97, 2/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   angr¿¡¼­ ½ºÅà ÁÖ¼Ò ±¸Çϱâ

http://www.hackerschool.org/HS_Boards/zboard.php?desc=desc&no=129 [º¹»ç]


angr¿¡¼­ ½ºÅÃÀ¸·Î ¸®ÅÏÇÏ´Â ½ºÅ©¸³Æ®¸¦ ¸¸µé·Á°íÇÕ´Ï´Ù.
(aslrÀº ²¨Á®ÀÖ½À´Ï´Ù.)
±×·±µ¥ ±âº»ÀûÀ¸·Î angr¿¡¼­ sp¶û gdb·Î È®ÀÎÇßÀ» ¶§ sp¶û Â÷ÀÌ°¡ ³³´Ï´Ù.

[ === angr ÄÚµå === ]
# base.py
import angr, claripy
import code
import sys
from angr import sim_options as so

def main():
    proj = angr.Project("./t2",load_options={"auto_load_libs":False})
    extras = {so.REVERSE_MEMORY_NAME_MAP, so.UNICORN_TRACK_STACK_POINTERS}
    main_addr = proj.loader.find_symbol("main").rebased_addr
    st = proj.factory.call_state(main_addr, add_options=extras)
    print(st.regs.pc)
    print(st.regs.sp)
    #sm = proj.factory.simulation_manager(st)

#    code.interact(local=locals())

if __name__ == "__main__":
    main()

[ === angr°á°ú === ]
$python base.py
<BV32 0x8049162>
<BV32 0x7ffefffc>


[ == gdb == ]
gdb-peda$ b *main
Breakpoint 1 at 0x8049162
gdb-peda$ r
gdb-peda$ p/x $eip
$2 = 0x8049162
gdb-peda$ p/x $esp
$3 = 0xffffd51c
gdb-peda$



angr¿¡¼­´Â 0x7f·Î ½ÃÀÛÇÏÁö¸¸, gdb¿¡¼­ È®ÀÎÇغ¸¸é 0xff·Î ½ÃÀÛÇÕ´Ï´Ù.
angr¿¡¼­´Â ¹ÙÀ̳ʸ®¸¦ cle°¡ µû·Î ·ÎµåÇϱ⠶§¹®¿¡ ½ÇÁ¦ ½ºÅà ÁÖ¼Ò¶û ´Ù¸¦ °ÍÀ̶ó°í ¿¹»óÀº ÇÏÁö¸¸, ¹®Á¦´Â ÀÌ°Ì´Ï´Ù.
angr¿¡¼­ Ãë¾àÇÑ »óŸ¦ ã°í ½ºÅÃÀ¸·Î ¸®ÅÏÇÏ´Â ÀͽºÇ÷ÎÀÕÀ» »ý¼ºÇÏ·Á¸é ÁÖ¼Ò¸¦ ¾Ë¾Æ¾ßÇϴµ¥, angr¸¸À¸·Î´Â ºÒ°¡´ÉÇÑ°Ç°¡¿ä?

  Hit : 1837     Date : 2021/05/24 12:35



    
turttle2s ½ºÅÃÀº º¯µ¿ÀÌ Ä¿¼­ angr¿¡¼­´Â ´Ù·çÁö ¾Ê´Â´Ù³×¿ä 2021/05/26  
±ºÀÎ ÇØ°á¿Ï·á 2021/05/31  
somass ÅÃÀº º¯µ¿ÀÌ Ä¿¼­ angr¿¡¼­´Â ´Ù·çÁö ¾Ê´Â´Ù³×¿ä 2022/09/16  
77   ¾Æ½ºÅ° ¹üÀ§ ¹Û ÆäÀ̷εå Àü¼Û ½Ã, 0xc2°¡ ºÙ´Â Çö»ó[7]     turttle2s
05/11 1766
  angr¿¡¼­ ½ºÅà ÁÖ¼Ò ±¸Çϱâ[3]     turttle2s
05/24 1836
75   ÆÄÀÏÀ» ºÐ¼®ÇÏ°í ½Í¾î¿ä[6]     tmchojo
11/22 4279
74   ¸®¹ö½º ¿£Áö´Ï¾î¸µ ¹ÙÀ̺íÀ» Àдٰ¡ ±Ã±ÝÇÑ Á¡ÀÌ »ý°å´Âµ¥¿ä¤Ð![1]     tjswn7051
10/14 3516
73   ¸®¹ö½ºÇؼ­ ³ª¿Â °á°ú¿¡ ´ëÇØ Áú¹®ÀÔ´Ï´Ù.[2]     sym4943
04/14 2824
72   ¹®ÀÚ¿­À» ¹®ÀÚ¿­·Î ³ª´©´Â°Ô ¾î¶² Àǹ̰¡ ÀÖÀ»±î¿ä?     swkim306
03/11 3036
71   dll ¸®¹ö½ÌÁú¹®.     stares
12/21 6086
70   ¾ðÆÐÅ· °ü·Ã Áú¹®ÀÔ´Ï´Ù.     spe
11/09 3099
69   ¾ðÆÐÅ· °ü·Ã Áú¹®ÀÔ´Ï´Ù2     spe
11/09 3988
68   dll ¸®¹ö½Ì ÇÒ ¶§ ÁÖ¼Ò °è»ê¹ý Áú¹®ÀÌ¿ä¤Ð![3]     spe
12/26 3943
67   Æ÷¸Ë½ºÆ®¸µ °ø°Ý Áú¹®[4]     sohun5013
01/11 3143
66   ¸®¹ö½Ì(¾î¼Àºí¸®¾î) ±âÃÊ Áú¹®Á» µå¸®°Ú½À´Ï´Ù[2]     skyclad1975
12/10 3309
65   gdb ¿¡¼­ display·Î º¯¼ö¸¦ º¸´Â °Í¿¡ ´ëÇÑ Áú¹®[1]     skyclad1975
12/11 2983
64   DWORD PTR SS ¿Í DWORD PTR DS[1]     skyclad1975
01/24 5853
63   ollydbg ÆĶó¹ÌÅÍ ³Ö´Â ¹ý[2]     skyclad1975
02/08 4933
62   ¸®¹ö½Ì ÀÔ¹®ÇÏ°í ½Í¾î¼­ Áú¹®µå¸³´Ï´Ù.[2]     shdac
09/27 4034
61   ¸®¹ö½Ì ÀÔ¹®ÀÚÀÔ´Ï´Ù     shdac
10/12 2804
60   ¸®¹ö½Ì Ãʺ¸ÀÔ´Ï´Ù. IDA¿¡ ´ëÇÑ Áú¹®ÀÖ½À´Ï´Ù.[3]     shdac
10/29 3830
59   quickbms ÀÇ ¿ø¸®°¡ ±Ã±ÝÇÕ´Ï´Ù.     sa0814
05/10 1991
58   ¸®¹ö½Ì °ü·ÃÇؼ­ ¼±¹è´Ôµé¿¡°Ô Áú¹®µå¸®°í ½ÍÀº°ÔÀִµ¥¿ä.     rptprl123
10/12 3058
[1] 2 [3][4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org