž 이메일 기반 * 이름 및 μ„± 기반 * 생년월일 기반 * μ•”ν˜Έν•™ 기반 * **μ™„ν™” 단계**: * 토큰 생성을 μœ„ν•΄ κ°•λ ₯ν•œ μ•”ν˜Έν™” 방법을 μ‚¬μš©ν•©λ‹ˆλ‹€. * 예츑 κ°€λŠ₯성을 λ°©μ§€ν•˜κΈ° μœ„ν•΄ μΆ©λΆ„ν•œ λ¬΄μž‘μœ„μ„±κ³Ό 길이λ₯Ό 보μž₯ν•©λ‹ˆλ‹€. * **도ꡬ**: Burp Sequencerλ₯Ό μ‚¬μš©ν•˜μ—¬ ν† ν°μ˜ λ¬΄μž‘μœ„μ„±μ„ λΆ„μ„ν•©λ‹ˆλ‹€. ## **μΆ”μΈ‘ κ°€λŠ₯ν•œ UUID** * UUID(버전 1)κ°€ μΆ”μΈ‘ κ°€λŠ₯ν•˜κ±°λ‚˜ 예츑 κ°€λŠ₯ν•˜λ©΄ κ³΅κ²©μžκ°€ 이λ₯Ό 무차별 λŒ€μž…ν•˜μ—¬ μœ νš¨ν•œ μž¬μ„€μ • 토큰을 생성할 수 μžˆμŠ΅λ‹ˆλ‹€. ν™•μΈν•˜μ‹­μ‹œμ˜€: {% content-ref url="uuid-insecurities.md" %} [uuid-insecurities.md](uuid-insecurities.md) {% endcontent-ref %} * **μ™„ν™” 단계**: * λ¬΄μž‘μœ„μ„±μ„ μœ„ν•΄ GUID 버전 4λ₯Ό μ‚¬μš©ν•˜κ±°λ‚˜ λ‹€λ₯Έ 버전에 λŒ€ν•œ μΆ”κ°€ λ³΄μ•ˆ 쑰치λ₯Ό κ΅¬ν˜„ν•©λ‹ˆλ‹€. * **도ꡬ**: [guidtool](https://github.com/intruder-io/guidtool)을 μ‚¬μš©ν•˜μ—¬ GUIDλ₯Ό λΆ„μ„ν•˜κ³  μƒμ„±ν•©λ‹ˆλ‹€. ## **응닡 μ‘°μž‘: λ‚˜μœ 응닡을 쒋은 μ‘λ‹΅μœΌλ‘œ κ΅μ²΄ν•˜κΈ°** * 였λ₯˜ λ©”μ‹œμ§€λ‚˜ μ œν•œμ„ μš°νšŒν•˜κΈ° μœ„ν•΄ HTTP 응닡을 μ‘°μž‘ν•©λ‹ˆλ‹€. * **μ™„ν™” 단계**: * 응닡 무결성을 보μž₯ν•˜κΈ° μœ„ν•΄ μ„œλ²„ μΈ‘ 검사λ₯Ό κ΅¬ν˜„ν•©λ‹ˆλ‹€. * μ€‘κ°„μž 곡격을 λ°©μ§€ν•˜κΈ° μœ„ν•΄ HTTPS와 같은 μ•ˆμ „ν•œ 톡신 채널을 μ‚¬μš©ν•©λ‹ˆλ‹€. * **μ°Έμ‘°**: * [라이브 버그 λ°”μš΄ν‹° 이벀트의 치λͺ…적인 버그](https://medium.com/@innocenthacker/how-i-found-the-most-critical-bug-in-live-bug-bounty-event-7a88b3aa97b3) ## **만료된 토큰 μ‚¬μš©** * 만료된 토큰이 μ—¬μ „νžˆ λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ •μ— μ‚¬μš©λ  수 μžˆλŠ”μ§€ ν…ŒμŠ€νŠΈν•©λ‹ˆλ‹€. * **μ™„ν™” 단계**: * μ—„κ²©ν•œ 토큰 만료 정책을 κ΅¬ν˜„ν•˜κ³  μ„œλ²„ μΈ‘μ—μ„œ 토큰 만료λ₯Ό κ²€μ¦ν•©λ‹ˆλ‹€. ## **무차별 λŒ€μž… λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • 토큰** * Burpsuite 및 IP-Rotator와 같은 도ꡬλ₯Ό μ‚¬μš©ν•˜μ—¬ μž¬μ„€μ • 토큰을 무차별 λŒ€μž…ν•˜λ €κ³  μ‹œλ„ν•˜μ—¬ IP 기반 λΉ„μœ¨ μ œν•œμ„ μš°νšŒν•©λ‹ˆλ‹€. * **μ™„ν™” 단계**: * κ°•λ ₯ν•œ λΉ„μœ¨ μ œν•œ 및 계정 잠금 λ©”μ»€λ‹ˆμ¦˜μ„ κ΅¬ν˜„ν•©λ‹ˆλ‹€. * 무차별 λŒ€μž… 곡격을 λ‚˜νƒ€λ‚΄λŠ” μ˜μ‹¬μŠ€λŸ¬μš΄ ν™œλ™μ„ λͺ¨λ‹ˆν„°λ§ν•©λ‹ˆλ‹€. ## **토큰 μ‚¬μš© μ‹œλ„** * 곡격자의 μž¬μ„€μ • 토큰이 ν”Όν•΄μžμ˜ 이메일과 ν•¨κ»˜ μ‚¬μš©λ  수 μžˆλŠ”μ§€ ν…ŒμŠ€νŠΈν•©λ‹ˆλ‹€. * **μ™„ν™” 단계**: * 토큰이 μ‚¬μš©μž μ„Έμ…˜ λ˜λŠ” 기타 μ‚¬μš©μž νŠΉμ • 속성에 λ°”μΈλ”©λ˜λ„λ‘ 