½Ã½ºÅÛ ÇØÅ·

 1574, 79/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   heeyoung0511
   ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?desc=desc&no=1999 [º¹»ç]


-Ãë¾à¼º ÀÖ´Â ÄÚµå-
#include <stdio.h>
#include <string.h>

void bar(char *last){
  char buf[48];
  strcpy(buf, last);
}
void foo(cahr *hard){
  int information =1;
  int protection =2;
  bar(hard);
}
int main (int argc, char *argv []){
  foo(argv[1]);
  return 0;
}

À§¸¦ Äڵ带 È°¿ëÇؼ­ ROP °ø°ÝÀ» ÇÏ°í ½Í¾î¿ä. ÄÄÆÄÀÏ ÇÒ¶§ ´õ¹Ì°ª¸¸ Á¦°ÅÇÏ°í SSP¿Í NXºñÆ®´Â ÇØÁ¦ ¾È ÇÑ »óÅÂÀÔ´Ï´Ù. ASLR È°¼ºÈ¸µÈ »óÅ¿¡¼­ ROP°ø°ÝÀ» ÇÏ°í ½Í½À´Ï´Ù.
payload¸¦ strcoy@plt+ppr+bssaddress+char(/bin/sh) ³Ö¾îÁÖ°í ¸¶Áö¸·¿¡ ½Ã½ºÅÛ ÁÖ¼Ò¿Í bssÁÖ¼Ò¸¦ ´Ù½Ã ³Ö¾îÁá´Âµ¥, °è¼Ó °ø°Ý¿¡ ½ÇÆÐÇÕ´Ï´Ù. Ȥ½Ã ½ÇÆпøÀÎÀ̳ª ÁÁÀº ¹æ¹ý ¾Ë ¼ö ÀÖÀ»±î¿ä???

  Hit : 1644     Date : 2021/06/16 10:52



    
turttle2s SSP ÇØÁ¦ ¾ÈÇϽŰŸé SSP °ªµµ ¸ÂÃçÁà¾ßÇØ¿ä. 2021/06/17  
heeyoung0511 Ȥ½Ã ¾î¶»°Ô ¸ÂÃß´Â Áö ¾Ë ¼ö ÀÖÀ»±î¿ä?
2021/06/17  
cd80 ¸Þ¸ð¸®¸¯À» ÇÏ°í ¸Þ¸ð¸®¸¯->ROPÇϴµ¿¾È Ä«³ª¸®°¡ ¾Èº¯ÇؾßÇϴµ¥ ±×·±Á¶°ÇÀ» ¸¸Á·½ÃÅ°±â ¾î·Á¿öº¸À̳׿ä SSP¸¦ ÇØÁ¦ÇÏ½Ã´Â°Ô ¸Â¾Æº¸ÀÔ´Ï´Ù 2021/06/17  
14   »ç±â[2]     jas08
03/31 2052
13   ÆÐŶ º¹È£È­¸¦ ¸¶½ºÅÍ ÇÏ·Á¸é ¾î¶² °úÁ¤ÀÌ ÀÖ¾î¾ßÇϳª¿ä?     sa0814
04/01 1758
12   dllÀÎÁ§¼Ç ½ÇÇèÁß Áú¹® µå¸³´Ï´Ù.[1]     kkk477
05/31 1914
11   Trainer3 ftz.hackerschool.org È£½ºÆ® Á¢¼Ó ºÒ°¡[1]     hyemin1826
07/18 3306
10   Level2 -> Level3 ¿¡¼­ vi¿Í /usr/bin/EditorÀÇ Â÷ÀÌ[2]     hyemin1826
07/18 1958
  ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     heeyoung0511
06/16 1643
8   pwnable.kr echo1 Áú¹®[2]     turttle2s
06/17 1826
7   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1561
6   ÇØÅ· ÇÁ¸®¼­¹ö ¾ø¾îÁ³³ª¿ä?[1]     terfkim
04/15 1818
5   ¸®¸ðÆ® ȯ°æ¿¡¼­ÀÇ ½ºÅà ÁÖ¼Ò È®ÀÎ ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù.[2]     lMaxl04
06/16 1009
4   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1244
3   libc°ü·Ã - 2[5]     lMaxl04
08/24 964
2   LOB GATE¹®Á¦ Ç®¸é¼­ ±Ã±ÝÇÑÁ¡[3]     hackxx123
08/24 1071
1   pwnable.kr echo1 Áú¹®2 (½ºÆ÷ ÁÖÀÇ)[2]     turttle2s
10/05 1363
[1]..[71][72][73][74][75][76][77][78] 79

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org