½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   pwnnnt
   °í¼ö´Ôµé²² Áú¹®ÇÕ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1838 [º¹»ç]


Codegate 2014 - angry doraemon ¹ÙÀ̳ʸ®¸¦ º¸´Ù ÀÌÇØ°¡ ¾È µÅ¼­ Áú¹®ÇÕ´Ï´Ù.


payload += (»ý·«)
paylaod += p32(elf.plt["write"]) # RET ¿µ¿ª
payload += pop3ret
payload += p32(4) + p32(elf.got["read"]) + p32(4) + text section + argv(4)

# Write() ÀÎÀÚ p32(4) + p32(elf.got["read"]) + p32(4)

pop3retÀº gdb peda¸¦ ÅëÇØ °¡Á®¿Í¼­ »ç¿ëÇß½À´Ï´Ù.
payload¸¦ º¸³»¸é eip°¡ argv °ªÀ¸·Î ¼¼ÆÃµË´Ï´Ù.... (??)
±×·¡¼­ Å×½ºÆ®¸¦ Çϱâ À§ÇØ payload¸¦ ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÏ¿´´õ´Ï,

payload += p32(4) + p32(elf.got["read"]) + p32(4) + p32(10) + text section + argv(4)

write()°¡ ³¡³ª¸ç pop3retÀ» ¸¸³ª eip°¡ Á¤»óÀûÀ¸·Î 0xa·Î ¹Ù²î¾ú½À´Ï´Ù.
¿Ö óÀ½ ¸¸µç payload¿¡¼­´Â eip°¡ text section·Î ¹Ù²îÁö ¾Ê´Â °É±î¿ä ?
ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù.... ¤Ì¤Ì¤Ì¤Ì¤Ì¤Ì

* angrydoraemonÀº ¼ÒÄÏÀ» ÀÌ¿ëÇÑ ¹®Á¦ÀÔ´Ï´Ù.



  Hit : 2842     Date : 2017/03/30 12:32



    
ÇØÄð·¯ text sectionÀ̶ó°í ¾²½Å°Ô ¾î¶² ÀνºÆ®·°¼Ç ½ÃÄö½ºÀÇ ÁÖ¼ÒÀÎÁö¸¦ ¾Ë¾Æ¾ß ÇÕ´Ï´Ù
0xa·Î ¼³Á¤ÀÌ µÆ´Ù¸é óÀ½¿¡µµ ºÐ¸íÈ÷ text sectionÀ¸·Î º¯°æµÆÀ»°Å°í ±× Äڵ忡¼­ argv·Î ¸®ÅÏÇϸ鼭 eip°¡ argv·Î ¼³Á¤µÆÀ»°Ì´Ï´Ù
2017/03/30  
pwnnnt °¨»çÇÕ´Ï´Ù :D 2017/03/30