|  |
| |
º°ºûÀ»´ã¾Æ |
Àú°Ô º°°Å ¾Æ´Ñ°Å °°Áö¸¸ »ç½Ç push¶ó´Â ¸í·É¾î°¡ µé¾î°¥ °ø°£ÀÌ
Â÷Áö ÇÏ°í ¾ÈÇϰí¶ó´Â Â÷À̰¡ ÀÖÁÒ.
¸¸¾à ¸ðµç ¸í·É¾î°¡ 1¹ÙÀÌÆ®¶ó¸é... À§¿¡ ¾´ ¸í·É¾î´Â ÃÑ 10¹ÙÀÌÆ®°Ú±º¿ä
±Ùµ¥ ¿©±â¿¡¼ ¸Ç À§¿¡ ÀÖ´Â
push $0x0 \n\t
push %ebx \n\t
µÎ°³ÀÇ Äڵ带 »©¹ö¸®¸é ¸í·É¾î¸¸ ÃÑ 8¹ÙÀÌÆ®°¡ µÇ´Â°ÅÁÒ.
push¸í·É¾î°¡ ¸î¹ÙÀÌÆ® ¸í·É¾îÀ̰í mov°¡ ¸î ¹ÙÀÌÆ®¸í·É¾îÀÎÁö ¸ð¸£°ÚÁö¸¸..
ftz¿¡¼ gdb·Î disass¸¦ ÇØ º¸¼Ì´Ù¸é push·Î 0À» ³Ö´Â ¸í·É¾î°¡ ¸Þ¸ð¸® ÁÖ¼Ò¿¡ +1½ÃŲ´Ù´Â °ÍÀ» º¼ ¼ö ÀÖ½À´Ï´Ù.
|
2011/05/29 |
|
| intmain1202 |
º°ºû´Ô ¸»¾¸´ë·Î¶ó¸é... ²À 10¹ÙÀÌÆ®°¡ µÇ¾î¾ßµÈ´Ù´Â °Ç°¡¿ä?
±×·¯Áø ¾ÊÀ»°Í°°Àºµ¥.....
¸Þ¸ð¸®¿¡ /bin/sh¸¦ Ǫ½¬ÇÞÀ»¶§ esp´Â ¾îÂ¥ÇÇ ±×¾Æ·¡¼ /bin/sh¸¦ ÁÖ¼Ò¸¦ °¡¸£Å³Å×°í..
±×·³ ¹Ù·Î mov %esp, %ebx
push 0x0 push %ebx¾ÈÇØµµ µÉ°Í°°Àºµ¥..
¿Ö Àú·± °úÁ¤À» °ÅÄ¡´Â°ÇÁö ¸ð¸£°Ù³×¿ä;; |
2011/05/29 |
|
| profreez |
int execve(const char *filename, char *const argv[], char *const envp[]);
execve("/bin//sh", ["/bin/sh", NULL], [NULL])
À§ ÇÔ¼ö ÀÎÀÚ¸¦ º¸½Ã¸é µË´Ï´Ù.
argv ºÎºÐ¿¡ "/bin/sh"¸¦ °¡¸£Ä¡´Â Æ÷ÀÎÅÍ¿Í ³¡À» ³ªÅ¸³»´Â NULL(0)ÀÌ ÇÊ¿äÇÕ´Ï´Ù.
±×·¡¼ 0À» ³Ö¾ú±º¿ä. |
2011/05/29 |
|
| profreez |
ÇØÅ· °ø°ÝÀÇ ¿¹¼ú À̶ó´Â Ã¥ ¼ÐÄÚµå ºÎºÐÀ» Âü°í ÇÏ½Ã¸é µÉµí ½Í½À´Ï´Ù.
°³Á¤ÆÇ ±âÁØÀ¸·Î 425ÆäÀÌÁö Âü°í Çϼ¼¿ä.
°³ÀÎÀûÀ¸·Î ÀúÃ¥ °³Á¤ÆÇÀÇ ÀåÁ¡Àº ÀÚ¼¼ÇÑ ¼³¸í°ú ¶óÀÌºê ½Ãµð°¡ ÁÁ°í
1ÆÇÀº Ã¥ÀÌ ¤·¤¿¤¬¾Æ¼ ÁÁ´õ±º¿ä. °³Á¤ÆÇÀº °¡Áö°í ´Ù´Ï±â¿£ ³Ê¹« µÎ²¨¿ö¿ä¤Ñ.¤Ì
1ÆÇµµ Çϳª »çµÖ¾ß°Ú³×¿ä ¤¾ |
2011/05/29 |
|