·¹º§ ÇØÅ·

 2839, 1/142 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¿ìÀ×22
   lob fc3 fgets·Î ÀԷ¹޴ ¿À¹öÇ÷οì°ü·Ã Áú¹®ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=3200 [º¹»ç]


lob fedora core3  hell_fire ¹®Á¦ Ç®°íÀÖ½À´Ï´Ù

fgets·Î ÀԷ¹޾Ƽ­ ¿À¹öÇÃ·Î¿ì ½Ã۴µ¥
gdb·Î È®ÀÎÇØº¸·Á°í Çϴµ¥

fgetsÀÌ¸é ½ÇÇàµÈ ÈÄ¿¡ ÀÔ·ÂÀ» ¹ÞÀ¸´Ï
r `perl -e 'print "~~~"`  ÀÌ·±½ÄÀ¸·Î ¸øÇÏÀݾƿä

r À¸·Î ½ÇÇàÇÑ ÈÄ¿¡
´Ù½Ã ÀԷ°ªÀ» ½á ³Ö¾î¾ß Çϴµ¥
±×ºÎºÐ¿¡ 16Áø¼ö °ªÀ» (\x20) ÀÌ·±½ÄÀ¸·Î ³ÖÀ¸¸é ¾Èµé¾î°¡Àݾƿä
python À̳ª perl ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÒ ¼öµµ ¾ø°í print¸¦ »ç¿ë ÇÒ ¼öµµ ¾ø°í
¾î¶»°Ô ÇØ¾ß Çϳª¿ä ?


Ãß°¡·Î dark_eyes·Î ·Î±×ÀÎÇØ¼­ hell_fireǪ´Âµ¥ Ǫ½ÅºÐ ÈùÆ®Á» Áּſä ~

  Hit : 4792     Date : 2011/04/14 07:54



    
CodeAche 1. ¼Ò½ºÄڵ忡 sleep(300) Äڵ带 Ãß°¡Çؼ­ ½©¿¡¼­ ÆäÀ̷ε屸¼º&½ÇÇà ÈÄ
gdb - attach PID

2. $ perl -e 'print "a"x100,"\x20\x4a\xb8\x4a" > payload
gdb> r < ./payload
2011/04/14  
Prox ÆÄÀÌÇÁ°¡ ¹ºÁö ±¸±Û¸µÇغ¸½Ã´Â°Íµµ µµ¿òÀ̵ǽǵí~ 2011/04/15  
h2spice CodeAche ´Ô
2. $ perl -e 'print "a"x100,"\x20\x4a\xb8\x4a" > payload
gdb> r < ./payload

¿©±â¼­ ' ºÎºÐ ºüÁø°Ç°¡¿ä ¾Æ´Ï¸é ¿ø·¡ ±×·¸°ÔÇØ¾ßÇϳª¿ä??
2012/05/20