½Ã½ºÅÛ ÇØÅ·

 1576, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   dnjsdnwja
   lob level19(nightmare) °ü·ÃÁú¹®

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=1986 [º¹»ç]


nightmare°°Àº °æ¿ì´Â ´Ùµé stdin file structure ³»ÀÇ buffer¸¦ ÀÌ¿ëÇØ¼­(½©ÄÚµå »ðÀÔ) ¹®Á¦¸¦ Ǫ´Â°ÍÀ¸·Î ¾Ë°í ÀÖ½À´Ï´Ù.

±×·¡¼­ ÀÌ ¹æ¹ýÀ» Àúµµ ÇØº¸´Ï µÇ±â´Â µÇ´Âµ¥ /proc/xxx/maps·Î º¸¸é ºÐ¸í ±× buffer address(´ëºÎºÐÀÇ °æ¿ì 0x40015000)´Â execute permission ÀÌ ¾ø´Â°ÍÀ¸·Î ³ª¿É´Ï´Ù.

µµ´ëü ½©Äڵ尡 ½ÇÇàÀÌ °¡´ÉÇÑ ÀÌÀ¯°¡ ¹«¾ùÀÎÁö µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù °í¼ö´Ôµé.

  Hit : 2474     Date : 2019/12/18 01:22



    
dnjsdnwja ´Ù½Ã º¸´Ï cpuinfo¿¡ nx flag°¡ ¾ø³×¿ä, vmware¸¦ ÅëÇØ guest OS»ó¿¡¼­ nx ¸¦ »ç¿ëÇÏÁö ¾Ê°Ô ÇѰͰ°Àºµ¥ ÀÌ°Í ¶§¹®Àϵí Çϳ׿ä. ÀÌ ÀÌÀ¯°¡ ¾Æ´Ï¶ó¸é Á¶¾ðµå¸³´Ï´Ù. ±×¸®°í ¸Â´ÂÁö µ¿ÀÇÇϽô ºÐµµ ´ä±Û ´Þ¾ÆÁֽøé Á» ´õ È®½ÅÇÒ ¼ö ÀÖÀ»°Í°°³×¿ä ºÎʵ右´Ï´Ù. 2019/12/18