97, 1/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   hrl733
   ¼¼³»±â°¡ Áú¹®Á»ÇÏ°Ù½À´Ï´Ù

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Reversing&no=51 [º¹»ç]


³× ÀÌÁ¦ ¾î¼Àºí¸®¾î¿Í ¸®¹ö½º¿£Áö´Ï¾î¸µ¿¡ È˹̸¦´À³¢¸ç ´«À»¶ß°ÔµÈ ¼¼³»±âÀÔ´Ï´Ù
´Ù¸§ÀÌ ¾Æ´Ï¶ó Á¦°øºÎ¹æ½ÄÀÌ µ¶ÇÐÀε¥ ±âº»»ó½ÄÃ¥ÀÐÁö¾Ê°í ¾î¼Àºí¸®¾î¼Ò½º¸¦ºÁ¼­ Çϳª¾¿Ç®¾î°¡¸é¼­ ¸ð¸£´Â°Ç ¹è¿ö°¡´Â ±×·±½ÄÀ¸·Î °øºÎÇϰŵç¿ä ±×·¡¼­ ´Ù¸§ÀÌ ¾Æ´Ï¶ó ±¸¹®ÀÌ ÀÌÇØ°¡ ¾ÈµÇ´ÂÁ¡µéÀÌ Àվ Áú¹®Çغ¾´Ï´Ù ¿¹¸¦µé¾î  

[enable]
registersymbol(Timer)
alloc(pu,256)
registersymbol(pu)
alloc(Timer,4)
//eip=  pu   º£À̽º=702C87
Timer:
dd 00
pu:  
cmp [Timer],2
jl 702c90
mov [Timer],0
jmp 702C89
[disable]
dealloc(pu)
unregistersymbol(pu)

ÀÌ·¸°Ô ÀÕÀ¸¸é Áú¹®À»Çغ¸°Ù½À´Ï´Ù (´Ü¾î µéÀº ¾Ë°í ÀÕ½À´Ï´Ù )
1.registersymbolÀֵ̿ΰ³ÁÒ?(À§¿¡´ÂŸÀ̸Ӱí¾Æ·¡´ÂǪÀε¥¿ÖµÎ°³Àΰ¡¿ä ÇÑ°³¸¸Àվ µÇ´Â°Å¾Æ´Ñ°¡¿ä)
2.allocÀÌ ¿Ö µÎ°³ÁÒ? (ù¹ø° alloc¿¡´Â ÀúµÎ°³°¡ eip°ªÀΰɾƴµ¥ ¾Æ·¡allocÀºÀÌÇØ°¡ °¡Áö¾Ê´Â±º¿ä )
3.±×¸®°í
Timer:
dd 00
pu:  
cmp [Timer],2
jl 702c90
mov [Timer],0
jmp 702C89

À̱¸¹®ÀÌ ±Ã±ÝÇÕ´Ï´Ù Àú°³ ¹«¾ùÀ»¶æÇÏ´ÂÁö ¼³¸íÇØÁֽǼöÀͫ塂 ´ÙÇØÁÖ½Ã¸é °¨»çÇÏ°Ù½À´Ï´Ù

  Hit : 2812     Date : 2012/11/06 01:04



    
housdd 1.timer¿Ípu´Â ¼­·Î Ʋ¸°ÇÔ¼öÀÔ´Ï´Ù.
°³º°ÀûÀ¸·Î ´ã±âÀ§Çؼ­ µû·Î¼±¾ðÇؼ­ µÎ°³¼±¾ðµÈ°ÍÀÔ´Ï´Ù.

2.allocµµ À§¿Í´äº¯ÀÌ ºñ½ÁÇÕ´Ï´Ù.
Áõ°¡¼ö°¡ Ʋ¸±»ÓÀÔ´Ï´Ù.

3. timer registerº¯¼ö¿¡
2¹ÙÀÌÆ®Ãâ·ÂÇÑ´Ù.
pu registerº¯¼ö¿¡
timerÀÇ º¯¼ö¿¡ °ªÀ»´ëÀÔÇؼ­ timerÀǺ¯¼ö¿¡°ªÀ»´õÇÏ°í
Á¡ÇÁ½ÃŲ´Ù 702C89
2012/12/16  
97   angr¿¡¼­ ½ºÅà ÁÖ¼Ò ±¸Çϱâ[3]     turttle2s
05/24 1752
96   ¾Æ½ºÅ° ¹üÀ§ ¹Û ÆäÀ̷εå Àü¼Û ½Ã, 0xc2°¡ ºÙ´Â Çö»ó[7]     turttle2s
05/11 1689
95   angr Áú¹®[2]     turttle2s
04/24 1753
94   ¸®¹ö½Ì Çٽɿø¸®¸¦ °øºÎÇÏ´Ù°¡ ¸·Çû½À´Ï´Ù.     aaasss445
06/12 2123
93   quickbms ÀÇ ¿ø¸®°¡ ±Ã±ÝÇÕ´Ï´Ù.     sa0814
05/10 1906
92   ÄݽºÅÿ¡ ¾Æ¹«°Íµµ ¾øÀ» °æ¿ì¿¡´Â ¾î¶»°Ô ÇؾßÇϳª¿ä..[2]     mij9929
01/14 1698
91   ollydbg 64bit ½ÇÇà ºÒ°¡ ¿Ö ÀÌ·±°ÅÁÒ? ¤Ð[4]     4ru4ka
04/24 3926
90   º¯¼ö ¼±¾ð½Ã ½ºÅÿ¡¼­ÀÇ À§Ä¡[5]     turttle2s
11/13 2114
89   Äڵ忣Áø Basic 02¿¡¼­     healer
04/08 2163
88   win32 api ¹× Áø·Î..?[2]     user0
02/26 3465
87   ¸Þ¸ð¸® ÁÖ¼Ò º¯°æ µÇ´Â ¹®Á¦¿¡ °üÇØ Áú¹®ÇÕ´Ï´Ù.[2]     jjunici
12/17 3481
86   ida¿¡¼­ ºÐ¼®ÇÒ ¶§,,,[3]     vngkv123
11/30 2320
85   ¸®¹ö½Ì-µð½º¾î¼Àºí¸®-µð¹ö°Å¿¡ ¹®ÀÇÁ»..     leonardo6
10/13 2530
84   dumpcode Çì´õÆÄÀÏ ¸»Àä..[1]     ys200209
07/20 2456
83   ¸®¹ö½Ì __security_cookie[3]     healer
07/17 3595
82   ´Ü¼ø ¸®¹ö½Ì °ü·Ã Áú¹®[8]     ewqqw
06/11 2957
81   elf ¹ÙÀ̳ʸ® ÆÐÄ¡ Áú¹®...[2]     vngkv123
06/07 3268
80   IDA hexray·Î º¸¾ÒÀ» ¶§...[2]     vngkv123
05/29 2797
79   µð½º¾î¼ÀºíµÈ ÄÚµåµé Áß¿¡¼­..[2]     vngkv123
05/14 2869
78   °ÔÀÓ º¸¾È (½ÎÀÎÄÚµå, X-Trap, °ÔÀÓ°¡µå) ºÐ¼® ¹ý·ü ±Ã±ÝÇÕ´Ï´Ù![4]     ¼È·Ï38
03/17 4016
1 [2][3][4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org