¸®´ª½º

 3923, 1/197 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ewqqw
   setuid ¸¦ ÀÌ¿ëÇÑ ±ÇÇѾò±â ¼Ò½º

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_linux&no=4450 [º¹»ç]


Á¦ ±ÇÇÑÀº Á¦ÇѵŠÀÖ°í, run_me ¶ó´Â ÇÁ·Î±×·¥Àº setuid°¡ ¼³Á¤µÇ¾î À־ run_me ¶ó´Â ÇÁ·Î±×·¥ »ó¿¡¼­ flag(setuid·Î ½ÇÇàÇØ¾ß ÇÏ´Â ÆÄÀÏ)À» ¾Ë¾ÆºÁ¾ß Çϴµ¥¿ä....  È¯°æº¯¼ö°¡ ¸ðµÎ »èÁ¦µÇ°í, ¹ØÀÇ º¯¼ö¸¸ ³²Àº »óÅ¿¡¼­ ¾î¶»°Ô setuid¸¦ ±â¹ÝÀ¸·Î shellÀ» ½ÇÇàÇÒ ¼ö ÀÖÀ»±î¿ä?

./run_me /bin/sh Çϴϱñ ´ç¿¬È÷ ¹ØÀÇ ÇÊÅ͸µ¿¡ °É¸®´õ¶ó±¸¿ä...

µµ¿ÍÁÖ¼¼¿ä ¤Ð¤Ð


#include <stdio.h>
#include <string.h>

int filter(char *cmd) {
        if (strstr(cmd, "f")) return 1;
        if (strstr(cmd, "sh")) return 1;
        if (strstr(cmd, "tmp")) return 1;
        return 0;
}

extern char **environ;
int main(int argc, char *argv[], char *envp[]) {
        char **p;

        printf("I am king the Godzo...\n");
        printf("I will let you execute a command again.\n");
        printf("However, I am much stronger than Tracer.\n");

        for (p=environ; *p; p++)
                memset(*p, 0, strlen(*p));

        putenv("PATH=/uri_mercy_gaemotham");

        if (filter(argv[1])) {
                printf("caught by filter!\n");
                return 0;
        }

        system(argv[1]);
        return 0;
}

  Hit : 2865     Date : 2017/03/11 12:23



    
ewqqw ./½ÇÇàÆÄÀÏ "cd */;head *" Çϴϱñ Ç®·È½À´Ï´Ù.... ÇÏÇÏ

ÆÄÀÏÀÌ ¾Æ´Ï¶ó µð·ºÅ丮¿´³×¿ä... ±× ¾È¿¡ ¶Ç ÆÄÀÏÀÌ ÀÖ¾ú½À´Ï´Ù...
2017/03/12  
3923   ¸®´ª½º°¡ ¼³Ä¡µÈ ÆÄÀÏÀ» ±âÁ¸ ³»Àåssd¿¡¼­ ¿ÜÀåssd·Î ¿Å±â±â      wnddkdch2004
01/16 1447
3922   VM ȯ°æ¿¡¼­ GPU »ç¿ë¹ý¿¡ ´ëÇÑ Áú¹®[1]     wuzu22
07/19 1451
3921   ¸®´ª½º °øºÎ ¹æ¹ý, ±³Àç ÃßõÇØ ÁÖ¼¼¿ä.[1]     Haike0548
05/24 1654
3920   vmware Ä®¸®¸®´ª½º Áú¹®ÀÖ¾î¿ä![2]     EgoistYI
04/05 1747
3919   ftz trainer1 ¾ÏÈ£¿ä¤Ð[1]     keeyeon
04/02 1587
3918   FTZÁ¢¼Ó¹æ¹ý[2]     tkd115
01/13 2319
3917   ¸®´ª½º john the ripper´ëÇÑ Áú¹® Á» ÇÒ°Ô¿ä     cd1641
11/20 1590
3916   ftz ȯ°æ±¸Ãà ÇÏ·Á°í Çϴµ¥ °è¼Ó ¿À·ù°¡ ¹ß»ýÇÕ´Ï´Ù. [2]     poh1207
07/10 1606
3915     [re] ftz ȯ°æ±¸Ãà ÇÏ·Á°í Çϴµ¥ °è¼Ó ¿À·ù°¡ ¹ß»ýÇÕ´Ï´Ù.      kimwoojin0952
08/02 1379
3914   x11vnc ¼³Ä¡ÈÄ, À©µµ¿ì ¾ÈµÊ. ubuntu18.04.2 LTS     localid
04/23 2125
3913   ÆÄÀÏ µð½ºÅ©¸³ÅÍ[1]     turttle2s
02/10 1586
3912   DVWA»ç¿ëÈÄ ÆÄÀ̾îÆø½º°¡¾ÈµË´Ï´Ù[1]     wlzh1313
02/07 2010
3911   ¸®´ª½º ºÎÆÃUSB Áú¹®     iioks
12/29 1707
3910   dionaea honeypot Çغ¸½ÅºÐ °è½Å°¡¿ä?     teletubbies
07/05 2351
3909   ¸®´ª½º¿¡¼­ pupy¼³Ä¡ÇÒ¶§..     redfrog
05/07 2942
3908   bootable USB ¸¸µé¶§     krimson701
03/27 2277
3907   FTZ ·ÎÄÃȯ°æ ±¸ÃàÁú¹®[1]     krimson701
03/19 2852
3906   ÇÏµå ¸µÅ©¿Í ½Éº¼¸¯ ¸µÅ©     ka0r1
12/07 2151
3905   ¸®´ª½º [1]     jeffrey4127
11/26 1882
3904   ¸®´ª½º vmware ¼³Ä¡[2]     jeffrey4127
10/31 2746
1 [2][3][4][5][6][7][8][9][10]..[197]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org