1581, 19/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lMaxl04
   http://lmaxl.tistory.com/
   ÇØÅ·Ä·ÇÁ ctf 5¹ø Ç®ÀÌ.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1572 [º¹»ç]


¿ì¼± ¹®Á¦¸¦ º¸¸é º½ ¹®Á¦ÀÌ´Ù. ¹Úº½Àΰ¡...?
³»½ºÅ¸ÀÏÀÌ ¾Æ´Ï¶ó¼­ Ç®±â ½ÈÁö¸¸ ¿äûÀ¸·Î Çѹø...

---------------------------------------------------------------------------------------
is this a right file À̶ó´Â ÈùÆ®°¡ ÀÖ´Ù.
¹«½¼ ¸»ÀÎÁö ¼ÖÁ÷È÷ Àß ¸ð¸£°ÚÀ½...

Á¢¼ÓÇϸé ÆÄÀÏÀÌ 4°³°¡ Àִµ¥ ¼Ò½ºÆÄÀÏÀ» ¿­¾îº¸ÀÚ.

#include <stdio.h>

int main()
{
        FILE *fp;
        char szStr[1024];

        fp = fopen("secret", "r");
        if(!fp){
                printf("secret file error\n");
                exit(-1);
        }

        fgets(szStr, 1024, fp);
        szStr[strlen(szStr)-1] = 0;
        fclose(fp);

        if(strcmp(szStr, "tell me your secret!") == 0)
                system("/bin/cat key");


        printf("Finished.\n");
}

°£´ÜÇÏ°Ô Çؼ®Çϸé secret ¿¡¼­ Àоî¿Â ½ºÆ®¸µÀÌ tell me your secret! ¸é Å° ÆÄÀÏÀ» Àоî¶ó ¶ó´Â °ÍÀÌ´Ù. (ÀÚ¼¼ÇÑ ¼Ò½º Çؼ®Àº ¾Ë¾Æ¼­...)

±×·±µ¥ secret ÆÄÀÏ¿¡´Â
I'm a invalid secret file
À̶ó´Â ½ºÆ®¸µÀÌ µé¾îÀÖ°í Àб⠱ÇÇѸ¸ ÀÖ¾î ¼öÁ¤ÀÌ ºÒ°¡´ÉÇÏ´Ù.

±×·³ ´Ù¸¥µ¥¼­ ÀÐÀ¸¸é µÇÁö ¾Ê°Ú³ª ½Í¾î¼­ ½Éº¼¸¯ ¸µÅ©¸¦ ÀÌ¿ëÇغ¸¾Ò´Ù.

tmp Æú´õ¿¡ ´ÙÀ½°ú °°ÀÌ ÇÁ·Î±×·¥ÀÇ ½Éº¼¸¯ ¸µÅ©¸¦ °Ç´Ù.

bom@ubuntu:/tmp/max$ ln -s /home/bom/bom_owned aa

±×·³ ÀÌÁ¦ tmp Æú´õ¿¡ ´ÙÀ½°ú °°Àº ÆÄÀÏÀÌ ÀÖÀ» °ÍÀÌ´Ù.

lrwxrwxrwx  1 bom  bom    19 2010-09-18 18:35 aa -> /home/bom/bom_owned*

½Éº¼¸¯ ¸µÅ©´Â °£´ÜÈ÷ »ý°¢Çϸé ÀÎÅͳÝÀÇ Áñ°Üã±â¿Í µ¿ÀÏÇÑ °ÍÀ¸·Î
ÆÄÀÏÀÌ ¿ø·¡ ÆÄÀÏÀ» °¡¸®Å°¸ç ÇØ´ç ÆÄÀÏ ½ÇÇà½Ã ¿øº» ÆÄÀÏÀ» ½ÇÇàÇÏ´Â ÆÄÀÏÀ̶ó°í º¸¸é µÈ´Ù.

¶ÇÇÑ ¿ø·¡ ¸ñÀûÀÌ secret ÆÄÀÏÀ» Àдµ¥ ¿©±â¼­ º¸¸é Àý´ë °æ·Î°¡ ¾Æ´Ñ »ó´ë°æ·Î¸¦ ÀÌ¿ëÇØ Âü°íÇÑ´Ù.
Áï /home/bom/secret ÀÌ ¾Æ´Ñ ÇÁ·Î±×·¥ÀÌ Á¸ÀçÇÏ´Â Æú´õ ³»ÀÇ secretÀ» Àд °ÍÀÌ´Ù.

±×·¯¹Ç·Î secret ÆÄÀϵµ ´ÙÀ½°ú °°ÀÌ ¸¸µé¾îÁØ´Ù.
bom@ubuntu:/tmp/max$ cat > secret
tell me your secret!

ÀÚ ÀÌÁ¦ ½ÇÇàÇغ¸ÀÚ.

bom@ubuntu:/tmp/max$ ./aa
/bin/cat: key: No such file or directory
Finished.

