22018, 1/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ocal
   pwnable.kr starcraft ¸¶¹«¸®¸¦ ¾î¶»°Ô ÇØ¾ß ÇÒ±î¿ä?

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=37361 [º¹»ç]


pwnable.kr starcraft ¹®Á¦¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.

ÀÏ´Ü checksec·Î °Ë»çµÇ´Â º¸È£±â¹ýÀº ´Ù °É·ÁÀÖ½À´Ï´Ù.(RELRO, Canary, NX, PIE)

ÀÌ·± »óȲ¿¡¼­ Á¤¼®Àº libc base address¸¦ µý ÈÄ¿¡ rip hijackÀ» ÇØ¼­ ¸ÅÁ÷ °¡Á¬À» ³ÖÀ¸¸é µÇ°ÚÁö¿ä. ±×·¡¼­ ±×·¸°Ô Çߴµ¥...

libc base leak, rip hijack, one gadgetÀ» Á¶ÇÕÇÏ·Á°í ¼¼°³ ´Ù ¾Ë¾Æ³Â½À´Ï´Ù.

±×·±µ¥ one gadgetÀÇ constraint¸¦ ¸¸Á·À» ¾ÈÇϳ׿ä. ¾î¶»°Ô ÇØ¾ß ÇÒÁö ¸ð¸£°Ú½À´Ï´Ù.

Ȥ½Ã ÀÌ ¹®Á¦ Ǫ¼Ì°Å³ª ¾Æ´Ï¸é ¾ÆÀ̵ð¾î ÀÖÀ¸½Å ºÐ Á¶¾ðÀ» Á» ÇØÁÖ½Ã¸é °¨»çÇϰڽÀ´Ï´Ù.

(cf) °¡Á¬ÀÇ Á¦ÇÑ »çÇ×Àº À̸¦Å׸é ÀÌ·±°Ì´Ï´Ù.
(ex) rax == NULL
(ex) [rsp+0x30] == NULL

  Hit : 6178     Date : 2020/06/26 03:21



    
ocal Ç®¾ú½À´Ï´Ù... 2020/06/27  
jason102938 Çæ µü ¸·È÷½Å °÷¿¡¼­ Àúµµ ¸·Çû´Âµ¥,,, one gadgetÀÇ Á¦¾à»çÇ×À» ¸¸Á·¸øÇؼ­ ´Ù¸¥ ºÎºÐÀ» º¸°í ÀÖ½À´Ï´Ù.
Ȥ½Ã ¾î¶»°Ô Ǫ¼Ì´ÂÁö Á¶¾ðÁ» ÇØÁֽǼö ÀÖÀ»±î¿ä?
2021/06/03  
ocal ¾ÈµÇ¸é µÇ°Ô ÇØ¾ß ÇÕ´Ï´Ù 2022/02/08