83, 1/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://www.hackerschool.org
   [°øÁö] BOF ¿øÁ¤´ë ¼­ºñ½º¸¦ ¿ÀÇÂÇÕ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Notice&no=1170881885 [º¹»ç]


[BOF-BufferOverflow- ¿øÁ¤´ë¶õ?]
ºñ±³Àû ½¬¿î BOF °ø·« ȯ°æÀÎ Redhat 6.2¿¡¼­ºÎÅÍ ±Ã±ØÀÇ Fedora 14±îÁö
¼ö½Ê°³ÀÇ ·¹º§À» °ÅÃÄ°¡¸ç BOF ½Ã½ºÅÛ ÇØÅ· ½Ç½ÀÀ» ÇÏ´Â War-GameÀÔ´Ï´Ù.

[Á¢¼Ó ¹æ¹ý]
BOF ¿øÁ¤´ë´Â µµ¸ÞÀÎÀ̳ª IP°¡ ¾Æ´Ñ, vmware À̹ÌÁö ÇüÅ·ΠÁ¦°øÇÕ´Ï´Ù.
µû¶ó¼­ °¢ÀÚÀÇ PC¿¡ ¿ö°ÔÀÓ ¼­¹ö¸¦ °¡µ¿ÇϽŠÈÄ Á¢¼ÓÇØ Ç®¾î³ª°¡´Â ¹æ½ÄÀÔ´Ï´Ù.

[´Ù¿î·Îµå]
1. ´ÙÀ½ Vmware À̹ÌÁö¸¦ ´Ù¿î¹Þ¾Æ ºÎÆÃÇÑ´Ù.
http://work.hackerschool.org/DOWNLOAD/TheLordOfTheBOF/TheLordOfTheBOF_redhat.zip

vmware »óÀ§ ¹öÀü¿¡¼­ ºÎÆà ¾È µÇ´Â ¿À·ù¸¦ ¼öÁ¤ÇÏ¿© ´Ù½Ã ¿Ã·È½À´Ï´Ù.
http://hackerschool.org/TheLordofBOF/TheLordOfTheBOF_redhat_bootable.zip

2. gate/gate·Î ·Î±×ÀÎÇÑ´Ù.
3. netconfig ¸í·ÉÀ¸·Î ³×Æ®¿öÅ© ¼³Á¤À» ÇÑ´Ù. (setuid °É¾î ³ù½À´Ï´Ù)
4. ip¸¦ È®ÀÎÇÑ´Ù. (/sbin/ifconfig)
5. putty, xshellµîÀ¸·Î Å͹̳ΠÁ¢¼ÓÇÏ¿© ¹®Á¦ Ç®À̸¦ ½ÃÀÛÇÑ´Ù. (telnet)

[±âº» ·ê]
1. single boot ±ÝÁö
2. root exploit ±ÝÁö
3. /bin/my-pass ¸í·É¿¡ LD_PRELOAD »ç¿ë ±ÝÁö

[·¹º§¾÷ Æнº¿öµå È®ÀÎ]
/bin/my-pass

[Àü¿ë °Ô½ÃÆÇ]
http://www.hackerschool.org/HS_Boards/zboard.php?id=bof_fellowship

[¸÷ ¸®½ºÆ®]
LEVEL1 (gate -> gremlin) :  simple bof
LEVEL2 (gremlin -> cobolt) : small buffer
LEVEL3 (cobolt -> goblin) : small buffer + stdin
LEVEL4 (goblin -> orc) : egghunter
LEVEL5 (orc -> wolfman) : egghunter + bufferhunter
LEVEL6 (wolfman -> darkelf) : check length of argv[1] + egghunter + bufferhunter
LEVEL7 (darkelf -> orge) : check argv[0]
LEVEL8 (orge -> troll) : check argc
LEVEL9 (troll -> vampire) : check 0xbfff
LEVEL10 (vampire -> skeleton) : argv hunter
LEVEL11 (skeleton -> golem) : stack destroyer
LEVEL12 (golem -> darkknight) : sfp
LEVEL13 (darkknight -> bugbear) : RTL1
LEVEL14 (bugbear -> giant) : RTL2, only execve
LEVEL15 (giant -> assassin) : no stack, no RTL
LEVEL16 (assassin -> zombie_assassin) : fake ebp
LEVEL17 (zombie_assassin -> succubus) : function calls
LEVEL18 (succubus -> nightmare) : plt
LEVEL19 (nightmare -> xavis) : fgets + destroyers
LEVEL20 (xavis -> death_knight) : remote BOF

* Level20±îÁöÀÇ ¸÷µéÀ» ¸ðµÎ ÀâÀ¸½Å ÈÄ Ç®À̹ýÀ» BOF Àü¿ë °Ô½ÃÆÇ¿¡
¿Ã¸®¸é, Fedora ¼ºÀ¸·Î ÀÔÀåÇÒ ¼ö ÀÖ´Â ±ÇÇÑÀ» ºÎ¿©ÇØ µå¸³´Ï´Ù.

