½Ã½ºÅÛ ÇØÅ·

 1574, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   in_reason
   ftz level11¹ø ¹®Á¦¿¡ ´ëÇÑ Áú¹®ÀÌ ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1937 [º¹»ç]


ftz levvel11¹ø¿¡ ´ëÇÑ ±Ã±ÝÁòÀÌ ÀÖ¾î Áú¹®À» ÇÏ°Ô µÇ¾ú½À´Ï´Ù.
gdb¸¦ ÅëÇÏ¿© level11ÀÇ attackme¸¦ µð¹ö±ë Çغ¸¸é

Dump of assembler code for function main:
0x08048470 <main+0>:    push   ebp
0x08048471 <main+1>:    mov    ebp,esp
0x08048473 <main+3>:    sub    esp,0x108
0x08048479 <main+9>:    sub    esp,0x8
0x0804847c <main+12>:   push   0xc14
0x08048481 <main+17>:   push   0xc14
0x08048486 <main+22>:   call   0x804834c <setreuid>
0x0804848b <main+27>:   add    esp,0x10
0x0804848e <main+30>:   sub    esp,0x8
0x08048491 <main+33>:   mov    eax,DWORD PTR [ebp+12]
0x08048494 <main+36>:   add    eax,0x4
0x08048497 <main+39>:   push   DWORD PTR [eax]
0x08048499 <main+41>:   lea    eax,[ebp-264]
0x0804849f <main+47>:   push   eax
0x080484a0 <main+48>:   call   0x804835c <strcpy>
0x080484a5 <main+53>:   add    esp,0x10
0x080484a8 <main+56>:   sub    esp,0xc
0x080484ab <main+59>:   lea    eax,[ebp-264]
0x080484b1 <main+65>:   push   eax
0x080484b2 <main+66>:   call   0x804833c <printf>
0x080484b7 <main+71>:   add    esp,0x10
0x080484ba <main+74>:   leave
0x080484bb <main+75>:   ret
0x080484bc <main+76>:   nop
0x080484bd <main+77>:   nop
0x080484be <main+78>:   nop
0x080484bf <main+79>:   nop
End of assembler dump.

ÀÌ·¸°Ô ¶ß°Ô µÇ´Âµ¥, ¿©±â¼­ ´Ù¸¥ »ç¶÷µéÀÇ ±ÛÀ» º¸¸é main+30ºÎºÐÀÌ SFP¿Í RET¸¦ °¢°¢ 4byte¸¸Å­ ¼±¾ðÇØ ÁØ´Ù°í ³ª¿ÍÀִµ¥ SFP¿Í RETÀÎÁö ¾î¶»°Ô ±¸ºÐÇÏ´ÂÁö ±Ã±ÝÇÕ´Ï´Ù.

±×¸®°í Á¦°¡ ¾Æ´Â Áö½ÄÀ¸·Î´Â ¸ðµç ÇÔ¼ö´Â »ç¿ëÇÒ ¶§ ret¸¦ ¼±¾ðÇÏ°í ½ÇÇàÇϴ°ÍÀ¸·Î ¾Ë°íÀִµ¥ ¿©±â¼­ setreuid´Â ÇÊ¿äÇÏ°í strcpy´Â ±×·¸°Ô Áß¿äÇÏÁö ¾Ê¾Æ¼­ strcpyÀÇ ret°ªÀ» ÀÌ¿ëÇؼ­ ½©À» Å»ÃëÇϴ°ǰ¡¿ä?

±×·¸´Ù¸é printf¿Í setreuid¿¡µµ SFP¿Í ret°ªÀÌ ¼±¾ðµÇ´Â°Ç°¡¿ä?


Áú¹® Á¤¸®
1. SFP¿Í RETÀÎÁö ¾Æ´Ï¸é ÀÏ¹Ý subÀÎÁö ±¸ºÐÇÏ´Â ¹æ¹ý
2. ¸ðµç ÇÔ¼ö¿¡ ret°ªÀÌ ÀÖ´ÂÁö ¾ø´ÂÁö
    ÀÖ´Ù¸é printfÀÇ ret°ª¿¡¼­µµ ½© Å»Ãë°¡ °¡´ÉÇÑÁö

°í¼ö´ÔµéÀÇ ´äº¯ÀÌ ÇÊ¿äÇÕ´Ï´Ù.

  Hit : 1897     Date : 2018/09/10 11:40



    
gihacker ¸ðµç ÇÔ¼ö¸¦ ½ÇÇàÇÒ¶§´Â ½ºÅÿ¡ ret¸¦ Ǫ½¬ÇÕ´Ï´Ù call ¸í·É¾î´Â »ç½Ç Ãà¾àµÈ ¸í·É¾î±¸¿ä 2018/09/10  
dc4458 call À» Çϸé ret ÁÖ¼Ò°¡ Ǫ½¬µÇ°í ¼­ºê·çƾ¾È¿¡¼­ sfp°¡ Ǫ½¬µË´Ï´Ù.
¸»¾¸ÇϽŠsub´Â ±×³É °ø°£È®º¸ÀÎ°Í °°³×¿ä. ¹®¸Æ»óÀ¸·Î´Â setreuid°¡ ret Çѵڿ¡ setreuid°¡ »ç¿ëÇÑ ½ºÅÃÀ» add ¿Í sub·Î Á¤¸®ÇØÁØ°Í °°½À´Ï´Ù.

