1586, 20/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ssuckies
   http://www.ganseo.com
   format stringÀ» À§ÇÑ ¸®ÅϾîµå·¹½º ±¸Çϱâ.

http://www.hackerschool.org/HS_Boards/zboard.php?desc=desc&no=162 [º¹»ç]


±×³É Áú¹®ÀÌ ¿Ô±æ·¡ ½áºÃ½À´Ï´Ù.
Ʋ¸°ºÎºÐÀÖÀ»Áö ¸ð¸£³ª °øÀ¯Â÷¿ø¿¡¼­...^^

Produced by ganseo
e-mail : postmaster@ganseo.com
homepage : http://www.ganseo.com


[Æ÷¸ä½ºÆ®¸µÀ» À§ÇÑ ¸®ÅϾîµå·¹½º ã±â]
1.mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º ÁÖ¼Òã±â.
2.printfÀÇ .got ÁÖ¼Òã±â.
3. .dtorsÀÇ ÁÖ¼Òã±â.

ÀÏ´Ü ÀÌ ÀÌ °­Á¿¡´Â ¸¹Àº ¼³¸í¾øÀÌ ½ÇÁ¦ ã´Â ¹æ¹ý¸¸ ¼³¸íÇØ µå¸®µµ·ÏÇÏ°Ú½À´Ï´Ù.

1.mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º ÁÖ¼Òã±â.
óÀ½ ¸ÞÀÎ ÇÔ¼ö¿¡ µé¾î°¡°Ô µÇ¸é ¸Þ¸ð¸® ±¸Á¶´Â ÀÌ·¸°Ô µË´Ï´Ù.

------------------------------------- low
º¯¼ö
------------------------------------- ebp
Saved frame pointer
-------------------------------------
retern address
------------------------------------- high

óÀ½ ¸ÞÀÎÇÔ¼ö°¡ µé¾î°¡´Â ºÎºÐ¿¡ ºê·¹ÀÌÅ© Æ÷ÀÎÆ®¸¦ °Ì´Ï´Ù.
±×·± ´ÙÀ½ ebpÀÇ ÁÖ¼Ò¸¦ ¾Ë¾Æº¾´Ï´Ù.
(gdb) x/16 $ebp              <-- ebp¸¦ 16°³ º¸¿©Áִµ¥..
0xbffff278:     0xbffff298      0x40038917      0x00000001      0xbffff2c4
0xbffff288:     0xbffff2cc      0x4001582c      0x00000001      0x080483b0
0xbffff298:     0x00000000      0x080483d1      0x08048458      0x00000001
0xbffff2a8:     0xbffff2c4      0x08048308      0x080484cc      0x4000c660
(gdb)
ÀÌ·±½ÄÀ¸·Î ³ªÅ¸³µ´Ù°í »ý°¢ÇØ º¾´Ï´Ù.
ebp´Â 0xbffff278ÀÔ´Ï´Ù.
¿äÁò ÄÄÆÄÀÏ·¯¿¡ µû¶ó ´Ù¸£°ÚÁö¸¸ º¸ÅëÀº ÀÌ·²°æ¿ì¿¡ 0xbffff27c¿¡¼­ 16¹ÙÀÌÆ® ´ÜÀ§·Î +,-ÇØÁÝ´Ï´Ù.
0xbffff24c , 0xbffff25c , 0xbffff26c , 0xbffff27c , 0xbffff28c , 0xbffff29c , 0xbffff2ac , 0xbffff2bc
ÀÌÁß¿¡ Çϳª°¡ mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º°¡ µË´Ï´Ù.

2.printfÇÔ¼öÀÇ .got ÁÖ¼Òã±â.
objdump¸¦ ÀÌ¿ëÇؼ­ ±¸ÇÒ¼ö ÀÖ½À´Ï´Ù.
objdump -R ./recluse5 | grep printf
080495cc R_386_JUMP_SLOT printf

ÀÌ°ÍÀ¸·Î printfÀÇ .got ÁÖ¼Ò´Â 080495ccÀÔ´Ï´Ù.

gdb¸¦ ÀÌ¿ëÇؼ­µµ ±¸ÇÒ¼ö ÀÖ½À´Ï´Ù.
disass printfÇϼż­ ±¸Çغ¸½Ç¼ö ÀÖ½À´Ï´Ù.

