1581, 15/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   CodeAche
   [ÀÚÀÛ] Linux Reverse Engineering - basic.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1405 [º¹»ç]


¿äÁò¿¡ ¸îÂ÷·Ê ´ëȸµéÀ» °ÞÀ¸¸é¼­.. ¸®´ª½º ¹®Á¦´Â °ÅÀÇ ¸®¹ö½ÌÀ» Çؾ߸¸ Ç®¸®´Â°Ô ´ëºÎºÐÀÌ´õ±º¿ä.
µû·Î ¹¹ ¸®´ª½º ¸®¹ö½ÌÀ̶ó°í °øºÎÇÒ Ä¿¹Â´ÏƼµµ ¾ø°íÇؼ­.
Á÷Á¢ °øºÎÇÑ ³»¿ëÀ» °øÀ¯ÇÏ·Á°íÇÕ´Ï´Ù.
°­Áµµ ¾Æ´Ï°í..°ÅÀÇ ÃßÃø¼º ³»¿ëÀ̸¹Áö¸¸,
°øÀ¯ÇϹǷνá Á¦°¡ ¸ô¶ú¶²°Å ´©±º°¡ ¹Ù·ÎÀâ¾ÆÁÖ°í, ¸ô¶ú¶²»ç¶÷Àº ¾Ë°ÔµÇ´Â °è±â°¡ µÉ¼öÀÖÁö¾ÊÀ»±îÇؼ­¿ä.
Ʋ¸®°Å³ª º¸Ãæ¼³¸íÀº ¾ðÁ¦¶óµµ ȯ¿µÀÔ´Ï´Ù.
¾ÕÀ¸·Î Áö¼ÓÀûÀ¸·Î ¿Ã¶ó°¥²¨°í,,
±âº»ÀûÀÎ ÇÁ·Î±×·¥ºÎÅÍ Áö¼ÓÀûÀ¸·Î ¸®¹ö½ÌÇسª°¥°Ì´Ï´Ù.
°­Á´ ¾Æ´ÏÁö¸¸ Áú¹®À̳ª Ãß°¡ÀûÀÎ »çÇ׿¡´ëÇØ Áú¹®ÇÏ½Ã¸é ´äº¯Àº ¼º½É¼ºÀDz¯ ´Þ°Ù½À´Ï´Ù.
Âü°í·Î À̱ÛÀ» º¸±âÀü¿¡ ±âº»ÀûÀÎ ¾î¼À ¹®¹ýÁ¤µµ´Â ¾Ë¾ÆµÎ´Â°Ô ÁÁ½À´Ï´Ù.

#include<stdio.h>
int main(int argc,char *argv[])
{
return 1;
}

RedHat 2.4.32 (gcc 3.2.2)
0x080482f4 <main+0>:    push   ebp            
//±âÁ¸¿¡ »ç¿ëµÇ´ø ebp ÁÖ¼Ò¸¦ ½ºÅÿ¡ ÀúÀå..(¹é¾÷°³³ä)

0x080482f5 <main+1>:    mov    ebp,esp      
//ÇöÀç ½ºÅà ÁÖ¼Ò¸¦ ¾ÕÀ¸·Î »ç¿ëÇÒ base pointer·Î ¼³Á¤.
0x080482f7 <main+3>:    sub    esp,0x8        
//esp-8
0x080482fa <main+6>:    and    esp,0xfffffff0  
//esp AND 0xfffffff0  Áï, espÁÖ¼ÒÀÇ ¸¶Áö¸· ÀÚ¸®¸¸ 0À¸·Î ¼¼ÆÃ
0x080482fd <main+9>:    mov    eax,0x0      
//eax = 0      
0x08048302 <main+14>:   sub    esp,eax      
//esp = esp - eax(0)
----------------ÇÁ·Ñ·Î±×-------------------
0x08048304 <main+16>:   mov    eax,0x1      
//eax = 1 (ÇÔ¼ö³»ÀÇ ¸¶Áö¸· eax´Â return value·Î½á »ç¿ëµÈ´Ù.)
----------------¿¡Çʷα×-------------------
0x08048309 <main+21>:   leave                  
//ÇÔ¼ö ¿¡Çʷα׺κÐ, ÇöÀç ½ºÅÿ¡¼­ exit ÇÔ.
0x0804830a <main+22>:   ret                      
//leave¿¡ ²À µÚµû¶ó¾ßÇϸç ÇÔ¼ö°¡ º»·¡ ÁÖ¼Ò·Î ¸®ÅÏÇÔ.(¿©±â¼± ¿î¿µÃ¼Á¦·Î.)
0x0804830b <main+23>:   nop    