¸ðµç ¼­ºê·çƾÀº ret ÇÕ´Ï´Ù.
´ç¿¬È÷ printf¿¡µµ ret¸í·É¾î°¡ ÀÖ±¸¿ä ¾î¶² ¹æ¹ýÀ» »ç¿ëÇؼ­ ret ÁÖ¼Ò¸¦ µ¤¾î¾º¿î´Ù¸é ¿øÇÏ´Â Äڵ带 ½ÇÇà½Ãų¼ö°¡ ÀÖ°ÚÁÒ.
2018/09/27  
dc4458 ÇÏÁö¸¸ ¹®Á¦¿¡¼­´Â printf³ª strcpyÀÇ retÁÖ¼Ò°ªÀ» µ¤¾î¾º¿ï ¼ö °¡ ¾ø½À´Ï´Ù.

¹®ÀÚ¿­ÀÌ Ä«ÇÇµÉ °ø°£ÀÇ ÁÖ¼Ò°¡ ¸ÕÀú ¼±¾ðµÇ°í ÈÄ¿¡ ÇÔ¼öµéÀÌ ÄݵDZ⠶§¹®¿¡
À§ ÇÔ¼öµéÀÇ ret °ªµéÀº ¹®ÀÚ¿­ÀÌ Ä«ÇÇµÉ °ø°£ÀÇ ÁÖ¼Òº¸´Ù Ç×»ó ³·Àº ÁÖ¼Ò¿¡ À§Ä¡ÇÏ°Ô µÇ¹Ç·Î ¾î¶² ¹®ÀÚ¿­À» Àü´ÞÇØÁ൵ ret°ªÀ» µ¤¾î¾º¿ï ¼ö °¡ ¾ø½À´Ï´Ù.

strcyp°¡ ÄÝÀÌ µÈ Á÷ÈÄÀÇ ½ºÅÃÀ» ±×¸®¸é ´ÙÀ½°ú °°½À´Ï´Ù.

strcpyÀÇ retÁÖ¼Ò - strcpyÀÇ ÀÎÀÚ1 - strcpyÀÇ ÀÎÀÚ2 - ¹®ÀÚ¿­ÀÌ Ä«ÇÇµÉ °ø°£ - ¸ÞÀÎÀÇ SFP - ¸ÞÀÎÀÇ retÁÖ¼Ò - ¸ÞÀο¡ Àü´ÞµÈ ÀÎÀÚµé...

¼ø¼­±â ¶§¹®¿¡ ¹®ÀÚ¿­ÀÌ Ä«Çǵɰø°£¿¡ ¾î¶² ¹®ÀÚ¿­ÀÌ µé¾î°¡µµ µÚ¿¡ ³ª¿À´Â ¸ÞÀÎÀÇ SFP ³ª ¸ÞÀÎÀÇ RET Áּҵ鸸 µ¤¾î ¾º¿ï ¼ö ÀÖ½À´Ï´Ù.
2018/09/27  
1574   pwnable.kr echo1 Áú¹®2 (½ºÆ÷ ÁÖÀÇ)[2]     turttle2s
10/05 1234
1573   LOB GATE¹®Á¦ Ç®¸é¼­ ±Ã±ÝÇÑÁ¡[3]     hackxx123
08/24 928
1572   libc°ü·Ã - 2[5]     lMaxl04
08/24 879
1571   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1143
1570   ¸®¸ðÆ® ȯ°æ¿¡¼­ÀÇ ½ºÅà ÁÖ¼Ò È®ÀÎ ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù.[2]     lMaxl04
06/16 939
1569   ÇØÅ· ÇÁ¸®¼­¹ö ¾ø¾îÁ³³ª¿ä?[1]     terfkim
04/15 1719
1568   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1449
1567   pwnable.kr echo1 Áú¹®[2]     turttle2s
06/17 1724
1566   ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     heeyoung0511
06/16 1570
1565   Level2 -> Level3 ¿¡¼­ vi¿Í /usr/bin/EditorÀÇ Â÷ÀÌ[2]     hyemin1826
07/18 1832
1564   Trainer3 ftz.hackerschool.org È£½ºÆ® Á¢¼Ó ºÒ°¡[1]     hyemin1826
07/18 3213
1563   dllÀÎÁ§¼Ç ½ÇÇèÁß Áú¹® µå¸³´Ï´Ù.[1]     kkk477
05/31 1843
1562   ÆÐŶ º¹È£È­¸¦ ¸¶½ºÅÍ ÇÏ·Á¸é ¾î¶² °úÁ¤ÀÌ ÀÖ¾î¾ßÇϳª¿ä?     sa0814
04/01 1689
1561   »ç±â[2]     jas08
03/31 1985
1560   ½Ã½ºÅÛ ÄÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ª°ú ºÒ°¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ªÀÌ Á¸ÀçÇϳª¿ä?     ocal
03/30 1727
1559   pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?[4]     ocal
01/09 2266
1558   lob level19(nightmare) °ü·ÃÁú¹®[1]     dnjsdnwja
12/18 1739
1557   ftz level2 Áú¹®ÀÖ½À´Ï´Ù[1]     kihyun1998
12/13 1828
1556   ftz level2¹ø Ǫ´Âµ¥¿ä ±ÇÇÑÀÌ...     kihyun1998
12/06 1704
1555   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2186
1 [2][3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org