* ±×µ¿¾È º£Å¸ Å×½ºÆÿ¡ Âü¿©ÇØÁֽŠ¸¹Àº ºÐµé²² °¨»çµå¸³´Ï´Ù.
trynerr, codeache, passket, stolenbyte, eM, buff3r, »êÀû, hex0d, sorucA´Ô µîµîµî

* FedoraÂÊÀÇ ´ëºÎºÐÀÇ ¹®Á¦¸¦ Á¦°øÇØ ÁֽŠrandomkid´Ô²²µµ °¨»çµå¸³´Ï´Ù.

  Hit : 80887     Date : 2010/09/23 12:05



    
xodnr631 ºÎžÄ! Àú³è¿¡ ½ÃµµÇغÁ¾ß°Ú±ºŸD 2010/09/23  
ÇÁ¶óÀÌµå ±Ùµ¥ level3Àΰ¡? ±×±îÁö¸¸ ftz¼öÁØ°°´øµ¥ ¾Æ¸¶ 2010/09/23  
trynerr Çü´Ô nÀÌ ºüÁ³½À´Ï´Ù. Àß »ì°í °è½ÃÁö¿ä? ´Ã ÁÁÀº ¹®Á¦ °¨»çÇØ¿ä ¤¾¤¾ 2010/09/23  
¸Û¸Û ½î¸®.. ¤»¤» ȸ»ç ÀÏ Àß Çϱ¸ ÀÖ¾î? ¿äÁò º¸±â Èûµå³×~ 2010/09/30  
trynerr ȸ»çÀÏ ¿­½ÉÈ÷ ÇÏ°í ÀÖÁö¿ä ¤¾¤¾ ÇÑÂü ºÎÁ·ÇÔÀ» ¸¹ÀÌ ´À³¢³×¿ä~~ ¿­½ÉÈ÷ ÇؾßÁÒ~~ Æ´Æ´È÷ µé¾î¿Í¼­ ´«ÆÃÇÏ°íÀÖ¾î¿ä Á¶¸¸°£ ¿øÁ¤´ë ¹®Á¦µµ ´Ù½Ã µµÀüÇÒ²²¿ä ^_^ 2010/10/01  
dbgksals123 À¸Çã¾û.. ¹«½¼¼Ò¸®ÀÎÁö Çϳªµµ ¸ð¸£°Ú¾î¿ä ¤Ð¤Ð ÇØÅ·°øºÎ Á» ´õ ¿­½ÉÈ÷ ÇØ¾ß ÇÒµí.. 2011/02/12  
¸ñŹµç±³È²´Ô ¹¹ÁÒ... ¸®´ª½º°øºÎ ¸¹ÀÌ Çؾ߰ξî¿ä. C¾ð¾î¹Û¿¡ °íºÎ¸¦ ¾ÈÇؼ­... ;;
±×°Íµµ 1³âÀÌ ¾ÈµÊ ¤Ð¤Ð
2011/05/02  
w7040 À̰Ŷû ´ëÇб³¿¡ ÀÖ´Â ÆÄÀÏÀ̶û ´Ù¸¥°Ç°¡¿ä ?? 2011/05/09  
¸Û¸Û w7040/ µ¿ÀÏÇÑ °Ì´Ï´Ù~! 2011/05/16  
jjjjangku ºÎ·´³×¿ä ¤Ð¤Ð 2011/10/10  
vbvbdldh Àú´Â ¿Ö 1¹ø¾Æ·¡ ¸µÅ©µÈ ÆÄÀÏÀÌ ´Ù¿î·Îµå°¡ ¾ÈµÉ±î¿ä? ..; 2011/11/27  
jwkzzangs ´Ù¿î ¾È ¹Þ¾Æ Áö³×¿ä 2012/01/17  
rocket07 gate/gate Á¢¼ÓÀÌ ¾ÈµÇ´Âµ¥¿ä ..?

root /hackerschool ·Î µé¾î°¡¼­ netconfig Çغôµ¥ netconfig ¼³Á¤Ç϶ó´Â°Ô ¹«½¼¶æÀΰ¡¿ä?

°Å±â´Ù°¡ Àڱ⠾ÆÀÌÇÇ ÀûÀ¸¸éµÇ³ª¿ä?
2012/01/21  
ehit À̹ÌÁö°¡ ¾È¹Þ¾ÆÁ®¿ä¤Ì¤Ì


work.hackerschool.org¿¡ ¿¬°áÇÒ ¼ö ¾ø½À´Ï´Ù.


