22016, 13/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   parkchul
   /bin/bash

http://www.hackerschool.org/HS_Boards/zboard.php?desc=asc&no=33639 [º¹»ç]


¾È³çÇϽʴϱî, Linux¸¦ È¥ÀÚ¼­ ¶Òµü´ë°í µ¶ÇÐÇÑÁö 7ÀÏ µÇ´Â ¿ÕÃʺ¸ ÀÔ´Ï´Ù
ftz ¿¡¼­ °­Á¸¦ º¸¸é¼­ µû¶ó Çߴµ¥ ÀÌÇؾȵǴ ºÎºÐÀÌ À־
ÀÌ·¸°Ô ¿Ã¸³´Ï´Ù, ²À ºÎŹ µå¸³´Ï´Ù

½Ã³ª¸®¿À: user level 2ÀÇ ºñ¹Ð¹øÈ£À» ã¾Æ¶ó (³ª´Â level1)
             level 2 ¶ó´Â À¯Àú¿¡¼­ setUID ¹æ¹®ÀÌ °¡´ÉÇÑ °÷ÀÌ ÀÖ½À´Ï´Ù
             ÇØ´ç ¹®¼­?¸¦ ½ÇÇà ½ÃÅ°¸é level2ÀÇ ±ÇÇÑÀ¸·Î
             µü ÇѹøÀÇ ¸í·ÉÀ» ¼öÇàÇÒ¼ö Àִµ¥
             my-pass ¿Í chmod´Â Á¦¿Ü°¡ µË´Ï´Ù,(½ÇÇà½Ã ±ÇÇÑ ¹ÚÅ»)

´ä      ¾È:  ÀÎÅÍ³Ý °­Á¸¦ ã¾Æº¸°í Ç®¾ú´Âµ¥¿ä,,,
              ¾Æ±î À§ÀÇ ´Ü ÇѹøÀÇ ¸í·ÉÀ» ¼öÇàÇÒ¼ö ÀÖÀ»¶§
               /bin/bash·Î ÇÏ´Ï ¾Æ¿¹ level2°í ³Ñ¾î¿Í¼­
               my-pass¸¦ »ç¿ëÇÒ¼ö ÀÖ°Ô µÇµå¸®±¸¿ä

ÀÇ     ¹®: 1. bash  ¶ó°í Çϴ°ÍÀº shell À̶ó°í Çϴµ¥ µµ´ëü ¹ºÁö?
                 À¯Àú¿Í ÄÄÇ»ÅÍÀÇ ±³·ù¸¦ Çϴ°Ŷó°í Çϴµ¥......
              2.  /bin/bash  ¸í·ÉÀ» º¸³»¸é ¾î¶»°Ô level2·Î ³Ñ¾î°¡´ÂÁö?

¿¡     ÇÊ: ½©ÀÌ ¶ó°í´Â Çϴµ¥ ÀÎÅͳݿ¡¼­ ¶ÑÁ® º¸¾ÒÀ¸³ª ¿ÕÃʺ¸¶ó¼­
              µµÀúÈ÷ ¹¹¶ó°í ÇÏ´ÂÁö °¨ÀÌ ¾ø¾î¼­
              ÀÌ·¸°Ô ¿Ã·Á µå¸®¿À´Ï
               °í¼ö´Ôµé~7ÀÏµÈ ÇÞ³»±â Àß~ ºÎŹ µå¸³´Ï´Ù!  °¨»çÇÕ´Ï´Ù!!

  Hit : 5371     Date : 2016/02/14 10:58



    
swkim306 ¼ÐÀº ÇϳªÀÇ ÇÁ·Î±×·¥ÀÌ¿¡¿ä
±ô±ôÇÑ È­¸é¼Ó¿¡¼­ ¼ÐÀ̶õ ÇÁ·Î±×·¥À» ÀÌ¿ëÇؼ­ ÄÄÇ»ÅÍ(¿î¿µÃ¼Á¦)¿Í ´ëÈ­Çϴ°̴ϴÙ.
¿î¿µÃ¼Á¦¸¦ ÀÌ¿ëÇؼ­ Çϵå¿þ¾î¸¦ Á¶ÀÛÇÑ´Ù´Â°Ç ¾ËÁö¿ä?
ÀÌ ¿î¿µÃ¼Á¦¿Í »ç¿ëÀÚ »çÀÌ¿¡ ¼ÐÀ̶õ ÇÁ·Î±×·¥ÀÌ Àִ°ſ¡¿ä.
¿î¿µÃ¼Á¦¸¦ ÅëÇØ Æú´õÇϳª¸¦ ¸¸µå´Âµ¥¿¡´Â ²Ï³ª ±ä ÇÔ¼ö°¡ ÇÊ¿äÇÏÁö¸¸ ¼ÐÀ»ÀÌ¿ëÇϸé,
mkdir 'Æú´õÀ̸§'
ÀÌ·¸°Ô °£´ÜÈ÷ ÇÑÁÙ·Î µÇ´Â°ÅÁö¿ä. (¼Ð¿¡ ±×·± ÀÛ¾÷µéÀÌ ¸ðµÎ ÇÁ·Î±×·¡¹Ö µÇ¾îÀִ°̴ϴÙ.)

