1581, 1/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   bugfixer2
   ;cat À» »ç¿ëÇÏ´Â ÀÌÀ¯ .

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=732 [º¹»ç]


°á·ÐÀº , '|' ¶§¹®¿¡ ;cat À» ºÙ¿©¾ß¸¸ µÇ´Â °Ì´Ï´Ù.

¤¡) (  A ¸í·É  ) | ./attackme   ÀÌ·± ÀÔ·ÂÀ» Çß´Ù¸é.

(perl -e 'print "\x32\xff\xff\xbf . . ..";cat)|./attackme ¶ó´Â ¿¹¸¦ µéÁÒ.

¤¡) °ú °°Àº ¹æ¹ýÀ» ÅëÇؼ­..

ÀÎÀÚÀü´Þ ¹æ½ÄÀÌ ¾Æ´Ñ, Ç¥ÁØÀÔ·Â(Å°º¸µå)À» ÅëÇØ µû·Î ÀÔ·ÂÀ» ¹Þ´Â

attackme ÇÁ·Î±×·¥ °°Àº °æ¿ì¶óµµ  '|' À» ÅëÇØ º¯¼ö¿¡ ³»°¡ ¿øÇÏ´Â °ªÀ» ³Ö¾î¼­

¿À¹öÇ÷ο츦 ½Ãų¼ö´Â ÀÖ¾úÁö¸¸.

attackme ÀÇ ÄÚµå Áß¿¡ system("/bin/sh") ¿¡ ÀÇÇØ »ý¼ºµÇ´Â ÇÁ·Î¼¼½º ¶ÇÇÑ

| ±âÁØÀ» ¿ÞÂÊ¿¡ ÀÖ´Â. ´Ù½Ã¸»Çؼ­ ( A ) ÀÚ¸®ÀÇ ÇÁ·Î¼¼½ºÀÇ Ç¥ÁØ Ãâ·Â ³»¿ëÀ»  

ÀԷ¹ÞÀ¸·Á°í Çϴ°ÅÁÒ..


*¿ø·¡ ½©(/bin/sh) ´Â ÇÁ·ÒÇÁÆ® $ ¸¦ ¶ç¿ì°í Ç¥ÁØÀÔ·Â(Å°º¸µå) ·ÎºÎÅÍ
ÀÔ·ÂÀ» ±â´Ù¸®´Â °ÍÀÌÁö¸¸...  À§ÀÇ °æ¿ì¿¡´Â | ¶§¹®¿¡
Å°º¸µå ´ë½Å ( A ) ÀÚ¸®ÀÇ ÇÁ·Î¼¼½ºÀÇ Ç¥ÁØÃâ·Â ³»¿ëÀ»
ÀԷ¹ÞÀ¸·Á ÇÑ´Ù´Â °ÅÁÒ..


Çåµ¥, ( A )ÀÚ¸®¿¡ ÀÖ´ø ÇÁ·Î¼¼½º°¡ Á¾·áµÇ¸é ´õÀÌ»ó ÀԷ¹ÞÀ» ³»¿ëÀÌ ¾ø±â ¶§¹®¿¡ Á¾·á µË´Ï´Ù.

µû¶ó¼­ ,ÆÄÀÌÇÁ ¿¬°áÀ» Áö¼ÓÀûÀ¸·Î À¯Áö½ÃÅ°±â À§Çؼ­

cat À» Çϳª ´õ Áý¾î³Ö¾î¼­ °è¼ÓÀûÀ¸·Î ( A ) ÀÚ¸®¿¡¼­ Ç¥ÁØÃâ·ÂÀ» ½Ãų¼ö ÀÖµµ·Ï

¸¸µé¾î Áִ°ÅÁÒ.. ±×°Ô ¹Ù·Î ;cat ÀÇ ¿ªÇÒ ÀÔ´Ï´Ù.


±×¸²À¸·Î ³ªÅ¸³»¾î º¸ÀÚ¸é..

perl  ===================    attackme (fget( ); ÆÄÀÌÇÁ·Î ³Ñ¾î¿Â°É ¹Þ°ÚÁÒ.)
|       ( ÆÄÀÌÇÁ )             |
|                              |
Ãâ·Â¸¶Ä¡°í Á¾·á.           system("/bin/sh"); ¶§¹®¿¡ ½© ÇÁ·Î¼¼½º ½ÇÇà.
                                |
(X¾øÀ½.) =  =   =  =  = =  =    {»õ·Î¿î ½©}
          (¿¬°á²÷±è)              => ÀÌ ½©Àº Ç¥ÁØÀÔ·Â(Å°º¸µå) ´ë½Å¿¡
                                  ÆÄÀÌÇÁ¸¦ ÅëÇØ ÀÔ·ÂÀ» ¹ÞÀ¸·ÁÇÑ´Ù.
                                  ÇÏÁö¸¸, perlÀº Á¾·áµÇ°í, ´õÀÌ»ó
                                  ÀԷ¹ÞÀ»°ªÀÌ ¾øÀ¸¹Ç·Î, terminateµÈ´Ù.

