½Ã½ºÅÛ ÇØÅ·

 1574, 5/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   pwnnnt
   °í¼ö´Ôµé²² Áú¹®ÇÕ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=1838 [º¹»ç]


Codegate 2014 - angry doraemon ¹ÙÀ̳ʸ®¸¦ º¸´Ù ÀÌÇØ°¡ ¾È µÅ¼­ Áú¹®ÇÕ´Ï´Ù.


payload += (»ý·«)
paylaod += p32(elf.plt["write"]) # RET ¿µ¿ª
payload += pop3ret
payload += p32(4) + p32(elf.got["read"]) + p32(4) + text section + argv(4)

# Write() ÀÎÀÚ p32(4) + p32(elf.got["read"]) + p32(4)

pop3retÀº gdb peda¸¦ ÅëÇØ °¡Á®¿Í¼­ »ç¿ëÇß½À´Ï´Ù.
payload¸¦ º¸³»¸é eip°¡ argv °ªÀ¸·Î ¼¼Æõ˴ϴÙ.... (??)
±×·¡¼­ Å×½ºÆ®¸¦ Çϱâ À§ÇØ payload¸¦ ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÏ¿´´õ´Ï,

payload += p32(4) + p32(elf.got["read"]) + p32(4) + p32(10) + text section + argv(4)

write()°¡ ³¡³ª¸ç pop3retÀ» ¸¸³ª eip°¡ Á¤»óÀûÀ¸·Î 0xa·Î ¹Ù²î¾ú½À´Ï´Ù.
¿Ö óÀ½ ¸¸µç payload¿¡¼­´Â eip°¡ text section·Î ¹Ù²îÁö ¾Ê´Â °É±î¿ä ?
ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù.... ¤Ì¤Ì¤Ì¤Ì¤Ì¤Ì

* angrydoraemonÀº ¼ÒÄÏÀ» ÀÌ¿ëÇÑ ¹®Á¦ÀÔ´Ï´Ù.



  Hit : 2242     Date : 2017/03/30 12:32



    
ÇØÄð·¯ text sectionÀ̶ó°í ¾²½Å°Ô ¾î¶² ÀνºÆ®·°¼Ç ½ÃÄö½ºÀÇ ÁÖ¼ÒÀÎÁö¸¦ ¾Ë¾Æ¾ß ÇÕ´Ï´Ù
0xa·Î ¼³Á¤ÀÌ µÆ´Ù¸é óÀ½¿¡µµ ºÐ¸íÈ÷ text sectionÀ¸·Î º¯°æµÆÀ»°Å°í ±× Äڵ忡¼­ argv·Î ¸®ÅÏÇϸ鼭 eip°¡ argv·Î ¼³Á¤µÆÀ»°Ì´Ï´Ù
2017/03/30  
pwnnnt °¨»çÇÕ´Ï´Ù :D 2017/03/30  
1494   FTZ - Level12..[1]     ys200209
07/19 2116
1493   BOF ÇÚµåºÏ ½Ã½ºÅÛ ÇØÅ· ¸¶Áö¸·¹®Á¦ Áú¹®ÀÔ´Ï´Ù[1]     deccj97
11/28 2117
1492   RTLÁú¹®![1]     Sp4wn
10/20 2130
1491   ROP Áú¹®ÀÔ´Ï´Ù[2]     turttle2s
09/09 2133
1490   c¾ð¾î ÇÔ¼ö Á¤ÀÇÁß¿¡...     vngkv123
06/20 2139
1489   rop gadgetãÀ» ¶§....[1]     vngkv123
03/30 2141
1488   ptraceÇÔ¼ö¸¦ ÅëÇØ µð¹ö°Å¸¦ ±¸ÇöÇϴµ¥...     vngkv123
09/25 2142
1487   gdb ºÐ¼® disas[5]     ewqqw
04/16 2153
1486   ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ü·Ã[2]     ewqqw
04/20 2158
1485   hex ray Áú¹®[2]     wwwlk
07/16 2165
1484   ret2kernel32? (À©µµ¿ì ret2libc)[3]     choboKing
06/11 2168
1483 ºñ¹Ð±ÛÀÔ´Ï´Ù  destruction[17]     sweetick
06/25 2171
1482   gdb¿¡¼­...[2]     vngkv123
04/05 2174
1481   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2186
1480   shellcode Áú¹®µå¸³´Ï´Ù.[1]     bong93
01/07 2218
1479   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã[1]     ewqqw
04/21 2224
1478   ITºÐ¾ß·Î Áø·Î°í¹ÎÀ̳ª,Ãë¾÷,ÀÌÁ÷°í¹ÎÀ¸·Î ±Ã±ÝÇÑÁ¡µéÀÌ ¸¹À¸½ÃÁÒ~?     koreais0
08/08 2232
  °í¼ö´Ôµé²² Áú¹®ÇÕ´Ï´Ù.[2]     pwnnnt
03/30 2241
1476   heap exploit ±â¹ý °øºÎ ¹æ¹ý....     choboKing
08/09 2241
1475   unlink¸ÅÅ©·Î¿¡¼­ P....[5]     vngkv123
05/12 2259
[1][2][3][4] 5 [6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org