22010, 19/1101 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   6¿ù
   BufferOverFlow¸¦ °øºÎÇÏ°í Àִµ¥¿ä. Ä¿³ÎÀÇ ¹æ¾î±â¹ý¶§¹®ÀÎÁö Á¦ ½Ç·Â¶§¹®ÀÎÁö ¾ÈµË´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Board&no=30731 [º¹»ç]


CentOS 6.3 ¹öÀüÀ¸·Î °øºÎÇÏ°í ÀÖ½À´Ï´Ù.

Ä¿³ÎÀº uname °á°ú 2.6.32-279 °°³×¿ä


#include <stdio.h>

int main()
{
     int access=0;
     char pass[40];

     printf("input password : ");
     scanf("%s", pass);

     if(pass == "totoro"); // ¾îÂ÷ÇÇ bof ´Ï±î ¾Æ¹«·¡µµ »ó°ü ¾øÀ¸´Ï±î
     {
         access ++;
     }

     if(access==1);
     {
         printf("Access!!!\n");
     }
     else
     {
         printf("Fail!!!\n");
     }
     return 0;
}


ÀÌ°Ô ÄÚµå°í¿ä.


¸®¹ö½Ì ³»¿ëÀº °£·«È÷ ¼³¸íÇص帮ÀÚ¸é

0x08048472 ¿¡¼­ scanf¸¦ ÄÝÇØ°©´Ï´Ù.
s¸¦ ´©¸£±ä Çߴµ¥ nÇÏ°í s ÇÏ°í Â÷ÀÌ°¡ ¾ø³×¿ë ;;

¿©±â¼­ 1111111111·Î ½ºÅÃÀ» ä¿öº¸¸é

esp ´Â 0xbffff2a0 ÀÌ°í ebp ´Â 0xbffff2e8 ÀÔ´Ï´Ù.

4 * 13 Byte Â÷ÀÌ ÀΰÅÁÒ.

±×·¡¼­ ´ÙÀ½¿¡ Àç disassemble À» ÇÕ´Ï´Ù.



Á¦°¡ °¡°í½ÍÀº ¸®ÅÏÁÖ¼Ò´Â printf("Access!!!\n"); ·Î °¡°í ½Í´Ü ¸»ÀÔ´Ï´Ù.

cmp jne ¹Ù·Î´ÙÀ½ÀÇ ÁÖ¼Ò´Â 0x0804847f ¿¡ ÀÖ°í ¿©±âºÎºÐÀÌ Access!!¸¦ Ãâ·ÂÇÏ´Â ºÎºÐÀÌ ¸Â½À´Ï´Ù.

scanf¿¡¼­ ½ºÅÿ¡ 1111111111111111111111 ·Î ebp±îÁö ä¿ì°í

±× ´ÙÀ½ 4¹ÙÀÌÆ®¿¡
\x7f\x84\x04\x08 À̶ó°í ³Ö¾ú´Âµ¥ Ʋ·Ç³ª¿ä?

µµÀúÈ÷ ¾ÈµÇ³×¿ä.



¹öÆÛ¿À¹öÇ÷οì´Â Áã¶Ëµµ ¸ð¸£´Â ³ðÀ̱º!

ÇÏÁö ¸¶½Ã°í

Ä¿³ÎÀÇ ¹æ¾î±â¹ý¶§¹®ÀÎÁö Á¦ À߸øÀÎÁö ¾Ë·ÁÁÖ¼¼¿ä ¤Ð¤Ð

¹æ¾î°¡ Á¦°¡ °øºÎÇϱ⿡ ³Ê¹« ½ê¼­ ±×·±Áöµµ ¸ð¸£°Ú³×¿ä.

±Ùµ¥ CANARY °ªµµ º¯°æµÇ¾úÀ» ÅÙµ¥ ÇÁ·Î±×·¥ÀÌ ¾Èƨ±â³×¿ä ;;