보μž₯ν•©λ‹ˆλ‹€. ## **λ‘œκ·Έμ•„μ›ƒ/λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • μ‹œ μ„Έμ…˜ λ¬΄νš¨ν™”** * μ‚¬μš©μžκ°€ λ‘œκ·Έμ•„μ›ƒν•˜κ±°λ‚˜ λΉ„λ°€λ²ˆν˜Έλ₯Ό μž¬μ„€μ •ν•  λ•Œ μ„Έμ…˜μ΄ λ¬΄νš¨ν™”λ˜λ„λ‘ 보μž₯ν•©λ‹ˆλ‹€. * **μ™„ν™” 단계**: * μ μ ˆν•œ μ„Έμ…˜ 관리λ₯Ό κ΅¬ν˜„ν•˜μ—¬ λ‘œκ·Έμ•„μ›ƒ λ˜λŠ” λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • μ‹œ λͺ¨λ“  μ„Έμ…˜μ΄ λ¬΄νš¨ν™”λ˜λ„λ‘ ν•©λ‹ˆλ‹€. ## **λ‘œκ·Έμ•„μ›ƒ/λΉ„λ°€λ²ˆν˜Έ μž¬μ„€μ • μ‹œ μ„Έμ…˜ λ¬΄νš¨ν™”** * μž¬μ„€μ • 토큰은 만료 μ‹œκ°„μ΄ μžˆμ–΄μ•Ό ν•˜λ©°, κ·Έ μ΄ν›„μ—λŠ” λ¬΄νš¨κ°€ λ©λ‹ˆλ‹€. * **μ™„ν™” 단계**: * μž¬μ„€μ • 토큰에 λŒ€ν•΄ 합리적인 만료 μ‹œκ°„μ„ μ„€μ •ν•˜κ³  이λ₯Ό μ„œλ²„ μΈ‘μ—μ„œ μ—„κ²©νžˆ μ‹œν–‰ν•©λ‹ˆλ‹€. ## μ°Έμ‘° * [https://anugrahsr.github.io/posts/10-Password-reset-flaws/#10-try-using-your-token](https://anugrahsr.github.io/posts/10-Password-reset-flaws/#10-try-using-your-token)
κ²½ν—˜μ΄ ν’λΆ€ν•œ 해컀 및 버그 λ°”μš΄ν‹° ν—Œν„°μ™€ μ†Œν†΅ν•˜κΈ° μœ„ν•΄ [**HackenProof Discord**](https://discord.com/invite/N3FrSbmwdy) μ„œλ²„μ— μ°Έμ—¬ν•˜μ„Έμš”! **ν•΄ν‚Ή 톡찰λ ₯**\ ν•΄ν‚Ήμ˜ 슀릴과 도전에 λŒ€ν•œ λ‚΄μš©μ„ νƒκ΅¬ν•˜μ„Έμš”. **μ‹€μ‹œκ°„ ν•΄ν‚Ή λ‰΄μŠ€**\ μ‹€μ‹œκ°„ λ‰΄μŠ€μ™€ 톡찰λ ₯을 톡해 λΉ λ₯΄κ²Œ λ³€ν™”ν•˜λŠ” ν•΄ν‚Ή 세계λ₯Ό μ΅œμ‹  μƒνƒœλ‘œ μœ μ§€ν•˜μ„Έμš”. **μ΅œμ‹  λ°œν‘œ**\ μƒˆλ‘œμš΄ 버그 λ°”μš΄ν‹° μΆœμ‹œ 및 μ€‘μš”ν•œ ν”Œλž«νΌ μ—…λ°μ΄νŠΈμ— λŒ€ν•œ 정보λ₯Ό μœ μ§€ν•˜μ„Έμš”. 였늘 [**Discord**](https://discord.com/invite/N3FrSbmwdy)에 μ°Έμ—¬ν•˜μ—¬ 졜고의 해컀듀과 ν˜‘μ—…μ„ μ‹œμž‘ν•˜μ„Έμš”! {% hint style="success" %} AWS ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ GCP ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
HackTricks μ§€μ›ν•˜κΈ° * [**ꡬ독 κ³„νš**](https://github.com/sponsors/carlospolop)을 ν™•μΈν•˜μ„Έμš”! * πŸ’¬ [**Discord κ·Έλ£Ή**](https://discord.gg/hRep4RUj7f) λ˜λŠ” [**ν…”λ ˆκ·Έλž¨ κ·Έλ£Ή**](https://t.me/peass)에 μ°Έμ—¬ν•˜κ±°λ‚˜ **Twitter** 🐦 [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**λ₯Ό νŒ”λ‘œμš°ν•˜μ„Έμš”.** * [**HackTricks**](https://github.com/carlospolop/hacktricks) 및 [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) κΉƒν—ˆλΈŒ 리포지토리에 PR을 μ œμΆœν•˜μ—¬ ν•΄ν‚Ή νŒμ„ κ³΅μœ ν•˜μ„Έμš”.
{% endhint %}