1616, 62/81 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lMaxl04
   http://lmaxl.tistory.com/
   ÇØÅ·Ä·ÇÁ ctf 5¹ø Ç®ÀÌ.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1572 [º¹»ç]


¿ì¼± ¹®Á¦¸¦ º¸¸é º½ ¹®Á¦ÀÌ´Ù. ¹Úº½Àΰ¡...?
³»½ºÅ¸ÀÏÀÌ ¾Æ´Ï¶ó¼­ Ç®±â ½ÈÁö¸¸ ¿äûÀ¸·Î Çѹø...

---------------------------------------------------------------------------------------
is this a right file À̶ó´Â ÈùÆ®°¡ ÀÖ´Ù.
¹«½¼ ¸»ÀÎÁö ¼ÖÁ÷È÷ Àß ¸ð¸£°ÚÀ½...

Á¢¼ÓÇÏ¸é ÆÄÀÏÀÌ 4°³°¡ Àִµ¥ ¼Ò½ºÆÄÀÏÀ» ¿­¾îº¸ÀÚ.

#include <stdio.h>

int main()
{
        FILE *fp;
        char szStr[1024];

        fp = fopen("secret", "r");
        if(!fp){
                printf("secret file error\n");
                exit(-1);
        }

        fgets(szStr, 1024, fp);
        szStr[strlen(szStr)-1] = 0;
        fclose(fp);

        if(strcmp(szStr, "tell me your secret!") == 0)
                system("/bin/cat key");


        printf("Finished.\n");
}

°£´ÜÇÏ°Ô ÇØ¼®Çϸé secret ¿¡¼­ Àоî¿Â ½ºÆ®¸µÀÌ tell me your secret! ¸é Ű ÆÄÀÏÀ» Àоî¶ó ¶ó´Â °ÍÀÌ´Ù. (ÀÚ¼¼ÇÑ ¼Ò½º ÇØ¼®Àº ¾Ë¾Æ¼­...)

±×·±µ¥ secret ÆÄÀÏ¿¡´Â
I'm a invalid secret file
À̶ó´Â ½ºÆ®¸µÀÌ µé¾îÀÖ°í Àб⠱ÇÇѸ¸ ÀÖ¾î ¼öÁ¤ÀÌ ºÒ°¡´ÉÇÏ´Ù.

±×·³ ´Ù¸¥µ¥¼­ ÀÐÀ¸¸é µÇÁö ¾Ê°Ú³ª ½Í¾î¼­ ½Éº¼¸¯ ¸µÅ©¸¦ ÀÌ¿ëÇØº¸¾Ò´Ù.

tmp Æú´õ¿¡ ´ÙÀ½°ú °°ÀÌ ÇÁ·Î±×·¥ÀÇ ½Éº¼¸¯ ¸µÅ©¸¦ °Ç´Ù.

bom@ubuntu:/tmp/max$ ln -s /home/bom/bom_owned aa

±×·³ ÀÌÁ¦ tmp Æú´õ¿¡ ´ÙÀ½°ú °°Àº ÆÄÀÏÀÌ ÀÖÀ» °ÍÀÌ´Ù.

lrwxrwxrwx  1 bom  bom    19 2010-09-18 18:35 aa -> /home/bom/bom_owned*

½Éº¼¸¯ ¸µÅ©´Â °£´ÜÈ÷ »ý°¢Çϸé ÀÎÅͳÝÀÇ Áñ°Üã±â¿Í µ¿ÀÏÇÑ °ÍÀ¸·Î
ÆÄÀÏÀÌ ¿ø·¡ ÆÄÀÏÀ» °¡¸®Å°¸ç ÇØ´ç ÆÄÀÏ ½ÇÇà½Ã ¿øº» ÆÄÀÏÀ» ½ÇÇàÇÏ´Â ÆÄÀÏÀ̶ó°í º¸¸é µÈ´Ù.

¶ÇÇÑ ¿ø·¡ ¸ñÀûÀÌ secret ÆÄÀÏÀ» Àдµ¥ ¿©±â¼­ º¸¸é Àý´ë °æ·Î°¡ ¾Æ´Ñ »ó´ë°æ·Î¸¦ ÀÌ¿ëÇØ Âü°íÇÑ´Ù.
Áï /home/bom/secret ÀÌ ¾Æ´Ñ ÇÁ·Î±×·¥ÀÌ Á¸ÀçÇÏ´Â Æú´õ ³»ÀÇ secretÀ» Àд °ÍÀÌ´Ù.

±×·¯¹Ç·Î secret ÆÄÀϵµ ´ÙÀ½°ú °°ÀÌ ¸¸µé¾îÁØ´Ù.
bom@ubuntu:/tmp/max$ cat > secret
tell me your secret!

ÀÚ ÀÌÁ¦ ½ÇÇàÇØº¸ÀÚ.

bom@ubuntu:/tmp/max$ ./aa
/bin/cat: key: No such file or directory
Finished.

