½Ã½ºÅÛ ÇØÅ·

 1574, 17/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ±ÀèÀÌ
   http://jack2.tistory.com
   [BOF] Hackerschool Handbook#1 BOF ¿Õ±âÃÊÆí p.121¿¡¼­

http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=1589 [º¹»ç]


½Ç½À ³»¿ëó·³ RET(¸®ÅÏ ¾îµå·¹½º)¸¦ 0xdeadbeef·Î ¹Ù²Ù·Á°í ÇÕ´Ï´Ù.
¼Ò½ºÄÚµå´Â ¾Æ·¡¿Í °°½À´Ï´Ù.

Jack2@SchoolPC ~/BOF/12
$ cat ex3.c
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include "dumpcode.h"

int main(int argc, char *argv[])
{
        char buffer[20] = {0,};         //0À¸·Î ÃʱâÈ­
        int *pointer_to_ret = (int *)(buffer+24);       //ret¸¦ Ãâ·ÂÇϱâ À§ÇÑ Æ÷ÀÎÅÍ

        if(argc < 2)
        {
                printf("argument error\n");
                exit(-1);
        }

        //dumpcode·Î ¸Þ¸ð¸® ´ýÇÁ
        dumpcode(buffer, 28);
        printf("[+] BEFORE : the return address is 0x%08x\n\n", *pointer_to_ret);

        //buffer overflow ¹ß»ý!!
        strcpy(buffer, argv[1]);

        //dumpcode·Î ¸Þ¸ð¸® ´ýÇÁ
        dumpcode(buffer, 28);
        printf("[+] AFTER : the return address is 0x%08x\n\n", *pointer_to_ret);
}


¸·»ó 0xdeadbeef·Î ¹Ù²Ù·Á°í Çϴµ¥ ¾Æ·¡¿Í °°Àº °á°ú°¡ ³ªÅ¸³³´Ï´Ù.
Jack2@SchoolPC ~/BOF/12
$ ./ex3 aaaaaaaaaaaaaaaaaaaaaaaa`python -c 'print "\xef\xbe\xad\xde"'`
0x0022ac78 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x0022ac88 00 00 00 00 90 ac 22 00 2f 00 00 00               ......"./...
[+] BEFORE : the return address is 0x0000002f

0x0022ac78 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61  aaaaaaaaaaaaaaaa
0x0022ac88 61 61 61 61 61 61 61 61 ef be ad de               aaaaaaaa....
Segmentation fault (core dumped)


Áï , printf("[+] AFTER : the return address is 0x%08x\n\n", *pointer_to_ret);
ÀÌ Äڵ尡 ½ÇÇàµÇÁö ¾Ê´Âµ¥¿ä...

Ȥ½Ã³ª ÇÏ´Â »ý°¢¿¡ ftz ¼­¹ö¿¡ Á¢¼ÓÀ» ÇÑ µÚ °°Àº ¼Ò½ºÄڵ带 ÄÄÆÄÀÏ ÇÑ °á°ú

[guest@ftz practice]$ ./ex3 aaaaaaaaaaaaaaaaaaaaaaaa`python -c 'print "\xef\xbe\xad\xde"'`
0xbffffa90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0xbffffaa0 00 00 00 00 04 fb ff bf b8 fa ff bf               ............
[+] BEFORE : the return address is 0xbffffab8

0xbffffa90 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61  aaaaaaaaaaaaaaaa
0xbffffaa0 61 61 61 61 61 61 61 61 ef be ad de               aaaaaaaa....
[+] AFTER : the return address is 0xdeadbeef

´ÙÀ½°ú °°ÀÌ Àß ³ªÅ¸³³´Ï´Ù.

Á¦°¡ ½Ç½ÀÇÑ È¯°æÀÌ windows xp cygwin ȯ°æ¿¡¼­ ÄÄÆÄÀÏÀ» Çß½À´Ï´Ù.
±×·¡¼­ ¹®Á¦°¡ »ý±ä°Í °°Àºµ¥
ÀÚ¼¼ÇÑ ¿øÀÎ ¾Æ½Ã´Â ºÐ ÀÖÀ¸½Ã¸é ´äº¯ Á» ºÎŹµå¸±²²¿ä

