½Ã½ºÅÛ ÇØÅ·

 1574, 5/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   Sp4wn
   RTLÁú¹®!

http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=1945 [º¹»ç]


¾È³çÇϼ¼¿ä À̹ø¿¡ ´Þ°í³ª´Ô BOF¹®¼­ º¸°í »õ·Î ½ÃÀÛÇÏ°ÔµÈ »ç¶÷ÀÔ´Ï´Ù
¹è¿ì´Ù°¡ ±Ã±ÝÇÑ°Ô À־ Áú¹®µå¸³´Ï´Ù!

gdb) disass main
Dump of assembler code for function main:
0x080481d0 <main+0>:    push   %ebp
0x080481d1 <main+1>:    mov    %esp,%ebp
0x080481d3 <main+3>:    sub    $0x8,%esp
0x080481d6 <main+6>:    and    $0xfffffff0,%esp
0x080481d9 <main+9>:    mov    $0x0,%eax
0x080481de <main+14>:   sub    %eax,%esp
0x080481e0 <main+16>:   call   0x8048898 <system>
0x080481e5 <main+21>:   leave
0x080481e6 <main+22>:   ret
0x080481e7 <main+23>:   nop
End of assembler dump.
(gdb) disass __libc_system
Dump of assembler code for function system:
0x08048898 <system+0>:  push   %ebp
0x08048899 <system+1>:  mov    %esp,%ebp
0x0804889b <system+3>:  push   %esi
0x0804889c <system+4>:  push   %ebx
0x0804889d <system+5>:  mov    0x8(%ebp),%ebx
0x080488a0 <system+8>:  test   %ebx,%ebx
0x080488a2 <system+10>: je     0x80488da <system+66>
0x080488a4 <system+12>: mov    0x80a4b14,%eax
0x080488a9 <system+17>: test   %eax,%eax
0x080488ab <system+19>: jne    0x80488b8 <system+32>
0x080488ad <system+21>: mov    %ebx,0x8(%ebp)
0x080488b0 <system+24>: lea    0xfffffff8(%ebp),%esp
0x080488b3 <system+27>: pop    %ebx
0x080488b4 <system+28>: pop    %esi
0x080488b5 <system+29>: leave
0x080488b6 <system+30>: jmp    0x80488f4 <do_system>
0x080488b8 <system+32>: call   0x804e548 <__libc_enable_asynccancel>
0x080488bd <system+37>: sub    $0xc,%esp
0x080488c0 <system+40>: push   %ebx
0x080488c1 <system+41>: mov    %eax,%esi
0x080488c3 <system+43>: call   0x80488f4 <do_system>
0x080488c8 <system+48>: mov    %eax,%ebx
0x080488ca <system+50>: mov    %esi,%eax
0x080488cc <system+52>: call   0x804e58c <__libc_disable_asynccancel>
0x080488d1 <system+57>: mov    %ebx,%eax
0x080488d3 <system+59>: lea    0xfffffff8(%ebp),%esp
0x080488d6 <system+62>: pop    %ebx
0x080488d7 <system+63>: pop    %esi
0x080488d8 <system+64>: leave
0x080488d9 <system+65>: ret

¸ÞÀÎÇÔ¼ö¿¡ system()ÇÔ¼ö¸¸ ³ÖÀºÃ¤·Î systemÇÔ¼öÀÇ argument°úÁ¤À» µð½º¾î¼Àºí¸®ÇÑ °á°úÀä ÇÔ¼ö ÇÁ·Ñ·Î±× ¸¶Ä¡°í ebp±âÁØ +8ÀÇ ÁÖ¼Ò°ªÀ» ebx¿¡ ³Ö´Â°Å±îÁö´Â ¾Ë°Í°°Àºµ¥ ±× ¾Æ·¡ÀÖ´Â °úÁ¤µéÀ» ¸ð¸£°Ú¾î¿ä ¤Ð.¤Ð