3. .dtorsÀÇ ÁÖ¼Òã±â.
ÀÌ°Í ¿ª½Ã objdump¸¦ ÀÌ¿ëÇؼ­ ±¸ÇÒ¼ö ÀÖ½À´Ï´Ù.
objdump -h ./recluse5 | grep .dtors
17 .dtors        00000008  080495a8  080495a8  000005a8  2**2
ÀÌ°ÍÀ¸·Î .dtorsÀÇ ÁÖ¼Ò´Â 080495a8ÀÔ´Ï´Ù.
.dtorsÀÇ ¼³¸íÀº ganseo.comÀÇ ÇØÅ· ±âÃÊÇй®¿¡ ÀÚ·á ÀÖ½À´Ï´Ù.

mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º¸¦ ±¸Çغ¸´Â°Ô ÁÁÀ¸½Ç°Í °°½À´Ï´Ù.

  Hit : 10850     Date : 2004/02/08 08:22



    
sjh21a ÀÌ°ÍÀ¸·Î printfÀÇ ¸®ÅϾîµå·¹½º ÁÖ¼Ò´Â 080495ccÀÔ´Ï´Ù. .got ¿µ¿ª¾Æ´Ñ°¡¿ä..? globl offset table..~ °£¼­´Ô ÁÁÀº ¹®Á¦ ¾ðÁ¦³ª°¨»çÇÏ°í ÀÖ½À´Ï´Ù ^^ 2004/02/12  
ssuckies ¼öÁ¤Çß½À´Ï´Ù.^^ °¨»çÇÕ´Ï´Ù^^ 2004/02/12  
1206   [ÀÚÀÛ] ¹ÙÀÌ·¯½º/Æ®·ÎÀ̸ñ¸¶ ÇÁ·Î¼¼½º°¡ ÀÛ¾÷ °ü¸®ÀÚ È¤Àº tskill, taskkill ¿¡ ÀÇÇØ ²¨ÁöÁö ¾Ê´Â °æ¿ì[1]     TeamDeveloper
04/17 6372
1205   [ÀÚÀÛ teachercyber] µµ¸ÞÀÎÁÖ¼Ò·Î »ó´ë¹æ IPã±â(nslookup)[12]     teachercyber
07/30 8225
1204   [ÀÚÀÛ teachercyber] java¿¡¼­ Garbage Collection À̶õ?[2]     teachercyber
07/30 6241
1203   C¾ð¾î °­Á     te04041
11/23 9770
1202   ¹öÆÛ¿À¹öÇÃ·Î¿ì ¹è¿ì±â 2[1]     sysopp2002
02/21 6883
1201   ¹öÆÛ¿À¹öÇÃ·Î¿ì ¹è¿ì±â 1      sysopp2002
02/21 7370
1200     [re] sql ÀÎÁ§¼Ç º¹±¸Äõ¸®     subroutine
01/11 8028
1199   sql ÀÎÁ§¼Ç °ø°Ý±â¹ý[4]     subroutine
01/11 19207
1198   [Æß]ÇØÄ¿µéÀÇ ÈçÀûÁö¿ì´Â¹æ¹ý[28]     starztp
10/08 12586
1197   [Reverse Engineering in StarCraft] (1) ½ºÅ¸Å©·¡ÇÁÆ®³»ÀÇ TEXT¸¦ ¹Ù²ãº¸ÀÚ.[5]     stares
12/12 7296
1196   alsduddlrk12@hanmir.com ÇØÅ·°¡¸£ÃÄÁÖ½Ç ½º½ÂºÐ±¸ÇÕ´Ï´Ù...[6]     st9203
02/05 6238
1195   BOF ÇØ°á ¹«ÀÛÁ¤ µû¶óÇϱâ #2     ssuckies
04/12 10180
1194   BOF ÇØ°á ¹«ÀÛÁ¤ µû¶óÇϱâ #1[7]     ssuckies
04/12 14701
1193   ±×³àÀÇ Vulnerabilities¿¡ µû¸¥ Remote/local one night stand exploit.[2]     ssuckies
03/29 10341
  format stringÀ» À§ÇÑ ¸®ÅϾîµå·¹½º ±¸Çϱâ.[2]     ssuckies
02/08 10849
1191   ³»°¡ »ý°¢ÇÏ´Â ¿Ã¹Ù¸¥ ÄÄÇ»ÅÍ °øºÎ.[20]     ssonacy
03/21 8558
1190   ¸®´ª½º ¸í·É¾î ÇѲ¨¹ø¿¡(¼ÒÀ¯´Ô²¨)[11]     ssakura
07/07 12297
1189   trainer[6]     sporagame123
04/16 8842
1188   Ȥ½Ã³ª À©7 ¾²½Ã´ÂºÐµé ÅÚ³ÝÀÌ ¾ÈµÉ¶§[1]     sotjs13
01/06 6259
1187   ÃÊÂ¥Àε¥ ¾îµð¼­ºÎÅÍ ½ÃÀÛÇϳı¸¿ä?[5]     sotjs13
01/04 7495
[1]..[11][12][13][14][15][16][17][18][19] 20 ..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org