½ÇÇàÀº Àß µÇ¾ú´Âµ¥ keyÆÄÀÏÀ» ÀÐÀ¸·Á°í ÇÏ´Ï ¾ø´Ù°í ±×·±´Ù.
±×·¯¹Ç·Î Å° ÆÄÀÏÀ» ¸¸µé¾îÁÖÀÚ.
À̶§µµ ¸¶Âù°¡Áö·Î ¼Ò½º¸¦ º¸¸é /bin/cat key ·Î½á Àý´ë °æ·Î°¡ ¾Æ´Ñ »ó´ë°æ·Î·Î ÆÄÀÏÀ» Àб⠶§¹®¿¡ ½Éº¼¸¯ ¸µÅ©¸¦ ÀÌ¿ëÇØ key ÆÄÀÏÀ» ¸¸µé¾î¾ß ÇÑ´Ù.

bom@ubuntu:/tmp/max$ ln -s /home/bom/key key

ÀÌÁ¦ µð·ºÅ丮 ³»ÀÇ Àüü ÆÄÀÏÀº ´ÙÀ½°ú °°´Ù.

lrwxrwxrwx  1 bom  bom    19 2010-09-18 18:35 aa -> /home/bom/bom_owned*
lrwxrwxrwx  1 bom  bom    13 2010-09-18 18:36 key -> /home/bom/key
-rw-r--r--  1 bom  bom    21 2010-09-18 18:35 secret

ÀÌÁ¦ aa¸¦ ½ÇÇàÇÏ¸é ³»½ºÅ¸ÀÏÀº ¾Æ´ÏÁö¸¸ º½µµ ³»²¨.

  Hit : 6729     Date : 2010/09/18 06:19



    
DeathStalker ¸Æ½ºÇü °í¸¶¿ö ¤¾¤¾ ´öºÐ¿¡ °øºÎ ‰ç¾î ¤¾¤¾ 2010/09/18  
ganesha °í¸¿½À´Ï´Ù Àß º¸°í °©´Ï´Ù ¤¾¤¾ 2010/09/19  
williamlee ¿À °¨»ç! 2010/09/19  
1221   c¾ð¾î[2]     jyc_joy
01/17 6702
1220   [º¸¾È´º½º]µ¿¿µ»ó °¨»ó ÄÚµ¦ Çü½ÄÀÇ ¹ÙÀÌ·¯½º À¯Æ÷Áß .. ±ä±Þ[1]     Ǫ¸¥ÇÏ´Ã
09/01 6717
1219   [Æß]ÆÄÀ̽ã ÀÔ¹®[5]     G.O.D
08/27 6720
1218   [ÀÚÀÛ] 3. Hello, World![4]     whdgusdl1220
08/23 6725
1217   ÃÖ´ëÈ­[1]     goldcsj
08/13 6728
  ÇØÅ·Ä·ÇÁ ctf 5¹ø Ç®ÀÌ.[3]     lMaxl04
09/18 6728
1215   [ÀÚÀÛ] ´Ù¸¥»ç¶÷ÀÌ ¾Ë±â½¬¿îÄڵ带 ¾²ÀÚ.[5]     qa22ahj
04/03 6737
1214   [ÀÚÀÛ]À©µµ¿ì!! ¼û°ÜÁø ³ÊÀÇ ¸ð½ÀÀ» º¸¿©Áà!!!(Intro)[8]     º°ºûÀ»´ã¾Æ
02/01 6739
1213   ÄÄÇ»ÅÍ º¸¾ÈÇÁ·Î±×·¥ ¹«½ÉÄÚ ³»·Á¹Þ¾Ò´Ù°£ ³¶ÆР    koresong
10/31 6745
1212   [JAVA] ¿¡¼­ abstract ¿Í interface Â÷ÀÌÁ¡     poiu2069
09/16 6745
1211   [ÀÚÀÛ] C °­ÁÂ [7] - PointerÀÇ È°¿ë (Device Driver)[2]     wolverine
07/13 6745
1210   ¿Â¶óÀÎ ½ºÅ͵ð -¾Ë°í¸®Áò ¹× c¾ð¾îµî º¸¾È°øºÎÀÇ ±âÃʺÎÅÍ ÇÔ²² ÇϽǺÐ[2]     hackcorps
09/26 6746
1209   [Æß] ³» ÄÄÇ»ÅÍ º¸¾ÈÀ» À¯ÁöÇÏ·Á¸é ??     dzhfldk
08/22 6748
1208   Shift ÀÇ °£ÆíÇÑ 9°¡Áö ±â´É[12]     Ǫ¸¥ÇÏ´Ã
12/02 6754
1207   gdb tip (at&t -> intel)     key
02/20 6756
1206   [ÀÚÀÛ]GoogleÇØÅ·±âº»-ÀÍ¸í¼ºÀ» À§ÇÑ Ä³½Ã»ç¿ëPart1[7]     lsn10919
10/09 6760
1205   ¾Ïȣȭ[3]     leewoongki
12/07 6762
1204   [C¾ð¾î]1-1 C¾ð¾î ½ÃÀÛ[2]     JJ4eye0ng
02/10 6763
1203   [ÀÚÀÛ]Ãʺ¸ÀÚ¸¦ À§ÇÑ C ¾ð¾î °­Á ¸ðÀ½[2]     kevin0960
08/15 6764
1202   [Æß]À̹ø ÇØÄ·¿¡ µµ¿òµÉ ³×Æ®¿öÅ© ±âÃÊ ÀÚ·á ÀÔ´Ï´Ù.[1]     BLu2Scr22n
02/11 6769
[1]..[11][12][13][14][15][16][17][18] 19 [20]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org