1581, 4/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ÇØÅ·ÀßÇÏ°í½Í´Ù
   http://¾øÀ½
   (²Ä¼ö) L.O.B Çѹ濡 Ŭ¸®¾îÇϱâ

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=8564 [º¹»ç]


ÇÊÀÚ°¡ LD_PRELOAD¿¡ ´ëÇØ ¿¬±¸Çϸ鼭 ¾Ë°Ô µÈ »ç½ÇÀε¥

my-pass ÆÄÀÏÀº ¸Å¿ì Ãë¾àÇÏ´Ù.

LD_PRELOAD´Â ȯ°æº¯¼ö Áß ÇϳªÀÌ´Ù.

ÇÁ·Î¼¼½º¸¦ ½ÇÇàÇÏ´Â °úÁ¤¿¡¼­ ¶óÀ̺귯¸®¸¦ ·ÎµùÇÒ ¶§,

LD_PRELOAD(ȯ°æº¯¼ö)°¡ ¼³Á¤ÀÌ µÇ¾îÀÖ´Ù¸é

ÇØ´ç º¯¼ö¿¡ ÁöÁ¤µÈ ¶óÀ̺귯¸®¸¦ ¸ÕÀú ·ÎµùÇÑ´Ù.

LD_PRELOAD ȯ°æº¯¼ö¿¡ ÀúÀåÇÏ´Â ¿©·¯°¡Áö ¹æ¹ý Áß ½©¿¡ µî·ÏÇÏ¿© »ç¿ëÇÏ´Â ¹æ¹ýÀÌ ÀÖ´Ù.

my-pass ÆÄÀÏÀº geteuid¸¦ Çؼ­ »ç¿ëÀÚÀÇ euid¿¡ ¸Â´Â Æнº¿öµå¸¦ Ãâ·ÂÇØÁØ´Ù.

±×·±µ¥ LD_PRELOAD¶ó´Â ȯ°æº¯¼ö´Â ƯÁ¤ÇÑ ÇÔ¼ö¸¦ ¹Ì¸® µî·ÏÇØ µÑ ¼ö ÀÖ´Ù.

±×·¸´Ù¸é ÀÌ LD_PRELOAD¶õ ¹«¾ùÀϱî?

¾Æ·¡´Â °£´ÜÇÏ°Ô ±¸±Û¸µÀ» ÇÏ¿©

ÇØ¿Ü »çÀÌÆ®¿¡¼­ ld_preload¿¡ ´ëÇØ Ã£¾Æº» ±ÛÀ» ÀοëÇÑ °ÍÀÌ´Ù.

========================================
.
.
.
Normally the Linux dynamic loader ld-linux (see ld-linux(8) man page) finds and loads the shared libraries needed by a program, prepare the program to run, and then run it. The shared libraries (shared objects) are loaded in whatever order the loader needs them in order to resolve symbols.
.
.
.

(Çؼ®)
.
.
.
º¸ÆíÀûÀ¸·Î ¸®´ª½º µ¿Àû ·Î´õ´Â ÇÁ·Î±×·¥¿¡ ÇÊ¿äÇÑ °øÀ¯ ¶óÀ̺귯¸®µéÀ»
ã°í ·ÎµåÇÏ¸ç ½ÇÇàÇÒ ÇÁ·Î±×·¥À» ÁغñÇÑ ´ÙÀ½ ½ÇÇàÇÑ´Ù.
°øÀ¯ ¶óÀ̺귯¸®´Â ±âÈ£¸¦ È®ÀÎÇϱâ À§ÇÏ¿© ·Î´õ°¡ ÇÊ¿äÇÑ ¼ø¼­´ë·Î ·ÎµåµÈ´Ù ±×¸®°í...
========================================







geteuid°¡ ¿øÇÏ´Â ´Ü°èÀÇ uid¸¦ ¸®ÅÏÇϵµ·Ï LD_PRELOAD¸¦ »ç¿ëÇؼ­ Á¶ÀÛÇÒ ¼ö ÀÖ´Ù.

±×·¯¸é my-pass´Â Á¶ÀÛµÈ geteuidÀÇ °á°ú¿¡ µû¶ó ´Ù¸¥ ¾ÆÀ̵ðÀÇ ºñ¹Ð¹øÈ£¸¦ ¹ñ¾î³¾ °ÍÀÌ´Ù.

---------------------
int geteuid(void);

int main(void)
{
        return geteuid();
}

int geteuid(void) {
    return 520;
}

--------------------

[gate@localhost gate]$ gcc -o geteuid -shared -fPIC geteuid.c
[gate@localhost gate]$ export LD_PRELOAD=./geteuid
[gate@localhost gate]$ my-pass















ÇÊÀÚ°¡ ÀÌ°ÍÀ» »ý°¢ÇÏ´Â µµÁß,

int geteuid(void)
{
    return 520;
}

ÀÌ·¸°Ô ¾²¸é mainÇÔ¼ö, Áï ½ÃÀÛÁ¡ÀÌ ¾ø´Ù°í ¿¡·¯¸¦ ¹ñ¾ú´Ù.

