½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   Deferto
   http://deferto.tistory.com/
   Æäµµ¶ó ¿øÁ¤´ë 3 gate ¹®Á¦ Áú¹®ÀÔ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1721 [º¹»ç]


Æäµµ¶ó¿øÁ¤´ë gate->iron_golem ¿¡´ëÇØ¼­ Àǹ®Á¡ÀÌ °¡ Áú¹®µå¸³´Ï´Ù.
¿©±â¼­ fake ebp¸¦ »ç¿ëÇØ ½©À» ȹµæÇÏ°Ô µÇ´Âµ¥
±× °úÁ¤¿¡¼­  
int main()
{
        setreuid(geteuid(),geteuid());
        execl("/bin/sh","",0);
}
ÀÌ·±½ÄÀ¸·Î ¸¸µé°í, À̰÷¿¡ \x01¸¦ ½Éº¼¸¯ ¸µÅ©¸¦ °Å´Âµ¥ ±× ÀÌÀ¯°¡ ¹«¾ùÀ̰í,

"A"*264][GOT address - 8][execl address + 3] ÆäÀ̷ε尡 ÀÌ·¸°Ô µÇ´Âµ¥

execl address¸¦ ³ÖÀ½¿¡µµ ºÒ°úÇϰí À§¿¡ Àִ¼ҽº°¡ ½ÇÇàµÇ´Â ±î´ßÀÌ ¹«¾ùÀΰ¡¿ä?

  Hit : 3964     Date : 2013/11/30 04:42



    
kumi123 ±×³É, &execl AAAA &/bin/sh NULL ³Ö¾îÁּŵµ »ó°üÀº ¾ø½À´Ï´Ù... ÇÏÁö¸¸, À§¿¡ ÀÖ´Â °ªÀ» ½áµµ »ó°üÀº ¾ø´Ù´Â °ÍÀÌÁÒ.. °¡Àå Å« ÀÌÀ¯´Â °£´ÜÇØ¼­ ÀÔ´Ï´Ù.. À§¿Í °°ÀÌ ¸¸µé¾î ÁÙ·Á¸é ²Ï ½Ã°£ÀÌ °É¸®´Â ÀÛ¾÷À̰ŵç¿ä..
±×¸®°í, fake ebp¸¦ Çϸé, ebp°ªÀÌ ¹Ù²î°Ô µÇ°í, execl+3ÀÇ ÁÖ¼Ò( push ebp °¡ µé¾î°¡¸é ¾ÈµÇ¹Ç·Î) ¸¦ ³Ö¾îÁÖ¸é ¹Ù²ï ebp+8¿¡ ¿ä¼Ò°¡ execl ù¹øÂ° ¿ä¼Ò ~~~ µÇ¸é¼­ ½©ÀÌ µûÁö°ÔµË´Ï´Ù.. ÀÌÇØ°¡ ¾È°¡¸é, Á¦ ºí·Î±× °¡¼­ ±¸°æÇϼ¼¿ä.. ÀÚ±â¼Ò°³¿¡ ÀÖ¾î¿ä
2013/12/10