·¹º§ ÇØÅ·

 2840, 1/142 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   gkswls123
   ´Ù¸¥ ¿ö°ÔÀÓ ¹®Á¦ Àε¥¿ä ¾î¶»°Ô Ç®¾î¾ß Çϳª¿ä?

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=3338 [º¹»ç]


centos ¸®´ª½º ȯ°æÀ̱¸¿ä hint´Â

#include <stdio.h>
#include <string.h>

int main(int argc, char *argv[]){

        char buffer[10];

        if(argc!=2){
                printf("no...just do it argc==2\n");
                return 0;
                }

        strcpy(buffer,argv[1]);

        if((buffer[0])=='a'){


        if((buffer[1])==' '){

        if((buffer[2])=='a'){
        printf("\nSuccess!\n");
        setuid(505);
        system("/bin/bash");

        }

        }

        }

        printf("read catchme.c\n");

        return 0;
}

À̰ÍÀε¥¿ä ±¸Ã¼ÀûÀ¸·Î ¹» ¾î¶»°Ô Ç϶ó´Â°Ç°¡¿ä?

  Hit : 4152     Date : 2015/01/08 02:39



    
cd80 ./catchme "a a" Ç϶ó´Â°Ô ¹®Á¦ Àǵµ¿¡¿ä 2015/01/08  
skyclad1975 ¹®ÀÚ¿­À» ÀÎÀÚ·Î Àü´ÞÇÒ ¼ö ÀÖ´À³Ä¸¦ ¹¯´Â ¹®Á¦³×¿ä
¿ø·¡¶ó¸é ¶ç¾î¾²±â°¡ Æ÷ÇԵǾîÀÖ´Â ¹®ÀÚ¿­Àº ¶ç¾î¾²±â¸¦ ±âÁØÀ¸·Î °¢°¢ ´Ù¸¥ º¯¼ö·Î ÀνĵDZ⠶§¹®¿¡ argv[1]°ú argv[2] ¿¡ °¢°¢ µé¾î°¡ À§ÀÇ if¹®¿¡ °É¸®°Ô µË´Ï´Ù¸¸ ¶ç¾î¾²±â°¡ Æ÷ÇÔµÈ ¹®ÀÚ¿­À» ÀÎÀÚ·Î Àü´ÞÇϱâ À§Çؼ­´Â " "(Å«µû¿ÈÇ¥)·Î ¹­¾îÁÖ½Ã¸é µË´Ï´Ù
2015/01/09  
4narchy_gh0st °¨»çÇÕ´Ï´Ù. 2016/11/05