  Hit : 5720     Date : 2013/04/09 12:01



    
cd80 ¿ì¼± µÇ´ÂÁö¸¸ È®ÀÎÇϽ÷Á¸é 0x0804847f¸¦ 50¹øÁ¤µµ ³Ö¾îº¸½Ã¸é µË´Ï´Ù
¼¾Å佺 6.3¿¡¼­ ±âº»¼³Á¤À¸·Î ½ºÅð¡µå°¡ ¼³Á¤ÀÌ µÅÀÖ´ÂÁö ¾ÈµÅÀÖ´ÂÁö´Â ¸ð¸£°ÚÁö¸¸
½ºÅð¡µå°¡ ¾ø´Ù¸é ¼º°øÇÏÁö ¾ÊÀ»±î ½Í½À´Ï´Ù
2013/04/09  
6¿ù ¾Æ!!!!! ±×·± ¹æ¹ýÀÌ!! ¤»¤»¤»¤»¤» °¨»çÇÕ´Ï´å!!
¿Ö ÀüºÎ 1·Î ä¿ï ¹æ¹ý¸¸ »ý°¢ÇßÀ» ±î¿ä...
±Ùµ¥.. ¾ÈµÇ³×¿ä. ¾Æ gdb »ç¿ë¹ý Àß ¸ð¸£°Ú³×¿ä.
´ÙÀ½ ³Ñ±â´Â°Ô n ÇÔ¼ö ³»ºÎ·Î µé¾î°¡´Â°Ô s ¾Æ´Ñ°¡¿ä?
2013/04/10  
cd80 siÀÔ´Ï´Ù~~
s¸¸ ´©¸£½Ã¸é ÇöÀç ÇÔ¼ö°¡ ³¡³¯¶§±îÁö ÇѴܰ辿 ½ÇÇàÇÑ´Ü°Å °°³×¿ä
(gdb) s
Single stepping until exit from function main,
which has no line number information.

¿øÇϽô ¸í·ÉÀº siÀÔ´Ï´Ù
2013/04/10  
6¿ù °¨»çÇÕ´Ï´ç~~~
Çغ¸°í ¸»¾¸µå¸®°Ú½À´Ï´Ù
2013/04/13  
21650   ±¸Å¸¸¸È­°­ÀÇ Áú¹®[3]     69
11/15 5508
21649   ³×Æ®¿öÅ©-¸®´ª½º-C¾ð¾î Å×Å©¼øÀ¸·Î °øºÎ Áß     69
11/16 5230
21648   Áú¹®ÀÔ´Ï´ç...[2]     6minsik6
10/12 8342
21647   ÁøÁ¤ÇÑ ÇØÄ¿¶õ...[2]     6Moderato
09/02 7173
  BufferOverFlow¸¦ °øºÎÇÏ°í Àִµ¥¿ä. Ä¿³ÎÀÇ ¹æ¾î±â¹ý¶§¹®ÀÎÁö Á¦ ½Ç·Â¶§¹®ÀÎÁö ¾ÈµË´Ï´Ù.[4]     6¿ù
04/09 5719
21645   ÄÚµå°ÔÀÌÆ® ´ëȸ ÁøÇàÁßÀ̳׿ä[4]     6¿ù
03/02 5380
21644   bof ¿øÁ¤´ë À̹ÌÁöÆÄÀÏÀÌ¿ä[3]     6¿ù
04/13 5821
21643   ÇØÄ¿½ºÄð ÇØÅ·´ëȸ[1]     6¿ù
03/29 5651
21642   ÇØÅ·´ëȸ Áú¹®ÀÔ´Ï´Ù.[1]     6¿ù
03/17 5324
21641   ½ºÅ©¸³Æ® Å°µð?[4]     6¿ù
03/17 5476
21640   ²ô¾Æ level7 óÀ½À¸·Î Ç®¾ú´Ù.....     6¿ù
03/02 5482
21639   ftz ¼­¹ö     6¿ù
02/25 5909
21638   À¸Èï... ftzÁ¢¼ÓÀÌ ¾ÈµÇ³×¿ä.     6¿ù
02/23 5589
21637   ÃÊÂ¥,,[1]     774958
08/05 6989
21636   c.¾ð¾î ¸®´ª½º °í¼öÀ̽źР¸ð½Ê´Ï´Ù[1]     78786789
07/15 6888
21635   ÇØÅ· ½Ç½ÀÇϴ°÷ÀÌ ¾îµðÀΰ¡¿ä? level1~[3]     79letter
06/25 6573
21634   Ȥ½Ã, °¡Àå °¡±î¿î ³¯Â¥¿¡ ¿­¸®´Â ÇØÅ·´ëȸ ¾Æ½Ã´ÂºÐ ÀÖ³ª¿ä~_~?[5]     7evenLeaf
06/27 6809
21633   °­Á Áú¹® °Ô½ÃÆÇ¿¡ ±¤°í±Û ³­¹«Çϳ׿ä;[7]     7evenLeaf
03/27 6982
21632   ÀÌ°Å FTZ ·¹º§ * 20 Æ÷ÀÎÆ® ...[3]     7evenLeaf
04/05 8842
21631   Áö±Ý ³ª¿À´Â CPU´Â ´Ù 64bitÁÒ??[6]     7evenLeaf
04/09 7288
[1]..[11][12][13][14][15][16][17][18] 19 [20]..[1101]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org