±×·¡¼­...  ( ) ºÎºÐ¿¡ ;cat À»³Ö°Ô µÇ¸é.

perl  ===================    attackme (fget();)
|       ( ÆÄÀÌÇÁ )             |
|                              |
Ãâ·Â¸¶Ä¡°í Á¾·á.           system("/bin/sh"); ¶§¹®¿¡ ½© ÇÁ·Î¼¼½º ½ÇÇà.
|                              |
cat   ====================  {»õ·Î¿î ½©}

;cat ¶§¹®¿¡
cat½ÇÇàµÇ°í Å°º¸µå·ÎºÎÅÍ ÀԷ±â´Ù¸®¸é¼­
ÀԷ¹ÞÀº³»¿ëÀ» Ç¥ÁØÃâ·ÂÀ¸·Î
º¸³»°í , ÀÌ°ÍÀº ÆÄÀÌÇÁ¸¦ µû¶ó ÀüÇØÁý´Ï´Ù.



Âü°í·Î..

(perl -e ' ';cat)|./attackme   ÀÌ·± ÇüŸ¦ µð¹ö±ëÇÏ·Á¸é

perl -e '...') > arg   ¸í·ÉÀ¸·Î Ãâ·Â³»¿ëÀ» ÆÄÀÏ¿¡´Ù ÀúÀåÇÑ´ÙÀ½

(gdb) r < ./arg  ÇÏ¸é µË´Ï´Ù.

µµ¿òÁֽŠIDNED ´Ô °¨»çÇÕ´Ï´Ù.¤¾

  Hit : 10525     Date : 2007/05/18 09:57



    
pinode ¦¦¦ 2007/08/12  
¼Ò¿ï ¦¦¦(2) 2010/05/04  
3rdlifer ¿À¿À ´ë¹Ú ¤£¤£¿ä 2012/01/09  
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 18751
1580   °í¼ö´ÔµéÀÇ µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù     vbnm111
02/11 200
1579   ¸®´ª½º Ä¿³Î 2.6 ¹öÀü ÀÌÈÄÀÇ LKM     jdo
07/25 705
1578   ½©ÄÚµå ¸ðÀ½     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 1532
1577   Call by value VS Call by Reference     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 911
1576   (²Ä¼ö) L.O.B Çѹ濡 Ŭ¸®¾îÇϱâ[2]     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 1253
1575   towelroot.c (zip) ÄÚ¸àÆÃ.[1]     scube
08/18 3773
1574   levitator.c (¾Èµå·ÎÀÌµå ·çÆÃ) °ø°Ý ºÐ¼® ¼Ò½º ÄÚµå °øÀ¯.[4]     scube
08/17 3685
1573   ¹«·á Á¤º¸º¸¾È ±â¼úÀÎÀç ¾ç¼º °úÁ¤ ±³À°»ý ¸ðÁý     chanjung111
06/17 4481
1572   K-Shield ÁִϾî 5±â ¸ðÁý     lrtk
06/17 4213
1571   [ÆÁ] ÆÄÀ̽ã 2¼Ò½º¸¦ 3À¸·Î º¯°æÇØÁÖ´Â »çÀÌÆ®[3]     ÇѽÂÀç
05/13 3924
1570   ±¸±Û ¹é¸µÅ© ÀÛ¾÷ Áú¹®¿ä     wkatnxka
03/30 3355
1569   [ÆÁ] ¿ìºÐÅõ ¹Ì·¯¸µ¼­¹ö     ÇѽÂÀç
03/09 4053
1568 ºñ¹Ð±ÛÀÔ´Ï´Ù  °¨À»¸øÀâ°Ú³×¿ä¤Ì¤Ì     À×À×À×
01/15 3
1567   µ¥ºñ¾È °è¿­ ¸®´ª½º ÀÇÁ¸¼º ±úÁ³À»¶§ ÇØ°á¹ý     ÇѽÂÀç
11/27 4528
1566   È«º¸ÇÕ´Ï´Ù. ½Å»ý º¸¾ÈÄ¿¹Â´ÏƼÀÔ´Ï´Ù.     kimwoojin0952
10/26 4262
1565   ½Å±âÇÑ ÇÁ·Î±×·¡¹Ö ¾ð¾î[3]     koreal33t
09/06 4652
1564   À©µµ¿ì,¸®´ª½º¿¡¼­ ³» ip¸¦ È®ÀÎÇØ º¸ÀÚ [1]     koreal33t
09/06 3854
1563   CTF »çÀÌÆ®[1]     koreal33t
09/06 4516
1562   ÀÚ°ÝÁõ (¹®Á¦)»çÀÌÆ® [2]     koreal33t
09/06 4332
1 [2][3][4][5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org