  Hit : 3386     Date : 2012/06/27 01:55



    
cd80 ÄÚ¾îÆÄÀÏ¿¡¼­ È®ÀÎÇغ¸¼Å¾ß ÇÒ °Í °°³×¿ä
¼¼±×ÆúÀÌ ÀϾÀ»¶© printfÇÔ¼ö°¡ ½ÇÇàÁßÀÏÅ×´Ï ÀÏ´Ü ÄÚ¾îÆÄÀÏ¿¡¼­ ½ºÅÿ¡ ¹¹°¡ Ǫ½¬µÆ³ª º¸½Å Èľȳª¿Â´Ù ½ÍÀ¸¸é gdb·Î Á÷Á¢ ½ÇÇà½ÃÅ°¸é¼­ printf ÀÇ ÀÎÀÚ·Î ¹¹°¡ Ǫ½¬µÇÀÖ³ª È®ÀÎÇغ¸¼¼¿ä
2012/06/28  
1254   ÄíÅ° Çؼ®¿¡ °üÇÑ Á¶¾ð ºÎŹµå¸³´Ï´Ù[1]     ddr6946
08/08 3742
1253   ÀÌ°Å ¾îµð´Ù ½á¾ß ÇÒÁö ¸ô¶ó¼­ ½Ã½ºÅÛ ÇØÅ·¿¡¼­ ¹°¾îº¾´Ï´Ù.[2]     yj6393
07/31 3651
1252   ½©ÄÚµå ¸¸µé°í µ¹¸±‹š... Áú¹®µå¸³´Ï´Ù.[1]     windowhan
07/30 3760
1251   À©Çí½º°¡ ¹¹¿¡¿ä?[1]     yj6393
07/29 3608
1250   IP°¡ ¸î´Þ° ¹Ù²îÁö ¾Ê³×¿ä[2]     falcon89
07/28 2836
1249   ¿¹Àü¿¡ ÇØÄ¿½ºÄð¿¡¼­ º»ÀûÀÖ´Â ÁñãµÇÀÖ´ø ¸µÅ©Áß¿¡¿ä »çÀÌÆ®·Î ¾ÆÀÌÇÇ µû´Â »çÀÌÆ®ÀÖÀÚ³ª¿©?[2]     kmc1993
07/28 10165
1248   À©µµ¿ì CD·Î ±ò°í ¹æÈ­º® ¹é½Å ¼³Ä¡ÇÏÀÚ¸¶ÀÚ ¹Ù·Î ÇØÅ·ÀÌ µË´Ï´Ù     falcon89
07/28 3322
1247   ·£Ä«µå ¸Æ ÁÖ¼Ò¸¸ ¾Ë¸é Àü±¹ ¾îµð¼­µµ ¾Ë ¼ö ÀÖÀ»±î¿ä?[1]     falcon89
07/28 3328
1246   À¯µ¿ IP °ü·Ã Çؼ­ Áú¹® µå¸³´Ï´Ù[1]     ymg1163
07/09 3637
1245   v3´Â ÇÁ·Î±×·¥ÀÇ ¼Ò½ºÄڵ带 º¸°í Ä¡·áÇÏ´Â ÇÁ·Î±×·¥Àΰ¡¿ä?     yj6393
07/08 2968
1244   ¹ÙÀÌ·¯½ºµµ ÇÁ·Î±×·¥Àΰ¡¿ä?[3]     yj6393
07/06 3322
1243   ¸®´ª½º ¹× À¥ÇØÅ·¿¡ ´ëÇØ ¹°¾îº¸¸é ´äº¯ÇØÁ٠ģ±¸³ª Çü´Ôµé..     yw720
07/04 3044
1242   ¼­¹öÆÄÀÏ ¤Ð[3]     wjdqkr312
07/03 3272
  [BOF] Hackerschool Handbook#1 BOF ¿Õ±âÃÊÆí p.121¿¡¼­[1]     ±ÀèÀÌ
06/27 3385
1240   µå¶ó¸¶ À¯·É[2]     hadez
06/27 3241
1239   bof ¿øÁ¤´ë \xFF ¹®Á¦...[1]     supershop
06/22 3799
1238   [BOF] Hackerschool Handbook#1 BOF ¿Õ±âÃÊÆí¿¡¼­...[1]     ±ÀèÀÌ
06/21 3487
1237   wpe pro ÅäÅ©¿ÂÁú¹®ÀÌ¿ä!!     ¿øºó
06/21 11465
1236   OS Á¦ÀÛ ºÎÆ®¼½ÅÍ ºÎºÐ Áú¹®[2]     dhxkgozj
06/14 2837
1235   ¸®´ª½º ÇØÅ· Áú¹® ÀÔ´Ï´Ù (³­¼ö »ç¿ë °ü·Ã)[3]     parkfile
06/01 7176
[1]..[11][12][13][14][15][16] 17 [18][19][20]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org