22019, 1/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   xhosa123
   sshµ¥¸óºÐ¼®

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=29993 [º¹»ç]


¾È³çÇϼ¼¿ä.

remote rop¸¦ ÇØº¼·Á°í ÇÕ´Ï´Ù.
Ãë¾àÇÑ ssh °ø°³µÈ ¹öÀüÀ» ã¾Æ¼­ gdb·Î ºÐ¼®Çغ¸°í½ÍÀºµ¥
ÀÌ·± sshµ¥¸óÀº ¾î¶»°ÔºÐ¼®ÇØÁִ°ǰ¡¿ä?

gdb vuln
ÇÁ·Î±×·¥Àº ÀÌ·±½ÄÀ¸·Î ÇØÁÖ¸éµÇÁö¸¸
ssh µ¥¸óÀº ¾î¶»°Ô gdb·Î¿­°íºÐ¼®ÇؾßÇϳª¿ä?
pid ¸¦attachÇϴ¹æ¹ýµµÀÖ´Ù°íÇϴµ¥ ÀÌ·¸°ÔÇØÁִ°ǰ¡¿ä??

±×¸®°í ¶Ç ropeme·Î °¡Á¬À» ã¾Æ¾ßÇϴµ¥
ropeme>generate [??]
¾î¶»°Ô ÇØÁà¾ßÇϳª¿ä..??

  Hit : 8247     Date : 2012/12/10 08:45



    
cd80 ´ëȸ¿¡¼­ ¸®¸ðÆ® ¹öÆÛ¿À¹öÇÃ·Î¿ì ¹®Á¦ ºÐ¼®ÇϽǶ§Ã³·³ ºÐ¼®ÇÏ½Ã¸é µË´Ï´Ù~~
°¡Àå Æí¸®ÇÑ ¹æ¹ýÀº IDA·Î Á¤ÀûºÐ¼®ÇϽø鼭 ¾î´ÀÁ¤µµ ±¸Á¶¸¦ ÀÍÈ÷½Å ÈÄ ÆÛÁ®¸¦ ÀÛ¼ºÇϽŠÈÄ ³ª¿Â Ãë¾àÁ¡À» °ø·«ÇÏ´Â ¹æ¹ýÀε¥
¿øÇϽô ¹æ¹ýÀº
Á¢¼ÓÇϽÅÈÄ ÇÁ·Î¼¼½º¸¦ º¸½Ã¸é
root 1296 0.0 0.1 6508 1104 ? Ss 10:25 0:00 /usr/sbin/sshd
root 1655 0.3 0.2 9404 2944 ? Ss 10:31 0:00 sshd: root@pts/0
root 1682 0.0 0.0 4312 732 pts/0 S+ 10:31 0:00 grep ssh
ÀÌ·±½ÄÀ¸·Î 1296¿¡¼­ µ¥¸óÇÁ·Î¼¼½º°¡ ÀÛµ¿Çϰí 1655¿¡¼­ ÀÚ½ÄÇÁ·Î¼¼½º ȤÀº ¾²·¹µå°¡ À¯Àú Á¢¼ÓÀ» ó¸®ÇϱâÀ§ÇØ ÀÛµ¿ÇÕ´Ï´Ù
´ëºÎºÐ Ãë¾àÁ¡ÀÌ À¯Àú ÀԷ¿¡¼­ ³ª´Ï ÀÚ½ÄÇÁ·Î¼¼½ºÀÇ pid¸¦ È®ÀÎÇϽŠÈÄ
gdb¿¡¼­ attach [ÇØ´ç pid]¸¦ ÀÔ·ÂÇÏ½Ã¸é ¾îÅÂÄ¡ ÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù
2012/12/11  
xhosa123 ±×··rop°¡Á¬Àº¾î¶»°Ôã¾ÆÁà¾ßÇϳª¿ä?
Ropeme±âÁØÀ¸·Î¿ä.
2012/12/11  
cd80 ropeme°°Àº°æ¿ì´Â vnsecurity ¿´³ª¿¡¼­ ÀÛ¼ºÇÑ ±Û¿¡ ÀÚ¼¼È÷ ¼³¸íµÇ¾îÀÖ½À´Ï´Ù
±»ÀÌ ropeme¸»°íµµ objdumpµîÀÇ ¸í·ÉÀ¸·Î retµéÀÇ ÁÖ¼Ò¸¦ ã°í ±× ÀÌÀü ¸î¹ÙÀÌÆ®¸¸Å­ÀÇ ¸í·É¾î¸¦ ã¾Æ³»´Â ¹æ½ÄÀ¸·Î
¾µ¸¸ÇÑ °¡Á¬À» ãÀ¸½Ç ¼öµµ ÀÖ½À´Ï´Ù