FreeBSD 8.0-RELEASE #0 (gcc 4.2.1)
0x080483d0 <main+0>:    lea    ecx,[esp+4]        
//espÁÖ¼Ò¿¡+4 ÇÑ ÁÖ¼Ò°ªÀ» ecx¿¡ ´ëÀÔ.(esp°¡ 0xfffff1 ÀÌ¿´´Ù¸é ecx´Â0xfffff5µÊ)
0x080483d4 <main+4>:    and    esp,0xfffffff0        
//ÇöÀç esp¿Í 0xfffffff0À» and. ¿ª½Ã³ª espÁÖ¼ÒÀÇ ¸¶Áö¸· ÀÚ¸®¸¸ 0À¸·Î ¼¼Æà                 
0x080483d7 <main+7>:    push   DWORD PTR [ecx-4]
//ÃÖÃÊesp+4 = ecx, ecx-4 = ÃÖÃÊesp ¸¦ 32ºñÆ®´ÜÀ§·Î ½ºÅÿ¡push
0x080483da <main+10>:   push   ebp
//ÇöÀç ebp°ª ½ºÅÿ¡ Ǫ½¬(¹é¾÷°³³ä)
0x080483db <main+11>:   mov    ebp,esp
//ÇöÀç esp(¸¶Áö¸·ÀÚ¸®°¡ 0À̵È) ¸¦ ebp¿¡ µ¤¾î¾¸.
0x080483dd <main+13>:   push   ecx
//ÃÖÃÊ esp+4 = ecx , ecx¸¦ ½ºÅÿ¡ Ǫ½¬ÇÔ.
----------------ÇÁ·Ñ·Î±×-------------------
0x080483e8 <main+24>:   mov    eax,0x1
//eax = 1 , ÇÔ¼ö ³» ¸¶Áö¸· eax°ªÀº return value.
----------------¿¡Çʷα×-------------------
0x080483f0 <main+32>:   pop    ecx
//ecx ´Ù½Ã ²¨³»¿È.
0x080483f1 <main+33>:   pop    ebp
//ebp ´Ù½Ã ²¨³»¿È.
0x080483f2 <main+34>:   lea    esp,[ecx-4]
//ÃÖÃÊÀÇ esp+4 = ecx, ecx-4 = ÃÖÃÊesp ¸¦ ´Ù½Ã esp¿¡ ³Ö¾îÁÜ.
//°á±¹ esp¸¦ ´Ü¼øÈ÷ ecx¿¡ ¹é¾÷ÇÏÁö¾Ê°í.+4 -4 ¸¦ ÀÌ¿ëÇؼ­ ±âÁ¸ esp¸¦ »ç¿ëÇÏ°ÔÇÔ.
0x080483f5 <main+37>:   ret  

  Hit : 10335     Date : 2010/02/24 08:07



    
º°ºûÀ»´ã¾Æ Çü... ¿ù¸» µÇ´Ï±î 3¿ù´Þ Æ÷ÀÎÆ® ¸ðÀ» Áغñ Çϴ°ÅÁÒ...?
±×·± °ÅÁÒ?