·¡¿ä? ¤Ì¤Ì
2012/12/01  
kkd927 ´Ù¿îÀÌ ¾È¹Þ¾ÆÁ®¿ä ¤Ð¤Ð 2013/09/30  
namjmnam ºÎÆÃÀÌ... ¿µ¿øÈ÷ ¾È µÇ³×¿ä... 2013/12/25  
buga0205 ºÎÆÃÀÌ ¾ÈµÈ´Ù ¤Ð 2014/02/06  
¸Û¸Û vmware »óÀ§ ¹öÀü¿¡¼­ ºÎÆà ¾È µÇ´Â ¿À·ù¸¦ ¼öÁ¤ÇÏ¿© ´Ù½Ã ¿Ã·È½À´Ï´Ù.
http://hackerschool.org/TheLordofBOF/TheLordOfTheBOF_redhat_bootable.zip
2014/07/12  
eraseZEROne ÇØÄ¿½ºÄð °ü°èÀÚ ¿©·¯ºÐµéÀÇ ³ë°í¿¡ °¨»çµå¸³´Ï´Ù. (_ _) 2019/01/06  
  [°øÁö] BOF ¿øÁ¤´ë ¼­ºñ½º¸¦ ¿ÀÇÂÇÕ´Ï´Ù.[19]     ¸Û¸Û
09/23 80886
82   [°øÁö] ¸®´ª½º Ä¿³ÎÀÇ do_mremap() Ãë¾àÁ¡¿¡ ´ëÇÑ ±Ç°í¹®ÀÔ´Ï´Ù.[105]     ¸Û¸Û
01/27 23932
81   [°øÁö] ¸®´ª½º Ä¿³ÎÀÇ do_brk() Ãë¾àÁ¡¿¡ ´ëÇÑ ±Ç°í¹® ÀÔ´Ï´Ù.[181]     ¸Û¸Û
12/18 18907
80   [°øÁö] »çÀÌÆ® ¾÷µ¥ÀÌÆ® ÁøÇà »óȲÀÔ´Ï´Ù.[82]     ¸Û¸Û
01/09 17836
79   BOF ¿øÁ¤´ë ÇöÀç ½ºÄÚ¾î (5/3ÀÏ ¾÷µ¥ÀÌÆ®)[25]     ¸Û¸Û
02/26 17498
78   [°øÁö] ÇØÄ¿½ºÄð ¾÷µ¥ÀÌÆ® ³»¿ëÀÔ´Ï´Ù.[39]     ¸Û¸Û
09/15 14667
77   [°øÁö] 07³â 6, 7¿ù ¿ì¼ö ȸ¿ø ¼±Á¤ °á°úÀÔ´Ï´Ù.[71]     ¸Û¸Û
11/01 14413
76   [°øÁö] Â÷ÈÄ ÇØÄ¿½ºÄð ¿î¿µ °èȹÀÔ´Ï´Ù.[82]     ¸Û¸Û
02/21 14286
75   [°øÁö] FTZ ¼­¹ö ÀÌÀü ¾È³»ÀÔ´Ï´Ù.[35]     ¸Û¸Û
09/27 13843
74   ÇØÄð °ø°³¼¼¹Ì³ª - Çϵå¿þ¾î ÇØÅ· ±âÃÊ (ÀçÁøÇà)[13]     ¸Û¸Û
10/18 13411
73   [°øÁö] FTZ Çϵå¿þ¾î¸¦ ¾÷±×·¹À̵å ÇÏ¿´½À´Ï´Ù.[46]     ¸Û¸Û
02/14 13233
72   2013³â µ¿°è ÇÙÄ· ³¯Â¥ & ¹ßÇ¥ÀÚ ¸ðÁý[26]     ¸Û¸Û
01/10 13186
71   [°øÁö] ÇØÄ¿½ºÄð ¼¼¹Ì³ª - C¾ð¾î Æ÷ÀÎÅÍ Æ¯°­ ¾È³»ÀÔ´Ï´Ù.[6]     ¸Û¸Û
01/10 12879
70   [°øÁö] Ãʵù&¿©¼º CTF °á°úÀÔ´Ï´Ù[12]     ¸Û¸Û
11/16 12762
69   [°øÁö] ÇØÄ¿½ºÄð4°¡ µåµð¾î ¿ÀǵǾú½À´Ï´Ù.^^[34]     ¸Û¸Û
09/01 12425
68   ÇØÄð BOF(Buffer Overflow) ¿øÁ¤´ë ¸ðÁý![33]     ¸Û¸Û
02/26 12376
67   [ÇØÅ·´ëȸ] Á¦ 2ȸ ÃʵîÇлý CTF°¡ °³Ãֵ˴ϴÙ.[25]     ¸Û¸Û
10/22 12165
66   [°øÁö] °­Á ¾÷µ¥ÀÌÆ® ¾È³»ÀÔ´Ï´Ù.[16]     ¸Û¸Û
01/21 12109
65   [°øÁö] ÇØÄð¼¥À» ¿ÀÇÂÇÕ´Ï´Ù.[18]     ¸Û¸Û
10/13 11999
64   [°øÁö] FTZ ¼­ºñ½º Á¡°Ë ÁßÀÔ´Ï´Ù.[39]     ¸Û¸Û
05/06 11860
1 [2][3][4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org