|
http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1856 [º¹»ç]
#include<stdio.h>
#include<string.h>
int main(int argc, char* argv[]){
int check1 = 0x200a0b00;
int check2 = 0xaabbccdd;
char buffer[20];
strcpy(buffer, argv[1]);
if(check2==0x11223344)
if(check1==0x200a0b00)
system("/bin/sh");
}
.. Àä
±× ÇØÄ¿½ºÄð BOF¿Õ±âÃÊÆíÀ¸·Î °øºÎÇÏ¸é¼ ¾î¶»°Ô ÇØº¸·Á°í ½ÃµµÇß½À´Ï´Ù.
¸Þ¸ð¸®¿¡ ½×ÀÌ´Â ¼ø¼°¡
| BUFFER[20] | check2 | check1 | ÀÌÀݾƿä... ±×·¡¼ ÀÎÀÚ°ª³Ö°í
./BOF1 AAAAAAAAAAAAAAAAAAAA(20°³)`perl -e 'print "\x44\x33\x22\x11"''perl -e 'print "\x00\x0b\x0a\x20"'` Çߴµ¥
¾ÈµÇ´õ¶ó±¸¿ä ¤¾¤¾¤¾ (little edian Àû¿ë Çß½À´Ï´Ù)
Á¶¾ðºÎʵå·Á¿ä ¤Ð¤Ð |
Hit : 2903 Date : 2017/04/16 02:36
|