1581, 3/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ssuckies
   http://www.ganseo.com
   format stringÀ» À§ÇÑ ¸®ÅϾîµå·¹½º ±¸Çϱâ.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=162 [º¹»ç]


±×³É Áú¹®ÀÌ ¿Ô±æ·¡ ½áºÃ½À´Ï´Ù.
Ʋ¸°ºÎºÐÀÖÀ»Áö ¸ð¸£³ª °øÀ¯Â÷¿ø¿¡¼­...^^

Produced by ganseo
e-mail : postmaster@ganseo.com
homepage : http://www.ganseo.com


[Æ÷¸ä½ºÆ®¸µÀ» À§ÇÑ ¸®ÅϾîµå·¹½º ã±â]
1.mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º ÁÖ¼Òã±â.
2.printfÀÇ .got ÁÖ¼Òã±â.
3. .dtorsÀÇ ÁÖ¼Òã±â.

ÀÏ´Ü ÀÌ ÀÌ °­Á¿¡´Â ¸¹Àº ¼³¸í¾øÀÌ ½ÇÁ¦ ã´Â ¹æ¹ý¸¸ ¼³¸íÇØ µå¸®µµ·ÏÇÏ°Ú½À´Ï´Ù.

1.mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º ÁÖ¼Òã±â.
óÀ½ ¸ÞÀÎ ÇÔ¼ö¿¡ µé¾î°¡°Ô µÇ¸é ¸Þ¸ð¸® ±¸Á¶´Â ÀÌ·¸°Ô µË´Ï´Ù.

------------------------------------- low
º¯¼ö
------------------------------------- ebp
Saved frame pointer
-------------------------------------
retern address
------------------------------------- high

óÀ½ ¸ÞÀÎÇÔ¼ö°¡ µé¾î°¡´Â ºÎºÐ¿¡ ºê·¹ÀÌÅ© Æ÷ÀÎÆ®¸¦ °Ì´Ï´Ù.
±×·± ´ÙÀ½ ebpÀÇ ÁÖ¼Ò¸¦ ¾Ë¾Æº¾´Ï´Ù.
(gdb) x/16 $ebp              <-- ebp¸¦ 16°³ º¸¿©Áִµ¥..
0xbffff278:     0xbffff298      0x40038917      0x00000001      0xbffff2c4
0xbffff288:     0xbffff2cc      0x4001582c      0x00000001      0x080483b0
0xbffff298:     0x00000000      0x080483d1      0x08048458      0x00000001
0xbffff2a8:     0xbffff2c4      0x08048308      0x080484cc      0x4000c660
(gdb)
ÀÌ·±½ÄÀ¸·Î ³ªÅ¸³µ´Ù°í »ý°¢ÇØ º¾´Ï´Ù.
ebp´Â 0xbffff278ÀÔ´Ï´Ù.
¿äÁò ÄÄÆÄÀÏ·¯¿¡ µû¶ó ´Ù¸£°ÚÁö¸¸ º¸ÅëÀº ÀÌ·²°æ¿ì¿¡ 0xbffff27c¿¡¼­ 16¹ÙÀÌÆ® ´ÜÀ§·Î +,-ÇØÁÝ´Ï´Ù.
0xbffff24c , 0xbffff25c , 0xbffff26c , 0xbffff27c , 0xbffff28c , 0xbffff29c , 0xbffff2ac , 0xbffff2bc
ÀÌÁß¿¡ Çϳª°¡ mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º°¡ µË´Ï´Ù.

2.printfÇÔ¼öÀÇ .got ÁÖ¼Òã±â.
objdump¸¦ ÀÌ¿ëÇؼ­ ±¸ÇÒ¼ö ÀÖ½À´Ï´Ù.
objdump -R ./recluse5 | grep printf
080495cc R_386_JUMP_SLOT printf

ÀÌ°ÍÀ¸·Î printfÀÇ .got ÁÖ¼Ò´Â 080495ccÀÔ´Ï´Ù.

gdb¸¦ ÀÌ¿ëÇؼ­µµ ±¸ÇÒ¼ö ÀÖ½À´Ï´Ù.
disass printfÇϼż­ ±¸Çغ¸½Ç¼ö ÀÖ½À´Ï´Ù.