0x080488a0 <system+8>:  test   %ebx,%ebx
0x080488a2 <system+10>: je     0x80488da <system+66>
0x080488a4 <system+12>: mov    0x80a4b14,%eax
0x080488a9 <system+17>: test   %eax,%eax
0x080488ab <system+19>: jne    0x80488b8 <system+32>
0x080488ad <system+21>: mov    %ebx,0x8(%ebp)
0x080488b0 <system+24>: lea    0xfffffff8(%ebp),%esp
0x080488b3 <system+27>: pop    %ebx
0x080488b4 <system+28>: pop    %esi
0x080488b5 <system+29>: leave
0x080488b6 <system+30>: jmp    0x80488f4 <do_system>
0x080488b8 <system+32>: call   0x804e548 <__libc_enable_asynccancel>
0x080488bd <system+37>: sub    $0xc,%esp
0x080488c0 <system+40>: push   %ebx
0x080488c1 <system+41>: mov    %eax,%esi
0x080488c3 <system+43>: call   0x80488f4 <do_system>
0x080488c8 <system+48>: mov    %eax,%ebx
0x080488ca <system+50>: mov    %esi,%eax
0x080488cc <system+52>: call   0x804e58c <__libc_disable_asynccancel>
0x080488d1 <system+57>: mov    %ebx,%eax
0x080488d3 <system+59>: lea    0xfffffff8(%ebp),%esp
0x080488d6 <system+62>: pop    %ebx
0x080488d7 <system+63>: pop    %esi
0x080488d8 <system+64>: leave
0x080488d9 <system+65>: ret

Á¦°¡ ¸ð¸£°Ú´Â ºÎºÐÀԴϴ٠Ȥ½Ã ÀÚ¼¼ÇÏ°Ô ¼³¸íÇØÁֽǼöÀÖ´Â ºÐ
Á¦¹ß ¼³¸íÇØÁÖ½Ã¸é °¨»çÇÏ°Ú½À´Ï´Ù¤Ð¤Ð

  Hit : 2131     Date : 2018/10/20 10:44



    
±ºÀÎ Return To Libc ±â¹ýÀ» ¸»¾¸ÇÏ½Ã´Â°Å¸é ¾à°£ Âø¿À°¡ ÀÖÀ¸½Å °Í °°½À´Ï´Ù.
ƯÀÌ»çÇ×À» Á¦¿ÜÇϸé, ´õ±º´Ù³ª ±âÃÊ ¹®¼­ ¹× ¹®Á¦¿¡¼­ ±»ÀÌ system ÇÔ¼öÀÇ ³»ºÎ¸¦ »ó¼¼ÇÏ°Ô ºÐ¼®ÇÒ ÇÊ¿ä±îÁö´Â ¾øÀ» °Ì´Ï´Ù.
2018/10/22  
1494   FTZ - Level12..[1]     ys200209
07/19 2116
1493   BOF ÇÚµåºÏ ½Ã½ºÅÛ ÇØÅ· ¸¶Áö¸·¹®Á¦ Áú¹®ÀÔ´Ï´Ù[1]     deccj97
11/28 2118
  RTLÁú¹®![1]     Sp4wn
10/20 2130
1491   ROP Áú¹®ÀÔ´Ï´Ù[2]     turttle2s
09/09 2134
1490   c¾ð¾î ÇÔ¼ö Á¤ÀÇÁß¿¡...     vngkv123
06/20 2139
1489   rop gadgetãÀ» ¶§....[1]     vngkv123
03/30 2142
1488   ptraceÇÔ¼ö¸¦ ÅëÇØ µð¹ö°Å¸¦ ±¸ÇöÇϴµ¥...     vngkv123
09/25 2142
1487   gdb ºÐ¼® disas[5]     ewqqw
04/16 2153
1486   ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ü·Ã[2]     ewqqw
04/20 2159
1485   hex ray Áú¹®[2]     wwwlk
07/16 2165
1484   ret2kernel32? (À©µµ¿ì ret2libc)[3]     choboKing
06/11 2169
1483 ºñ¹Ð±ÛÀÔ´Ï´Ù  destruction[17]     sweetick
06/25 2171
1482   gdb¿¡¼­...[2]     vngkv123
04/05 2175
1481   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2187
1480   shellcode Áú¹®µå¸³´Ï´Ù.[1]     bong93
01/07 2218
1479   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã[1]     ewqqw
04/21 2224
1478   ITºÐ¾ß·Î Áø·Î°í¹ÎÀ̳ª,Ãë¾÷,ÀÌÁ÷°í¹ÎÀ¸·Î ±Ã±ÝÇÑÁ¡µéÀÌ ¸¹À¸½ÃÁÒ~?     koreais0
08/08 2233
1477   heap exploit ±â¹ý °øºÎ ¹æ¹ý....     choboKing
08/09 2241
1476   °í¼ö´Ôµé²² Áú¹®ÇÕ´Ï´Ù.[2]     pwnnnt
03/30 2242
1475   unlink¸ÅÅ©·Î¿¡¼­ P....[5]     vngkv123
05/12 2259
[1][2][3][4] 5 [6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org