http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=1838 [º¹»ç]
Codegate 2014 - angry doraemon ¹ÙÀ̳ʸ®¸¦ º¸´Ù ÀÌÇØ°¡ ¾È µÅ¼ Áú¹®ÇÕ´Ï´Ù.
payload += (»ý·«)
paylaod += p32(elf.plt["write"]) # RET ¿µ¿ª
payload += pop3ret
payload += p32(4) + p32(elf.got["read"]) + p32(4) + text section + argv(4)
# Write() ÀÎÀÚ p32(4) + p32(elf.got["read"]) + p32(4)
pop3retÀº gdb peda¸¦ ÅëÇØ °¡Á®¿Í¼ »ç¿ëÇß½À´Ï´Ù.
payload¸¦ º¸³»¸é eip°¡ argv °ªÀ¸·Î ¼¼Æõ˴ϴÙ.... (??)
±×·¡¼ Å×½ºÆ®¸¦ Çϱâ À§ÇØ payload¸¦ ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÏ¿´´õ´Ï,
payload += p32(4) + p32(elf.got["read"]) + p32(4) + p32(10) + text section + argv(4)
write()°¡ ³¡³ª¸ç pop3retÀ» ¸¸³ª eip°¡ Á¤»óÀûÀ¸·Î 0xa·Î ¹Ù²î¾ú½À´Ï´Ù.
¿Ö óÀ½ ¸¸µç payload¿¡¼´Â eip°¡ text section·Î ¹Ù²îÁö ¾Ê´Â °É±î¿ä ?
ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù.... ¤Ì¤Ì¤Ì¤Ì¤Ì¤Ì
* angrydoraemonÀº ¼ÒÄÏÀ» ÀÌ¿ëÇÑ ¹®Á¦ÀÔ´Ï´Ù.
|
Hit : 2242 Date : 2017/03/30 12:32
|