3. .dtorsÀÇ ÁÖ¼Òã±â.
ÀÌ°Í ¿ª½Ã objdump¸¦ ÀÌ¿ëÇؼ­ ±¸ÇÒ¼ö ÀÖ½À´Ï´Ù.
objdump -h ./recluse5 | grep .dtors
17 .dtors        00000008  080495a8  080495a8  000005a8  2**2
ÀÌ°ÍÀ¸·Î .dtorsÀÇ ÁÖ¼Ò´Â 080495a8ÀÔ´Ï´Ù.
.dtorsÀÇ ¼³¸íÀº ganseo.comÀÇ ÇØÅ· ±âÃÊÇй®¿¡ ÀÚ·á ÀÖ½À´Ï´Ù.

mainÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º¸¦ ±¸Çغ¸´Â°Ô ÁÁÀ¸½Ç°Í °°½À´Ï´Ù.

  Hit : 10715     Date : 2004/02/08 08:22



    
sjh21a ÀÌ°ÍÀ¸·Î printfÀÇ ¸®ÅϾîµå·¹½º ÁÖ¼Ò´Â 080495ccÀÔ´Ï´Ù. .got ¿µ¿ª¾Æ´Ñ°¡¿ä..? globl offset table..~ °£¼­´Ô ÁÁÀº ¹®Á¦ ¾ðÁ¦³ª°¨»çÇÏ°í ÀÖ½À´Ï´Ù ^^ 2004/02/12  
ssuckies ¼öÁ¤Çß½À´Ï´Ù.^^ °¨»çÇÕ´Ï´Ù^^ 2004/02/12  
1541   ³× Æ® ¿ö Å© °­ ÁÂ[17]     ¼ÒÀ¯
10/05 18157
1540   [[ÃʱÞ/°­ÁÂ]] À¯´Ð½º ÁÖ¿ä ¸í·É¾î[7]     ¼ÒÀ¯
10/09 14593
1539   [[ÃʱÞ/°­ÁÂ]] À¯´Ð½º ±âº» Á¤¸®[8]     ¼ÒÀ¯
10/09 14480
1538   Äְܼú ¿¢½ºÀ©µµ¿¡¼­ ¸¶¿ì½º »ç¿ëÇϱâ[1]     ¼ÒÀ¯
10/28 10031
1537   ¸®´ª½º¿¡¼­ Çѱ¹Åë½Å adsl ¼³Á¤[10]     jgminam
11/06 11539
1536   gdb»ç¿ë¹ý_¸µÅ©ÀÓ´Ù...[3]     esang72
01/10 8895
1535   ¸®¸ðÆ®¿¡¼­ ¸í·É¾î ½ÇÇà½ÃÅ°±â[1]     xiangyi
02/03 10638
  format stringÀ» À§ÇÑ ¸®ÅϾîµå·¹½º ±¸Çϱâ.[2]     ssuckies
02/08 10714
1533   ±×³àÀÇ Vulnerabilities¿¡ µû¸¥ Remote/local one night stand exploit.[2]     ssuckies
03/29 10203
1532   ¿Ö C À̾î¾ß Çϴ°¡ ?[96]     ¼ÒÀ¯
04/09 25090
1531   BOF ÇØ°á ¹«ÀÛÁ¤ µû¶óÇϱâ #1[7]     ssuckies
04/12 14517
1530   BOF ÇØ°á ¹«ÀÛÁ¤ µû¶óÇϱâ #2     ssuckies
04/12 10081
1529   Ä¿³Î¹öÀü È®ÀÎÇϱ⤻[1]     ±«µµjs
07/02 9138
1528   [C°­ÁÂ] C¾ð¾îÀÇ ±âº»°³¿ä     ±«µµjs
07/02 11295
1527   C¾ð¾î ±âº»±¸Á¶[1]     ±«µµjs
07/02 12533
1526   C°­ÁÂ;;¶ó ÇÒ°ÍÀÕ³ª?[1]     ±«µµjs
07/03 11279
1525   2¹ø°C°­ÁÂ~![9]     ±«µµjs
07/03 11976
1524   I. ¸®´ª½º ±¸Á¶ ¹× ÀÏ¹Ý ¸í·É¾î.     ±«µµjs
07/04 12855
1523   II. ÀϹݸí·É¾î2.     ±«µµjs
07/04 10421
1522   [Bash Shell] Á¤º¹Çϱâ[1]     ±«µµjs
07/04 10121
[1][2] 3 [4][5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org