±×·¸´Ù¸é mainÇÔ¼ö¿¡¼­ ¼­ºêÇÔ¼ö¸¦ ¸¸µç´ÙÀ½ 520À» ¸®ÅÏÇÏ°í ±× °ªÀ»

mainÇÔ¼ö°¡ ¸®ÅÏÇϸé ÀÌ·¨´ø Àú·¨´ø 520À» ¸®ÅÏÇÑ´Ù´Â »ç½ÇÀº º¯ÇÔ¾øÁö ¾Ê´Â°¡?

¸ðµç ÇÁ·Î±×·¥Àº ½ÃÀÛÁ¡ÀÌ Á¸ÀçÇÑ´Ù.

ÀϹÝÀûÀÎ C¾ð¾î¶ó¸é mainÇÔ¼ö°¡ ½ÃÀÛÁ¡ÀÌ µÇ´Âµ¥ (ÀÌ°ÍÀ» entry point¶ó°íµµ ÇÑ´Ù)

ÀÌ ½ÃÀÛÁ¡À» mainÀÌ ¾Æ´Ñ ´Ù¸¥ À̸§ÀÇ ÇÔ¼ö°¡ µÉ ¼ö ÀÖÀ»±î?

¶ó´Â °íÂûÀ» Çϸ鼭 °­Á´ ¿©±â±îÁö ¸¶Ä¡°Ú´Ù.


  Hit : 1266     Date : 2023/01/14 03:09



    
ÇØÅ·ÀßÇÏ°í½Í´Ù ¸¶Áö¸· ¹®´Ü¿¡ ¿ÀÇØÀÇ ¼ÒÁö°¡ Àֳ׿ä.
Windows API¿¡¼± WinMainÀÌ ½ÃÀÛÁ¡ÀÌ¶ó¼­ mainÇÔ¼ö¿Í À̸§ÀÌ ´Ù¸£±ä Çѵ¥
"gcc°°Àº ÄÜ¼Ö C¾ð¾î ÇÁ·Î±×·¡¹Ö¿¡¼­ mainÇÔ¼ö À̸§À» º¯°æÇÒ ¼ö ÀÖÀ»±î?"°¡ °íÂûÇÒ Á¡ÀÔ´Ï´Ù.
±¸±Û¸µÀ» Çؼ­ Çѹø ¾Ë¾ÆºÁ¾ß µÇ°Ú³×¿ä.
2023/01/15  
Àܵ¥½º ¤§ 2024/03/16  
1521 ºñ¹Ð±ÛÀÔ´Ï´Ù  Å×ÀÏÁî·±³Ê ÇØÅ· »ç°Ç     festal
09/24 0
1520   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1519   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1518   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1517   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1516   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1515   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1514   ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] c++ °­Á     sinslove
02/22 0
1513 ºñ¹Ð±ÛÀÔ´Ï´Ù  Áú¹®ÇÕ´Ï´Ù~     ¸¶´©¶ó
08/05 1
1512 ºñ¹Ð±ÛÀÔ´Ï´Ù  [re] : ÇØÄ𠱤ÁÖ¿¡¼­ °°ÀÌ °ÏºÎÇϽǺР¼±»ý´Ô & ½º½Â ±¸ÇÕ´Ï´Ù.     ne4760
03/25 1
1511 ºñ¹Ð±ÛÀÔ´Ï´Ù  2.3 ¸ð´ÏÅÍ¿¡ µ¥ÀÌÅÍ Ãâ·ÂÇϱâ printf()      xownsdk2
08/20 2
1510 ºñ¹Ð±ÛÀÔ´Ï´Ù  ÇØÄ¿½ºÄð °ü¸®ÀÚ´Ô²²     packer
03/20 2
1509 ºñ¹Ð±ÛÀÔ´Ï´Ù  °¨À»¸øÀâ°Ú³×¿ä¤Ì¤Ì     À×À×À×
01/15 3
1508   °í¼ö´ÔµéÀÇ µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù     vbnm111
02/11 217
1507   ¸®´ª½º Ä¿³Î 2.6 ¹öÀü ÀÌÈÄÀÇ LKM     jdo
07/25 715
1506   Call by value VS Call by Reference     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 927
  (²Ä¼ö) L.O.B Çѹ濡 Ŭ¸®¾îÇϱâ[2]     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 1265
1504   ½©ÄÚµå ¸ðÀ½     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 1545
1503   ±¸±Û ¹é¸µÅ© ÀÛ¾÷ Áú¹®¿ä     wkatnxka
03/30 3368
1502   ¾È³çÇϼ¼¿ä.     god0631a
03/16 3573
[1][2][3] 4 [5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org