½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kjy30532
   ½©ÄÚµå Áú¹® ¤Ì¤Ì Á¦¹ßµµ¿ÍÁÖ¼¼¿©

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1506 [º¹»ç]


Á¦°¡ ÇØÄ¿½ºÄ𠼿ÄÚµå ¸¸µé±â °­Á Áß ÇϳªÀΰ۰Àº°Å¸¦ º¸°í µû¶ó°¡´Âµ¥..

(ÁÖ¼Ò : http://research.hackerschool.org/Datas/Research_Lecture/sc_making.txt)

½©ÄÚµå ¸¸µé±â ºÎºÐ¿¡¼­ ¾î¼ÀÀ¸·Î ÀÛ¼ºÇÏ´Â ºÎºÐ Áï


  1 .globl main
  2 main :
  3         jmp come_here
  4 func :
  5         movl $0x0b, %eax
  6         popl %ebx
  7         movl %ebx, (%esi)
  8         movl $0x00, 0x4(%esi)
  9         leal (%esi), %ecx
10         movl $0x00, %edx
11         int $0x80
12
13         movl $0x01, %eax
14         movl $0x00, %ebx
15         int $0x80
16 come_here :
17         calll func
18         .string "/bin/sh\00"


À̺κР¤Ì¤Ì

±× °­Á¿¡ ³ª¿Â ±×´ë·Î ÃÆ´Âµ¥

¼¼±×ÆúÀÌ ¶ß´õ¶ó°í¿ä..

±×·¡¼­ gdb·Î ¾îµð¼­ ¶ß´ÂÁö ºÃ´õ´Ï

7         movl %ebx, (%esi)

ÀÌ ºÎºÐ¿¡¼­ ¶ß±æ·¡ info reg esi ÇØ¼­ ºÃ´õ´Ï esiÀÇ ÁÖ¼Ò°¡ ³ÎÀΰ۰¾Ò¾î¿ä..

(±¸±Û¿¡¼­ info reg º¸´Â¹ý¿¡ ´ëÇØ¼­ °Ë»öÇØºÃ´Âµ¥ Àß ¸øÃ£°Ú´õ¶ó°í¿ä ¤Ì¤Ì)

±×·¡¼­ movlÀ» ÀÌ¿ëÇØ¼­ esi¿¡ ÁÖ¼Ò¸¦ ³Ö¾îÁÖ°í ÇØ”f´Âµ¥µµ ¾ÈµÅ°í..

Á¦¹ß ¾Ë·ÁÁÖ¼¼¿ä ¤Ì¤Ì À̰Ŷ§¸Å ´ä´äÇØ ¹ÌÄ¡°Ú¾î¿ä..

  Hit : 3302     Date : 2011/07/24 03:38