83, 3/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://www.hackerschool.org
   [°øÁö] BOF ¿øÁ¤´ë ¼­ºñ½º¸¦ ¿ÀÇÂÇÕ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Notice&no=1170881885 [º¹»ç]


[BOF-BufferOverflow- ¿øÁ¤´ë¶õ?]
ºñ±³Àû ½¬¿î BOF °ø·« ȯ°æÀÎ Redhat 6.2¿¡¼­ºÎÅÍ ±Ã±ØÀÇ Fedora 14±îÁö
¼ö½Ê°³ÀÇ ·¹º§À» °ÅÃÄ°¡¸ç BOF ½Ã½ºÅÛ ÇØÅ· ½Ç½ÀÀ» ÇÏ´Â War-GameÀÔ´Ï´Ù.

[Á¢¼Ó ¹æ¹ý]
BOF ¿øÁ¤´ë´Â µµ¸ÞÀÎÀ̳ª IP°¡ ¾Æ´Ñ, vmware À̹ÌÁö ÇüÅ·ΠÁ¦°øÇÕ´Ï´Ù.
µû¶ó¼­ °¢ÀÚÀÇ PC¿¡ ¿ö°ÔÀÓ ¼­¹ö¸¦ °¡µ¿ÇϽŠÈÄ Á¢¼ÓÇØ Ç®¾î³ª°¡´Â ¹æ½ÄÀÔ´Ï´Ù.

[´Ù¿î·Îµå]
1. ´ÙÀ½ Vmware À̹ÌÁö¸¦ ´Ù¿î¹Þ¾Æ ºÎÆÃÇÑ´Ù.
http://work.hackerschool.org/DOWNLOAD/TheLordOfTheBOF/TheLordOfTheBOF_redhat.zip

vmware »óÀ§ ¹öÀü¿¡¼­ ºÎÆà ¾È µÇ´Â ¿À·ù¸¦ ¼öÁ¤ÇÏ¿© ´Ù½Ã ¿Ã·È½À´Ï´Ù.
http://hackerschool.org/TheLordofBOF/TheLordOfTheBOF_redhat_bootable.zip

2. gate/gate·Î ·Î±×ÀÎÇÑ´Ù.
3. netconfig ¸í·ÉÀ¸·Î ³×Æ®¿öÅ© ¼³Á¤À» ÇÑ´Ù. (setuid °É¾î ³ù½À´Ï´Ù)
4. ip¸¦ È®ÀÎÇÑ´Ù. (/sbin/ifconfig)
5. putty, xshellµîÀ¸·Î Å͹̳ΠÁ¢¼ÓÇÏ¿© ¹®Á¦ Ç®À̸¦ ½ÃÀÛÇÑ´Ù. (telnet)

[±âº» ·ê]
1. single boot ±ÝÁö
2. root exploit ±ÝÁö
3. /bin/my-pass ¸í·É¿¡ LD_PRELOAD »ç¿ë ±ÝÁö

[·¹º§¾÷ Æнº¿öµå È®ÀÎ]
/bin/my-pass

[Àü¿ë °Ô½ÃÆÇ]
http://www.hackerschool.org/HS_Boards/zboard.php?id=bof_fellowship

[¸÷ ¸®½ºÆ®]
LEVEL1 (gate -> gremlin) :  simple bof
LEVEL2 (gremlin -> cobolt) : small buffer
LEVEL3 (cobolt -> goblin) : small buffer + stdin
LEVEL4 (goblin -> orc) : egghunter
LEVEL5 (orc -> wolfman) : egghunter + bufferhunter
LEVEL6 (wolfman -> darkelf) : check length of argv[1] + egghunter + bufferhunter
LEVEL7 (darkelf -> orge) : check argv[0]
LEVEL8 (orge -> troll) : check argc
LEVEL9 (troll -> vampire) : check 0xbfff
LEVEL10 (vampire -> skeleton) : argv hunter
LEVEL11 (skeleton -> golem) : stack destroyer
LEVEL12 (golem -> darkknight) : sfp
LEVEL13 (darkknight -> bugbear) : RTL1
LEVEL14 (bugbear -> giant) : RTL2, only execve
LEVEL15 (giant -> assassin) : no stack, no RTL
LEVEL16 (assassin -> zombie_assassin) : fake ebp
LEVEL17 (zombie_assassin -> succubus) : function calls
LEVEL18 (succubus -> nightmare) : plt
LEVEL19 (nightmare -> xavis) : fgets + destroyers
LEVEL20 (xavis -> death_knight) : remote BOF

* Level20±îÁöÀÇ ¸÷µéÀ» ¸ðµÎ ÀâÀ¸½Å ÈÄ Ç®À̹ýÀ» BOF Àü¿ë °Ô½ÃÆÇ¿¡
¿Ã¸®¸é, Fedora ¼ºÀ¸·Î ÀÔÀåÇÒ ¼ö ÀÖ´Â ±ÇÇÑÀ» ºÎ¿©ÇØ µå¸³´Ï´Ù.

