½Ã½ºÅÛ ÇØÅ·

 1574, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kumi123
   http://blog.naver.com/kumik12
   x86-64bit ½ºÅÿÀ¹öÇÃ·Î¿ì ¸·¸·Çϳ׿ä...¤Ð

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1733 [º¹»ç]


strcpy·Î °ø·«ÇÏ´Â ±âÁØ

Äڵ念¿ªÀº,

00 00 00 00 00 ?? ?? ??

ÀÌ·¸°Ô ÀâÈ÷°í,

¾Æ½ºÅ° ¾Æ¸Ó·Î, ¶óÀ̺귯¸®´Â

00 00 ?? ?? ?? ?? ?? ??

ÀÌ·± ÁּҴ븦 °¡Áö°í,

exec-shield ·Î ½ºÅðú Èü¿¡´Â ½©ÄÚµå ¿Ã·Á °ø°Ý ºÒ°¡´É..

rtl Àº 1¹øÀº °¡´ÉÇÏÁö¸¸, Çѹ濡 ¹Ù·Î °íÁ¤ÁÖ¼Ò°¡ ¾øÀ¸¸é ¾Æ¿ô, ±×°Íµµ ret sled´Â ºÒ°¡´É

Äڵ念¿ªÀ¸·ÎÀÇ rtlµµ ºÒ°¡´É.. 00 ÀÌ 1±º´ë°¡ ºÎÁ·Çؼ­ µ¤¾î¾²±â ºÒ°¡´É

got overwriteµµ ÇÔ¼ö¿µ¿ªÀÇ ÁÖ¼Ò°¡ Àú·¯´Ï ºÒ°¡´É..

ropµµ Äڵ念¿ªÀÇ ÁÖ¼Ò°¡ Àú·¯´Ï ºÒ°¡´É...

°á±¹, Çö½ÇÀûÀ¸·Î strcpy¸¦ ÀÌ¿ëÇÑ 64bit-¸®´ª½º ¿À¹öÇÃ·Î¿ì ¾îÅÃÀº ±×³É ´Ù ¸·Çû´Ù º¸¼Åµµ µÉ °Í °°½À´Ï´Ù..

±×·¡µµ, ¿ì¸®¿¡°Ô´Â ¾ÆÁ÷ ³»ºÎÀÔ·ÂÇÔ¼ö gets·ù°¡ Àֳ׿ä..

°ÑÀº 64bitÁö¸¸, °¡»ó¸Þ¸ð¸®´Â °è¼Ó 32bit ¾²±æ ºô¾î¾ß °Ú±º¿ä.. ¤Ð¤Ð

  Hit : 4650     Date : 2014/02/15 05:13



    
itchy ·ÎÄÃÀÏ°æ¿ì¿¡ ascii armor·Î ÀÎÇؼ­ rop°¡ ºÒ°¡´ÉÇϽôٸé virtual system call ¿µ¿ª¿¡¼­ ropÇÏ¿© °ø°Ý ÇÒ ¼ö ÀÖ½À´Ï´Ù. 2014/02/16  
kumi123 óÀ½µé¾î º¸³×¿ä?? ¹¹ÁÒ?? 2014/02/16  
itchy ¹ÙÀ̳ʸ®ÀÇ /proc/pid/maps ¸¦ È®ÀÎÇغ¸½Ã¸é vsyscall ¿µ¿ªÀÌ Á¸ÀçÇϴµ¥ ÀÌ ÆäÀÌÁö¿¡ rx±ÇÇÑÀÌ ÀÖ°í ÁÖ¼Ò ¶ÇÇÑ 0xffffffffff600000 ºÎÅÍ ½ÃÀÛÇؼ­ ÇÑ ÆäÀÌÁö ¸¸Å­ Â÷ÁöÇϹǷΠrop¸¦ Çϴµ¥¿¡ À־ ascii armor¸¦ ÇÇÇÒ ¼ö ÀÖ½À´Ï´Ù.
°¡Á¬ ¶ÇÇÑ ret / pop&retÀÌ Á¸ÀçÇÏ´Ï ret slide°¡ °¡´ÉÇÏ°ÚÁÒ..?
2014/02/16  
1574   pwnable.kr echo1 Áú¹®2 (½ºÆ÷ ÁÖÀÇ)[2]     turttle2s
10/05 1287
1573   LOB GATE¹®Á¦ Ç®¸é¼­ ±Ã±ÝÇÑÁ¡[3]     hackxx123
08/24 1015
1572   libc°ü·Ã - 2[5]     lMaxl04
08/24 920
1571   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1189
1570   ¸®¸ðÆ® ȯ°æ¿¡¼­ÀÇ ½ºÅà ÁÖ¼Ò È®ÀÎ ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù.[2]     lMaxl04
06/16 974
1569   ÇØÅ· ÇÁ¸®¼­¹ö ¾ø¾îÁ³³ª¿ä?[1]     terfkim
04/15 1760
1568   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1493
1567   pwnable.kr echo1 Áú¹®[2]     turttle2s
06/17 1760
1566   ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     heeyoung0511
06/16 1603
1565   Level2 -> Level3 ¿¡¼­ vi¿Í /usr/bin/EditorÀÇ Â÷ÀÌ[2]     hyemin1826
07/18 1913
1564   Trainer3 ftz.hackerschool.org È£½ºÆ® Á¢¼Ó ºÒ°¡[1]     hyemin1826
07/18 3250
1563   dllÀÎÁ§¼Ç ½ÇÇèÁß Áú¹® µå¸³´Ï´Ù.[1]     kkk477
05/31 1884
1562   ÆÐŶ º¹È£È­¸¦ ¸¶½ºÅÍ ÇÏ·Á¸é ¾î¶² °úÁ¤ÀÌ ÀÖ¾î¾ßÇϳª¿ä?     sa0814
04/01 1720
1561   »ç±â[2]     jas08
03/31 2021
1560   ½Ã½ºÅÛ ÄÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ª°ú ºÒ°¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ªÀÌ Á¸ÀçÇϳª¿ä?     ocal
03/30 1760
1559   pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?[4]     ocal
01/09 2317
1558   lob level19(nightmare) °ü·ÃÁú¹®[1]     dnjsdnwja
12/18 1774
1557   ftz level2 Áú¹®ÀÖ½À´Ï´Ù[1]     kihyun1998
12/13 1865
1556   ftz level2¹ø Ǫ´Âµ¥¿ä ±ÇÇÑÀÌ...     kihyun1998
12/06 1727
1555   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2220
1 [2][3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org