¿ª½Ã Æ÷ÀÎÆ® ¸ðÀ¸´Â°Ç ±â´ÏÇÇ±× °ÇÃÊ ¸ÔÀÌ´Â°Í º¸´Ù ½±´Ù´õ´Ï... ÁøÂ¥ ÇϽó×;;

°Ô½Ã¹° 3°³·Î ´ñ±Û ½Ï ¸ðÀ¸·Á´Â°ÅÁÒ?
2010/02/24  
½È¾î ³»°¡ÇÒ²¨¾ß ¾Ì. ¹º¤»¸»¤»ÀÌÁö; ¸®¹ö½Ì¿¡´ëÇÑ°Ç°¡; 2010/02/24  
CodeAche ¾Æ Á¹¶ó ±ÛÀÇ Ä÷¸®Æ¼¸¦ ¸ø¾Ë¾Æº¸´Ù´Ï
±×µûÀ§ Æ÷ÀÎÆ®50¶§¹®¿¡ ³»°¡ ÀÌ·±°Å °øÀ¯ÇÏ°Ù³Ä ¤»
2010/02/24  
º°ºûÀ»´ã¾Æ ³ª¾ß ¸®¹ö½ÌÀ» ¸ð¸£´Ï±î¿ä 2010/02/24  
kanate °í±Þ¾ð¾î¸¦ °³¹ßÇϽźеéÀÌ Á¸°æ½º·¯¿öÁö´Â ±ÛÀÔ´Ï´Ù!! 2010/02/25  
1301   TCP/IP ÀÌÇØ ¾È°¡½Ã´Â ºÐµéÀ» À§ÇÏ¿©...(ÀÚÀ¯°Ô½ÃÆÇ¿¡ ÀÖ´Â °ÍÀÔ´Ï´Ù...)[3]     idl0521
09/21 10527
1300   ³×Æ®¿öÅ©1±Þ ÀÚ°ÝÁõ´ëºñ^^[5]     appleone
02/13 10518
1299   WebHacking ¹®Á¦ 54 ¹ø Ç®ÀÌ.[1]     Ǫ¸¥ÇÏ´Ã
03/25 10504
1298   ¼Ò¼ö ±¸ÇÏ´Â ÇÁ·Î±×·¥[3]     0226daniel
10/26 10489
1297   ÇØÄ¿½ºÄð level1 - ¸®¹ö½ÌÇϱ⠠   qwased55
11/24 10482
1296   II. ÀϹݸí·É¾î2.     ±«µµjs
07/04 10477
1295   nProtect Å°º¸µå ÇØÅ·¹æÁö ÇÁ·Î±×·¥ ¼³Ä¡[5]     bongcheur
07/07 10466
1294     [re] [ÀÚÀÛ]±¸±Û¸µÀ» ¸·´Â °£´ÜÇÑÆÁ[1]     ÃÊÄÝ·¿³ªÀÎ
03/12 10448
1293   ¿À¹öŬ·°Å·ÀÇ ¿ø¸®[11]     ÄÁƼ´º
10/09 10439
1292   - [º¸¾ÈÆÁ] ÇÁ·Î±×·¡¹Ö Äڵ庸ȣ (1)     twinz
08/28 10429
1291   About Reversing     zen0c1de
07/19 10423
1290   ÇØÄ¿¶õ?[3]     vlmathlv
02/21 10399
1289   6¹ø°C°­ÁÂ~!![10]     ±«µµjs
07/15 10398
1288   vi ¾ÆÁÖ Àá±ñ üÇèÇϱâ~^^;;[9]     hkzine
09/07 10393
1287   - [ÇØÅ·±â¹ý] ¹öÆÛ¿À¹öÇ÷ο젠   twinz
08/28 10360
  [ÀÚÀÛ] Linux Reverse Engineering - basic.[5]     CodeAche
02/24 10334
1285   [Æß]¸®´ª½º ¸í·É¾î ¸ðÀ½ -3     G.O.D
08/28 10327
1284   ¿Ö ÇØÄ¿°¡ µÇ·Á´Â°¡[6]     dontknow
07/22 10320
1283   - Á¤º¸º¸¾ÈÀü¹®°¡ÀÇ Çʿ伺[1]     twinz
08/27 10314
1282   [°­ÁÂ] 98 ºÎÆõð½ºÄÏ °ú fdisk Çϱâ, µµ½º¿¡¼­ ¼³Ä¡Çϱâ[2]     chagang531
09/18 10308
[1]..[11][12][13][14] 15 [16][17][18][19][20]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org