½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   RTL Áú¹® ÀÔ´Ï´Ù

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1955 [º¹»ç]


Ubuntu 18.04 LTS ¹öÀü¿¡¼­ RTL ¿¬½À°íÀÖ½À´Ï´Ù.

RTL À̱⶧¹®¿¡ ½ºÅÿ¡ ½ÇÇà±ÇÇѸ¸ »©°í ³ª¸ÓÁö º¸È£±â¹ýÀº ÇØÁ¦Çß°í, 32bit ÄÄÆÄÀÏ Çß½À´Ï´Ù.
ASLRµµ ÇØÁ¦Çß½À´Ï´Ù. ( /proc/sys/kernel/randomize_va_space = 0 )
system ÇÔ¼ö ÁÖ¼Ò, /bin/sh ÀÇ ½ÃÀÛÁÖ¼Òµµ ã°í RTL ±â¹ýÀ¸·Î Á¦°¡¸¸µç Ãë¾àÇÑ ÇÁ·Î±×·¥ ÀͽºÇ÷ÎÀÕÀ» Çϸé Segmentation Fault ¿¡·¯°¡ ¶å´Ï´Ù.

Ȥ½Ã ÀÌ·± °æÇè ÇØº¸½Å ¼±»ý´Ôµé °è½Ã¸é Á¶¾ðÁ» ºÎʵ右´Ï´Ù. ¤Ð¤Ð

  Hit : 3420     Date : 2019/01/11 10:17



    
qw3709 32bit RTl½Ã¿¡´Â buff | ebp | ret ¿¡¼­ ret¿¡ systemÀ»¾²°í ´ÙÀ½ 4byte´Â ´ÙÀ½ÇÔ¼ö¿¬°è¸¦À§ÇÑ rop_gadgetÀ̳ª exit()ÇÔ¼ö¸¦ ¾²½Ã°í ±×´ÙÀ½ 4byteºÎÅÍ /bin/sh ÀÎÀÚ¸¦³Ö¾îÁÖ¸éµË´Ï´Ù. system("/bin/sh")¸¸ ½ÇÇàÇϽDz¨¸é ret´ÙÀ½ 4byte´Â±×³É 0À¸·Î ºñ¿ì¼ÅµµµÇ¿ä 2019/01/14  
turttle2s gdb·Î ±îº¸´Ï±î ¸¶Áö¸· ÁÙ¿¡

leave
lea esp, [ecx-0x4] << ?????
ret

ÀÌ·¸°Ô µÇÀÖ¾ú½À´Ï´Ù. ecx¿¡´Â systemÇÔ¼ö ´ÙÀ½ 4¹ÙÀÌÆ®¿¡ ³ÖÀº 'aaaa'°ªÀÌ µé¾îÀִµ¥ ÀÌ ¸í·ÉÀÌ
-fno-builtin ¿É¼ÇÀ» ÁÖ¸é ¾ø¾îÁö³×¿ä.
ÀÌ°Ô ¹¹ÇÏ´Â ¸í·ÉÀΰ¡¿ä?
2019/01/18  
turttle2s Àú°Å¶§¹®¿¡ °è¼Ó Áß°£¿¡ Segmentation Fault ¶ß´Âµ¥...
-fno-builtin ¿É¼ÇÀ» Á༭ Àú ¸í·ÉÀ» ¾ø¾Ö¸é RTLÀÌ µË´Ï´Ù.
2019/01/18  
qw3709 -fno-buiiltinÀÌ ¶óÀ̺귯¸®¶û ¸µÅ©¾ÈµÇ°ÔÇϴ°ǵ¥
Àú°Å´Â ±×³É leaveÀü¿¡ ºê·¹ÀÌÅ©Æ÷ÀÎÅ͸¦ °É¾î¼­ ¸Þ¸ð¸®È®ÀÎÇØº¸½Ã°í ecx-0x4À§Ä¡¿¡ systemÀ̵é¾î°¡°Ô ÇϽøéµÇ¿ä.
2019/01/22