½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   vngkv123
   fuzzer¸¦ ±¸ÇöÇϰí½ÍÀºµ¥...

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1896 [º¹»ç]


´Ü¼øÇÏ°Ô ¹ÙÀ̳ʸ® exploitÇϰųª, ºÐ¼®ÇÏ´Â°É ³Ñ¾î¼­
ÆÛÁ®¸¦ °³ÀÎÀûÀ¸·Î API¼öÁغÎÅÍ ±¸ÇöÇØº¸°í ½ÍÀºµ¥,
±¦ÂúÀº ÀÚ·áµéÀÌ ¾øÀ»±î¿ä ¤Ð

  Hit : 5168     Date : 2017/08/25 01:40



    
±è´äº¯ ÆÛÁ®¸¦ °Ë»ö¸¸Çصµ À¢¸¸ÇÑ°Ç ³ª¿À´Ï Á» ¾µ¸¸ÇÏ°í ¸ÚÀÖ´Â ÆÛÁ®¸¦ ¸¸µé°í ½ÍÀ¸½Å °Í °°½À´Ï´Ù
¸ÚÀÖ´Â ÆÛÁ®¸¦ ¸¸µç´Ü°Ç Áö±Ý±îÁö ³ª¿Â ÆÛÁ®µéÀ» ¸ðµÎ °øºÎÇϰí ÀÌÇØÇÏ¿© »õ·Î¿î ÀåÁ¡À» ¸¸µé¾î³»°í ´ÜÁ¡À» ¾ø¾Ö´Â ÀÏÀε¥
ÆÛÁ®´Â °£´ÜÇÑ random mutationalºÎÅÍ ½ÃÀÛÇØ¼­, structural fuzzing, in-memory fuzzing, instrumentation based fuzzing ( American Fuzzy Lop ), Program adaptive mutational fuzzing ( Â÷»ó±æ ±³¼ö´Ô ¿¬±¸ ) µîÀ» °ÅÄ¡¸é¼­ ÁøÈ­ÇؿԴµ¥¿ä
'±¸ÇöÇÏ´Â ¹æ¹ý'Àº ±×³É ÇÁ·Î±×·¡¹Ö ½Ç·ÂÀÔ´Ï´Ù. Áß¿äÇÑ°Ç ¾ÆÀ̵ð¾îÁÒ
ÇÁ·Î±×·¡¹Ö ½Ç·ÂÀ» ÆÛÁ®¸¦ ¸¸µé¸é¼­ Ű¿î´Ü°Ç ¾îºÒ¼º¼³À̶ó°í »ý°¢ÇÕ´Ï´Ù. ³²ÀÌ ¸¸µç ¾ÆÀ̵ð¾î¸¦ ¾î¶»°Ô ¾î¶»°Ô ±¸ÇöÇϼ¼¿ä. ¶ó´Â ÀνºÆ®·°¼Ç±îÁö ºÁ°¡¸é¼­ ±¸ÇöÇÒ°Ô ºÐ¸íÇϱ⠶§¹®ÀÌÁÒ. »ç½Ç ÀÌ·¸°Ô °øºÎÇØµµ ±¦Âú±äÇÕ´Ï´Ù. ±×·¡¼­ ¸¹Àº »ç¶÷µéÀÌ ±×·¹ÀÌÇÞÆÄÀ̽ãÀ̳ª °õÃ¥(Fuzzing: Brute Force Vulnerability Discovery)À» º¸¸é¼­ ÆÛÁ® ¸¸µå´Â¹ýÀ» °øºÎÇß¾ú±¸¿ä
AFL¸¸ º¸°í ÀÌÇØÇØµµ Çö´ë ÆÛ¡±â¹ý¿¡ ¸¹ÀÌ °¡±î¿öÁö¼Ì´Ù°í ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÆÐ·¯´ÙÀÓÀ» ¹Ù²Û ÆÛÁ®ÀÔ´Ï´Ù
2017/08/25  
±è´äº¯ À§¿¡¼­ ¼Ò°³ÇÑ Ã¥µéÀº
±×·¹ÀÌÇÞÆÄÀ̽ã - http://www.acornpub.co.kr/book/python-hacking#toc
°õÃ¥ - http://www.kyobobook.co.kr/product/detailViewEng.laf?ejkGb=BNT&mallGb=ENG&barcode=9780321446114&orderClick=LAG&Kc=
2017/08/25  
vngkv123 Ä£ÀýÇÑ ´äº¯ °¨»çÇÕ´Ï´Ù ¤¾¤¾ 2017/08/25