29, 1/2 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://cyworld.co.kr/codesire
   LEVEL1~20 Á¤¸®

http://www.hackerschool.org/HS_Boards/zboard.php?id=bof_fellowship_2round&no=1 [º¹»ç]


[¸÷ ¸®½ºÆ®]
LEVEL1 (gate -> gremlin) :  simple bof
Ç®ÀÌ
- ·ÎÄà º¯¼ö¿¡ ½©ÄÚµå
- ȯ°æ º¯¼ö¿¡ ½©ÄÚµå
- argv¿¡ ½©ÄÚµå
- µîµî

LEVEL2 (gremlin -> cobolt) : small buffer
- ·ÎÄà º¯¼ö¿¡ ½©ÄÚµå X
- ȯ°æ º¯¼ö¿¡ ½©ÄÚµå
- argv¿¡ ½©ÄÚµå
- µîµî

LEVEL3 (cobolt -> goblin) : small buffer + stdin
- cat°ú ÆÄÀÌÇÁ(|) ÀÌ¿ë

LEVEL4 (goblin -> orc) : egghunter
- ·ÎÄà º¯¼ö¿¡ ½©ÄÚµå
- ȯ°æ º¯¼ö¿¡ ½©ÄÚµå X
- argv¿¡ ½©ÄÚµå
- µîµî

LEVEL5 (orc -> wolfman) : egghunter + bufferhunter
- ·ÎÄà º¯¼ö¿¡ ½©ÄÚµå X
- ȯ°æ º¯¼ö¿¡ ½©ÄÚµå X
- argv¿¡ ½©ÄÚµå
- µîµî

LEVEL6 (wolfman -> darkelf) : check length of argv[1] + egghunter + bufferhunter
- argv¿¡ ½©ÄÚµå -> argv[2] ÀÌ»óÀ» ÀÌ¿ë
- µîµî

LEVEL7 (darkelf -> orge) : check argv[0]
- ½Éº¼¸¯ ¸µÅ©
- exec* ÀÌ¿ë

LEVEL8 (orge -> troll) : check argc
- argv[0]¿¡ ½©ÄÚµå

LEVEL9 (troll -> vampire) : check 0xbfff
- ȯ°æ º¯¼ö spraying
- µîµî

LEVEL10 (vampire -> skeleton) : argv hunter
- º¹»çµÈ argv[0]¿¡ ½©ÄÚµå
- µîµî

LEVEL11 (skeleton -> golem) : stack destroyer
- LD_PRELOAD, LD_LIBRARY_PATH

LEVEL12 (golem -> darkknight) : sfp
- frame pointer overflow

LEVEL13 (darkknight -> bugbear) : RTL1
- system ÇÔ¼ö »ç¿ë

LEVEL14 (bugbear -> giant) : RTL2, only execve
- execve ÀÎÀÚ Àß ¸ÂÃçÁÖ±â

LEVEL15 (giant -> assassin) : no stack, no RTL
- ret + ret

LEVEL16 : assassin -> zombie_assassin
- fake ebp

LEVEL17 : zombie_assassin -> succubus
- ¿¬¼Ó ÇÔ¼ö È£Ãâ

LEVEL18 : succubus -> nightmare
- PLT È°¿ë
- AAAA µ¤±â
- strcpyÀÇ ÄÚµå µ¤±â
- printfÀÇ ÄÚµå ȤÀº printfÀÇ PLT ȤÀº GOT µ¤±â
- µîµî

LEVEL19 : nightmare -> xavis
- fgets + destroyers

LEVEL20 : xavis -> dragon
- remote BOF



  Hit : 2691     Date : 2010/03/24 09:46



    
29   ÈåÀ¸ Æäµµ¶ó¼º[1]     »êÀû
09/25 2819
28   Æäµµ¶ó fc10ºÎÅÍ ´Ù¿î·Îµå°¡ ¾ÈµÇ¿ä[1]     »êÀû
08/14 2706
27 ºñ¹Ð±ÛÀÔ´Ï´Ù  FC10 1¹ø¹®Á¦ ÀÌ»óÇÑ °Í °°¾Æ¿ä(?)     »êÀû
08/27 1
  LEVEL1~20 Á¤¸®     ¸Û¸Û
03/24 2690
     [°øÁö] Fedora Core 3, 4, 10, 14 ´Ù¿î·Îµå ÁÖ¼Ò [21] ¸Û¸Û 04/13 19123
24   ¸÷ µÎ ¸¶¸® Ãß°¡¿ä~[1]     ¸Û¸Û
04/27 2337
23   ·¹º§ 3 ¹®Á¦ º¯°æ ¹× ¸®¸ðÆ® µÎ °³ Ãß°¡¿ä~[1]     ¸Û¸Û
04/28 2405
22   GOT Overwriting ¹®Á¦¿¡ ¹®Á¦°¡ ÀÖ¾ú½À´Ï´Ù.     ¸Û¸Û
04/28 2292
21   À̹ø ÁÖ¸»¿¡ ½ºÅ͵ð ¿À½Ç ºÐ~[3]     ¸Û¸Û
04/29 2184
20   Remote RET Sleding ¹®Á¦¿¡ ¹®Á¦°¡ ÀÖ¾ú½À´Ï´Ù[4]     ¸Û¸Û
04/30 2810
19   FC3 À̹ÌÁö ¾÷µ¥ÀÌÆ® Çß½À´Ï´Ù~[1]     ¸Û¸Û
05/03 2860
18   FC4 À̹ÌÁö°¡ ¾÷µ¥ÀÌÆ® µÇ¾ú½À´Ï´Ù.[2]     ¸Û¸Û
05/03 2794
17   FC3 À̹ÌÁö°¡ ¾÷µ¥ÀÌÆ® µÇ¾ú½À´Ï´Ù.     ¸Û¸Û
05/17 3032
16   FC7 À̹ÌÁö ¾÷·Îµå Çß½À´Ï´Ù~[2]     ¸Û¸Û
05/19 3060
15   »õ·Î¿î ´Ù¿î·Îµå ÁÖ¼ÒÀÔ´Ï´Ù.[2]     ¸Û¸Û
02/05 5638
14   ¿©±â°¡ ±× Æäµµ¶ó¼º ¿øÁ¤´ë ÁøÁöÀΰ¡¿ä[1]     µÎ·ç¹¶¼ú
11/12 3453
13 ºñ¹Ð±ÛÀÔ´Ï´Ù  Fedora 1st :: gate > iron golem     wkror0318
02/19 1
12 ºñ¹Ð±ÛÀÔ´Ï´Ù  Fedora 1st :: iron golem > dark eyes     wkror0318
02/19 2
11   À¸À½... ¿©±â°¡ ±× Æäµµ¶ó¼ºÀΰ¡¿ä..[1]     W.H.
04/09 2748
10   1µîÀ¸·Î ±ÛÀ» ¾µ¼ö ÀÖ´Ù´Ï... ¿µ±¤ÀÔ´Ï´Ù.     trynerr
04/23 2011
1 [2]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org