½Ã½ºÅÛ ÇØÅ·

 1574, 74/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ka0r1
   argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë°í ½Í½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?desc=desc&no=1942 [º¹»ç]


[wolfman@localhost wolfman]$ ls
darkelf  darkelf.c
[wolfman@localhost wolfman]$ cat darkelf.c
/*
        The Lord of the BOF : The Fellowship of the BOF
        - darkelf
        - egghunter + buffer hunter + check length of argv[1]
*/

#include <stdio.h>
#include <stdlib.h>

extern char **environ;

main(int argc, char *argv[])
{
        char buffer[40];
        int i;

        if(argc < 2){
                printf("argv error\n");
                exit(0);
        }

        // egghunter
        for(i=0; environ[i]; i++)
                memset(environ[i], 0, strlen(environ[i]));

        if(argv[1][47] != '\xbf')
        {
                printf("stack is still your friend.\n");
                exit(0);
        }

        // check the length of argument
        if(strlen(argv[1]) > 48){
                printf("argument is too long!\n");
                exit(0);
        }

        strcpy(buffer, argv[1]);
        printf("%s\n", buffer);

        // buffer hunter
        memset(buffer, 0, 40);
}
[wolfman@localhost wolfman]$









argv[1]ÀÌ 48ÀÌ ³Ñ¾î°¡¹ö¸®¸é ÇÁ·Î±×·¥ÀÌ Á¾·á°¡ µÇ´Â ÇÁ·Î±×·¥À̳׿ä.
Á¦°¡ ¹®¶à »ý°¢³µ´Âµ¥ argv[2]ÀÇ ÀÎÀÚ·Î ½©Äڵ带 ¿Ã¸®°í
argv[1][44]~argv[1][47]·Î argv[2]ÀÇ ÁÖ¼Ò¸¦ ³ÖÀ¸¸é µÇÁö ¾ÊÀ»±î?¶ó´Â ¾ÆÀ̵ð¾î°¡ ¶°¿Ã¶ú½À´Ï´Ù.
±×·±µ¥ °ø±³·Ó°Ôµµ... argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë ¼ö ÀÖ´Â ¹æ¹ýÀ» ¸ð¸¨´Ï´Ù.
gdb·Î µð¹ö±ëÇÏ¸é ¾Ë ¼öµµ Àְڴµ¥...
¾î¶»°Ô ÇÏ¸é ¾Ë ¼ö ÀÖ³ª¿ä?

  Hit : 2398     Date : 2018/09/23 04:19



    
ka0r1 ½º½º·Î ´äÀ» ã¾Ò½À´Ï´Ù.
(gdb) r `python -c 'print "A"*47+"\xbf"` `python -c 'print "B"*1000'`
±×¸®°í x/1000x $esp ÀÌ·±½ÄÀ¸·Î Çϸé argv[2]ÀÇ ÁÖ¼Ò°¡ º¸ÀÌ±ä º¸À̳׿ä.
Ŭ¸®¾î ¿Ï·á!
2018/09/23  
±ºÀÎ start, main ½ÃÀÛ µÇ´Â ºÎºÐ¿¡ bp ¹Ù·Î °É°í º¸¼Åµµ µË´Ï´Ù.... 2018/10/20  
  argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë°í ½Í½À´Ï´Ù.[2]     ka0r1
09/23 2397
113   RTL±â¹ý Áú¹®[6]     vngkv123
03/23 2390
112   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã Áú¹®..[1]     ewqqw
04/17 2382
111   libc-db¿¡¼­ main_arena ¾î¶»°Ô ãÁÒ?     vngkv123
07/30 2370
110   FC10 1¹ø¹®Á¦     exqa123
01/24 2366
109   ȯ°æº¯¼ö¸¦ ÀÌ¿ëÇÑ BOF °ø°Ý½Ã Àǹ®Á¡ Áú¹®ÀÔ´Ï´Ù.[5]     tjdalstjr938
01/02 2360
108   Æ÷¸Ë½ºÆ®¸µ °³³ä Á¦´ë·Î ¼³¸íÇØÁֽǺÐ[1]     pkdo1030
07/24 2359
107   ¹öÆÛ¿À¹öÇ÷οì Áú¹®....[2]     ewqqw
04/16 2348
106   remote exploit½Ã¿¡ ¾ÈµÇ´Â°Å ÀÌÀ¯ ¾Ë ¼ö ÀÖÀ»±î¿ä,..[2]     vngkv123
08/13 2338
105   checksec, ELF±â´É, ±×¿Ü Áú¹®....     vngkv123
06/14 2336
104   µµ¿ÍÁÖ¼¼¿ä ´ëÇб³¼ö´ÔµéÇÑÅ× ¹°¾îºÁµµ ÀÌ»óÇÏ°Ô ´äº¯ÇØÁÖ¼¼¿ä ¤Ð.[1]     morieye
03/14 2334
103   pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?[4]     ocal
01/09 2317
102   pwnable.kr uaf ¹®Á¦ Áú¹®ÀÖ½À´Ï´Ù     pkdo1030
07/22 2308
101   asis CTF ¹®Á¦Ç®´Ù°¡....[4]     vngkv123
04/12 2298
100   unlink¸ÅÅ©·Î¿¡¼­ P....[5]     vngkv123
05/12 2285
99   heap exploit ±â¹ý °øºÎ ¹æ¹ý....     choboKing
08/09 2273
98   °í¼ö´Ôµé²² Áú¹®ÇÕ´Ï´Ù.[2]     pwnnnt
03/30 2270
97   ITºÐ¾ß·Î Áø·Î°í¹ÎÀ̳ª,Ãë¾÷,ÀÌÁ÷°í¹ÎÀ¸·Î ±Ã±ÝÇÑÁ¡µéÀÌ ¸¹À¸½ÃÁÒ~?     koreais0
08/08 2270
96   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã[1]     ewqqw
04/21 2259
95   shellcode Áú¹®µå¸³´Ï´Ù.[1]     bong93
01/07 2251
[1]..[71][72][73] 74 [75][76][77][78][79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org