bash¶ó´Â°Ç ¼ÐÇÁ·Î±×·¥Áß ÇϳªÀÌ°í¿ä.
/bin/bash ¸í·ÉÀ» ÀÔ·ÂÇϽøé level2ÀÇ ±ÇÇÑÀÎ ¼ÐÀ» ¾ò°ÔµÇ´Â°Ì´Ï´Ù. (level2±ÇÇÑÀÇ ¼ÐÀ» ½ÇÇà½ÃÅ´)
ÀÌ level2±ÇÇÑÀÇ ¼Ð·Î my-pass ¸¦ ½ÇÇàÇغ¸¸é level2ÀÇ Æнº¿öµå¸¦ º¼¼öÀÖ°ÚÁÒ?
ÀÌ Æнº¿öµå·Î ÈÄ¿¡ level2 ·Î ·Î±×ÀÎÇÏ¸é µÇ´Â°Å¿¡¿ä. (login : level2 / passwd : ~~~~)
2016/03/11  
parkchul swkim306´Ô, Â÷±Ù°í ¾Ë±â½±°Ô ¼³¸íÇÏ¿© Áּż­ ´ë´ÜÈ÷ °¨»çÇÕ´Ï´Ù 2016/03/13  
21776   ..ÇØÄ¿.Ãʺ¸°¡ ¼±¹è´Ôµé²²..ÀÚ¹®Á» ±¸ÇÒ°Ô¿ä..[1]     the0258
11/01 6897
21775   ..ÈåÀ½ ÇØÄ𸮴ª½ºÃ¥...[2]     asd3253
10/24 8533
21774   ..¾î.. ±×·¯´Ï±î..[4]     qw7995
05/18 6232
21773   ./ ¿Í ../ ÀÇ Â÷ÀÌÁ¡.[4]     awsedr45
05/13 8103
21772   .dolphin´ÔÀÌ ¤LÀÀÀ» ½ÃÀüÇÏ¿´½À´Ï´Ù.[3]     .Dolphin
11/28 9878
21771   .NET JointOwnership Study¸ðÁýÇÕ´Ï´Ù.[5]     master0
02/25 7092
21770   .pot ¾Æ½Ã´Â ºÐÀÌ ¾ø´Â°Ç°¡¿ä???     kaelhkim
11/08 6657
21769   .potÆÄÀÏ °øÀ¯ÇØ ÁÖ½Ç »Ó ã½À´Ï´Ù..[3]     kaelhkim
11/06 6914
21768   .soÆÄÀϾ°ÔÇϳª¿ä     qw3709
05/15 6157
21767   // ´Ý¾Ò½À´Ï´Ù ..[8]     buff3r
02/19 6415
21766   /bin/bash[4]     TalVez
05/05 6799
  /bin/bash[2]     parkchul
02/14 5370
21764   /bin/bash : ¿¡ ´ëÇؼ­ ÀÌÇØ°¡ À߾ȵ˴ϴÙ. µµ¿ÍÁÖ¼¼¿ä.[9]     aplombna
01/17 7277
21763   /bin/bash2´Â À§´ëÇß´Ù[5]     µÎ·ç¹¶¼ú
04/04 7273
21762   /usr/bin/level5 ÆÄÀÏÀ¸·Î Àå³­Ä¡½ÅºÐ?[3]     ArtHacker7
11/14 7117
21761 ºñ¹Ð±ÛÀÔ´Ï´Ù  0[2]     pjh1351
02/28 474
21760   0-Day exploit hacking using linux[4]     nsh009
01/13 6760
21759   03. 10. 24. AM 07:41 ºÐ.. ftz ´Ù¿î?[7]     indra
10/24 7551
21758   06 ´ëÇб³ Áß¿¡ ¾È¿­¸®´Â °Íµé     th3425
09/18 5917
21757   08¿îµ¿Àå¿¡ ¾Èµé¾î°¡Á®¿ä.[2]     js147
10/09 6461
[1]..[11][12] 13 [14][15][16][17][18][19][20]..[1101]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org