½ÇÇàÀº Àß µÇ¾ú´Âµ¥ keyÆÄÀÏÀ» ÀÐÀ¸·Á°í ÇÏ´Ï ¾ø´Ù°í ±×·±´Ù.
±×·¯¹Ç·Î Ű ÆÄÀÏÀ» ¸¸µé¾îÁÖÀÚ.
À̶§µµ ¸¶Âù°¡Áö·Î ¼Ò½º¸¦ º¸¸é /bin/cat key ·Î½á Àý´ë °æ·Î°¡ ¾Æ´Ñ »ó´ë°æ·Î·Î ÆÄÀÏÀ» Àб⠶§¹®¿¡ ½Éº¼¸¯ ¸µÅ©¸¦ ÀÌ¿ëÇØ key ÆÄÀÏÀ» ¸¸µé¾î¾ß ÇÑ´Ù.

bom@ubuntu:/tmp/max$ ln -s /home/bom/key key

ÀÌÁ¦ µð·ºÅ丮 ³»ÀÇ Àüü ÆÄÀÏÀº ´ÙÀ½°ú °°´Ù.

lrwxrwxrwx  1 bom  bom    19 2010-09-18 18:35 aa -> /home/bom/bom_owned*
lrwxrwxrwx  1 bom  bom    13 2010-09-18 18:36 key -> /home/bom/key
-rw-r--r--  1 bom  bom    21 2010-09-18 18:35 secret

ÀÌÁ¦ aa¸¦ ½ÇÇàÇÏ¸é ³»½ºÅ¸ÀÏÀº ¾Æ´ÏÁö¸¸ º½µµ ³»²¨.

  Hit : 7574     Date : 2010/09/18 06:19



    
DeathStalker ¸Æ½ºÇü °í¸¶¿ö ¤¾¤¾ ´öºÐ¿¡ °øºÎ ‰ç¾î ¤¾¤¾ 2010/09/18  
ganesha °í¸¿½À´Ï´Ù Àß º¸°í °©´Ï´Ù ¤¾¤¾ 2010/09/19  
williamlee ¿À °¨»ç! 2010/09/19  
396   [ÀÚÀÛ]GoogleÇØÅ·±âº»-ÀÍ¸í¼ºÀ» À§ÇÑ Ä³½Ã»ç¿ëPart1[7]     lsn10919
10/09 7559
395   Shift ÀÇ °£ÆíÇÑ 9°¡Áö ±â´É[12]     Ǫ¸¥ÇÏ´Ã
12/02 7549
394     [re] tseugÀÇ Ãʺ¸¸¦ À§ÇÑ ¹®Á¦ [1] ÇØ¼³![2]     tseug
10/18 7548
393   ÃÖ´ëÈ­[1]     goldcsj
08/13 7548
392   [ÀÚÀÛ] ÇÁ¶óÀ̵åÀÇ C °­Á 1ìíÂ÷ (1) C¾ð¾î¶õ ?     ÇÁ¶óÀ̵å
08/20 7543
391   ¡áHDD (ÇÏµå µð½ºÅ©) Layout ¼³Á¤[1]     BLu2Scr22n
01/24 7534
390   C¿¡¼­ ÇÁ·Î±×·¥ÀÇ ¼Óµµ¸¦ ¿Ã¸®ÀÚ.[8]     kjwon15
03/06 7534
389   [ÀÚÀÛ±Û]ÇØÅ·À» ¹è¿ï¶§ °¡Á®¾ß ÇÏ´Â ¸¶À½ °¡Áü     ÇѽÂÀç
12/23 7533
388   °£´ÜÇÑÅ©·º[9]     qzoom
11/11 7528
387   Ä«À̽ºÆ®¿¡ ÄÚµå°ÔÀÌÆ® 2011 º¸°í¼­ ÀÔ´Ï´Ù.[3]     BLu2Scr22n
02/23 7522
386   À¥»ó¿¡¼­ÀÇ °­ÀǸ¦ ¼ÒÀåÇÏ°í ½ÍÀ»¶§ ÀÌ·¸°Ô Çϼ¼¿ä.[3]     vbvbdldh
02/18 7521
385   ¾È³çÇϼ¼¿ä^^     kakaman
09/11 7506
384       [re] [re] ȨÆäÀÌÁö Ãë¾àÁ¡ Á¡°Ë ¹× Á¶Ä¡¹æ¹ý#1     answp
03/15 7505
383   chenkim4ÀÇ ¹ÙÀÌ·¯½ºÀÇ À¯·¡ Æí[1]     chenkim4
08/27 7505
382   [º¸¾È´º½º] Áß±¹ÇØÄ¿¿¡°Ô ÀÎÅͳݹðÅ·ÀÌ Èçµé¸®°íÀÖ´Ù.     dzhfldk
08/22 7500
381     [re] Á» ´Ù¸£°Ô ÇØ¼®[4]     rootguy
09/14 7497
380     [re] ¾ÕÀ¸·Î À̾îÁú ±Û¿¡ ´ëÇØ¼­.....     answp
01/01 7493
379   * printf »ç¿ë¹ý     limjongmin
08/20 7492
378     [re] [Àâ] ³×Æ®¿öÅ© TCP     answp
01/01 7492
377   c¾ð¾î[2]     jyc_joy
01/17 7490
[1]..[61] 62 [63][64][65][66][67][68][69][70]..[81]

Copyright 1999-2025 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org