http://www.vnsecurity.net/2010/08/ropeme-rop-exploit-made-easy/
ÀÌ ±Û¿¡ µû·Î Âü°íÇÏ½Ç ¼ö ÀÖ´Â ¹®¼­¿Í ¹ßÇ¥ÀÚ·á, PoCÄÚµå±îÁö °°ÀÌ ÀÖÀ¸´Ï °øºÎÇϽñ⠼ö¿ùÇϽø®¶ó »ý°¢ÇÕ´Ï´Ù
2012/12/11  
xhosa123 Ssh µ¥¸óÀ» ¾î¶»°Ôropeme. ¿¡¼³Á¤ÇØÁà¾ßÇϳª¿ä?

Generate ssh ÀÌ·¸°Ô´Â¾ÈµÇÁö¾Ê³ª¿ä?
2012/12/11  
cd80 generate /usr/sbin/sshd ÇØÁÖ½Ã¸é µË´Ï´Ù 2012/12/12  
cd80 »ç¿ë¹ý¿¡ ´ëÇØ¼­´Â
http://www.youtube.com/watch?feature=player_embedded&v=1nPCJQtecrk
¿©±â µ¿¿µ»ó¿¡¼­ ²Ï ÀÚ¼¼È÷ ¼³¸íÇØÁÖ°í ÀÖ½À´Ï´Ù Âü°íÇØº¸¼¼¿ä
2012/12/12  
cd80 ±×·±µ¥ Áö±Ý °¡Á¬À» ã´Â°Í¸¸ »ý°¢ÇÏ°í °è½Å°Í°°Àºµ¥ °á±¹ ±× °¡Á¬µéÀ» Á¶ÇÕÇØ ½ÇÇàÇÏ·Á¸é eip¸¦ Á¶ÀÛÇÏ¼Å¾ß ÇÕ´Ï´Ù
ÀÌ ¶§¹®¿¡ ÆÛÁ®¸¦ ¾ð±ÞÇѰÍÀ̱¸¿ä
2012/12/12  
xhosa123 Ãë¾àÁ¡À» Gdb·Îµð¹ö±ëÇØ¼­Ã£À¸¸éµÇ°Ô¿À·¡°É¸± ·Á³ª¿ä? 2012/12/12  
cd80 ¾î¼Àºí¸®¾î¸¦ ¾ó¸¶³ª »¡¸® ºÐ¼®ÇÏ½Ç ¼ö ÀֳĿ¡ µû¶ó ´Ù¸£Áö¸¸ Çí½º·¹ÀÌ·Î µðÄÄÆÄÀÏÇØ¼­ ã´Â°Å³ª ¿ÀǼҽº ÇÁ·Î±×·¥ÀÇ ¼Ò½º¸¦ º¸¸é¼­ Ãë¾àÁ¡À» ã´Â°Íº¸´Ü ¸¹ÀÌ ¿À·¡°É¸±°Í °°½À´Ï´Ù 2012/12/12  
xhosa123 ±×·³ ÆÛ¡¸»°í ´Ù¸¥¹æ¹ýÀ¸·Î Ãë¾àÁ¡À» ã´Â ¹æ¹ýÀº¾ø³ª¿ä???? 2012/12/12  
cd80 ÆÛÁ®°¡ Ãë¾àÁ¡ ã´Â°ÍÀ» ÀÚµ¿È­ÇÑ ÅøÀ̱⠶§¹®¿¡ ÆÛ¡À» Á¦¿ÜÇÑ ´Ù¸¥¹æ¹ýÀ¸·Î ÇÏ½Ã´Â°Ç ¼öµ¿À¸·Î ãÀ¸½Ã´Â°Å¸»°í´Â ¾ø½À´Ï´Ù
¸»¾¸ÇϽŠgdb¸¦ ÀÌ¿ëÇÏ¿© ¾î¼Àºí¸®¾î¸¦ ºÐ¼®Çϼŵµ µÇ°í,
openssh³ª freeSSHd°°Àº ¿ÀǼҽº ¼ÒÇÁÆ®¿þ¾î¸¦ ¼Ò½º¸¦ º¸½Ã¸é¼­ Ãë¾àÁ¡À» ã¾Æº¸½Ç ¼ö ÀÖ½À´Ï´Ù
2012/12/12  
xhosa123 ¤¤¤¤ cd80 °¨»çÇÕ´Ï´Ù!! 2012/12/12