½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   gorani
   ¾È³çÇϼ¼¿ä ÆÛ¹Ì¼Ç°øºÎÇϰí ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1556 [º¹»ç]


°øºÎÇÏ´Ùº¸´Ï

ÇØÅ·¼­¹ö

level1 ¿¡¼­ level2 uid ±ÇÇÑÀ» ¾òÀºÈÄ¿¡.

my-pass ¸¦ ÀÔ·ÂÇØ¼­ ºñ¹Ð¹øÈ£¸¦ ¾Ë¾Æ³»¼­ ´ÙÀ½ ·¹º§·Î °¡´Â Çü½ÄÀÌ´øµ¥

my-pass´Â ½ÇÁ¦ Á¸ÀçÇÏ´Â ¸í·É¾î°¡ ¾Æ´Ï¶ó°í µé¾ú½À´Ï´Ù.


±×·¸´Ù¸é ½ÇÁ¦·Î´Â ¾î¶»°Ô uid ¸¦ ¾òÀº ÈÄ ¾ÏÈ£¸¦ ¾Ë¾Æ³»³ª¿ä ?

  Hit : 3320     Date : 2011/12/31 05:17



    
havu ÀÌ¹Ì ÀúÀåµÈ ÆÐ½º¿öµå¸¦ Ãâ·ÂÇÏ´Â°Í °°½À´Ï´Ù.

#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
#include <sys/types.h>

#define MAXLEVEL 3

char *uid_pass[MAXLEVEL] =
{
"level1 password",
"level2 password",
"level3 password"
};

int main(void)
{
int i = 0;
uid_t init_uid = 3001, my_uid = 0;

my_uid = getuid();
if((i = (my_uid%init_uid)) > MAXLEVEL) {
fprintf(stderr, "illegal uid.\n");
exit(EXIT_FAILURE);
} else {
fprintf(stdout, "%s\n", uid_pass[i]);
}

exit(EXIT_SUCCESS);
}
Âü°í.
2011/12/31  
phpmyadmin À­ºÐ ¸»¾¸´ë·Î FTZ¿¡¼± ÄÚµùÇØ¼­ ÀúÀåÇÑ ÆÐ½º¿öµå¸¦ ±×´ë·Î Ãâ·ÂÇÕ´Ï´Ù.

FTZ³ª FTZ¿Í À¯»çÇÑ ¸ðÀÇ ÇØÅ·¼­¹ö¿¡¼­ º¸Åë my-pass ¸í·É¾î¸¦ Á¦°øÇÕ´Ï´Ù.
FTZÀÇ °æ¿ì¿£ /bin µð·ºÅ丮¿¡ µé¾îÀִµ¥ °£´ÜÇÑ ¼Ò½º´Â ÀÌ·¯ÇÕ´Ï´Ù.

#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>

int main(){

int i,a;

i = geteuid();
a = getuid();
system("clear");

if( i == 3001 ) printf("\nLevel1 Password is \"ºí¶óºí¶óºí¶ó\".\n\n");
if( i == 3002 ) printf("\nLevel2 Password is \"ºí¶óºí¶óºí¶ó\".\n\n");
....
}
2012/01/01