½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   pwntools ¾²½Ã´Â ºÐµé ~

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1979 [º¹»ç]


p = process('./my_elf')

..

p.sendline(payload)
..

print p.recv()    <<< ¿©±â¼­ ¹ÝÀÀÀÌ ¾ø´Âµ¥ ÀÌ°Ç ¹«½¼ °æ¿ìÀΰ¡¿ä?
...

p.interactive()

  Hit : 2505     Date : 2019/09/17 11:31



    
pushrbp recvline() ȤÀº recv(¹ÞÀ»¹ÙÀÌÆ®) ÀÌ·±½ÄÀ¸·Î ÀÛ¼ºÈÄ Ãâ·ÂÇØº¸¼¼¿ë 2019/09/19  
turttle2s ´äº¯°¨»çÇÕ´Ï´Ù.

recvline()Àº ÇØºÃ¾ú´Âµ¥ ¶È°°ÀÌ ¹ÝÀÀÀÌ ¾ø´õ±º¿ä...
³ª¸ÓÁö ¹æ¹ýÀº ³ªÁß¿¡ ÇØº¸°í ¾Ë·Áµå¸±°Ô¿ä
2019/09/19  
turttle2s ¾Æ... ¶È°°³×¿ä. Á¶±ÝÀÇ Èñ¸ÁÀ» °¡Á³°Ç¸¸..

retÀ» read(1, printf@plt, 8)·Î Çߴµ¥ ¿©±â¿¡ ¹®Á¦°¡ ÀÖ³ª¿ä?
2019/09/20  
qkqk123 ex) write(1,printf@got,8); -> printf@got leak ÇÒ ¶§

ex) read(0,printf@got,8); -> printf@got µ¥ÀÌÅÍ ³ÖÀ» ¶§
2019/09/20  
turttle2s ¹ÙÀ̳ʸ®¿¡¼­ write()ÀÇ plt³ª got°¡ ¾ø¾î¼­ leakÀ» write()À¸·Î leakÀ» ÇÒ ¼ö°¡ ¾ø¾î¿ä¤Ð 2019/09/22  
ss4747 ¾È³çÇϼ¼¿ä!!

¸ðÀÇÇØÅ· °¡´ÉÀÚ ¸ðÁý ÁßÀÎ ÇØ¿Ü¾÷üÀÔ´Ï´Ù

¾÷¹«ÀÇ ÁøÇà¹æ½ÄÀº ÇÁ¸®·£¼­ Çü½ÄÀ¸·Î ÀúÈñ°¡ Á¦°øÇص帰

»çÀÌÆ® ¸ðÀÇÇØÅ· ¼º°ø½Ã °Ç´ç À¸·Î Áö±ÞÇØµå¸³´Ï´Ù

ÀÚ¼¼ÇѾȳ»»çÇ×¹× ±âŸ¹®ÀÇ´Â ÅÚ·¡±×·¥ ss4747 ¿©±â·Î ¿¬¶ôÁÖ½Ã¸é »ó¼¼ÇÏ°Ô ¾Ë·Áµå¸®°Ú½À´Ï´Ù
2019/10/04