* ±×µ¿¾È º£Å¸ Å×½ºÆÿ¡ Âü¿©ÇØÁֽŠ¸¹Àº ºÐµé²² °¨»çµå¸³´Ï´Ù.
trynerr, codeache, passket, stolenbyte, eM, buff3r, »êÀû, hex0d, sorucA´Ô µîµîµî

* FedoraÂÊÀÇ ´ëºÎºÐÀÇ ¹®Á¦¸¦ Á¦°øÇØ ÁֽŠrandomkid´Ô²²µµ °¨»çµå¸³´Ï´Ù.

  Hit : 80716     Date : 2010/09/23 12:05



    
xodnr631 ºÎžÄ! Àú³è¿¡ ½ÃµµÇغÁ¾ß°Ú±ºŸD 2010/09/23  
ÇÁ¶óÀÌµå ±Ùµ¥ level3Àΰ¡? ±×±îÁö¸¸ ftz¼öÁØ°°´øµ¥ ¾Æ¸¶ 2010/09/23  
trynerr Çü´Ô nÀÌ ºüÁ³½À´Ï´Ù. Àß »ì°í °è½ÃÁö¿ä? ´Ã ÁÁÀº ¹®Á¦ °¨»çÇØ¿ä ¤¾¤¾ 2010/09/23  
¸Û¸Û ½î¸®.. ¤»¤» ȸ»ç ÀÏ Àß Çϱ¸ ÀÖ¾î? ¿äÁò º¸±â Èûµå³×~ 2010/09/30  
trynerr ȸ»çÀÏ ¿­½ÉÈ÷ ÇÏ°í ÀÖÁö¿ä ¤¾¤¾ ÇÑÂü ºÎÁ·ÇÔÀ» ¸¹ÀÌ ´À³¢³×¿ä~~ ¿­½ÉÈ÷ ÇؾßÁÒ~~ Æ´Æ´È÷ µé¾î¿Í¼­ ´«ÆÃÇÏ°íÀÖ¾î¿ä Á¶¸¸°£ ¿øÁ¤´ë ¹®Á¦µµ ´Ù½Ã µµÀüÇÒ²²¿ä ^_^ 2010/10/01  
dbgksals123 À¸Çã¾û.. ¹«½¼¼Ò¸®ÀÎÁö Çϳªµµ ¸ð¸£°Ú¾î¿ä ¤Ð¤Ð ÇØÅ·°øºÎ Á» ´õ ¿­½ÉÈ÷ ÇØ¾ß ÇÒµí.. 2011/02/12  
¸ñŹµç±³È²´Ô ¹¹ÁÒ... ¸®´ª½º°øºÎ ¸¹ÀÌ Çؾ߰ξî¿ä. C¾ð¾î¹Û¿¡ °íºÎ¸¦ ¾ÈÇؼ­... ;;
±×°Íµµ 1³âÀÌ ¾ÈµÊ ¤Ð¤Ð
2011/05/02  
w7040 À̰Ŷû ´ëÇб³¿¡ ÀÖ´Â ÆÄÀÏÀ̶û ´Ù¸¥°Ç°¡¿ä ?? 2011/05/09  
¸Û¸Û w7040/ µ¿ÀÏÇÑ °Ì´Ï´Ù~! 2011/05/16  
jjjjangku ºÎ·´³×¿ä ¤Ð¤Ð 2011/10/10  
vbvbdldh Àú´Â ¿Ö 1¹ø¾Æ·¡ ¸µÅ©µÈ ÆÄÀÏÀÌ ´Ù¿î·Îµå°¡ ¾ÈµÉ±î¿ä? ..; 2011/11/27  
jwkzzangs ´Ù¿î ¾È ¹Þ¾Æ Áö³×¿ä 2012/01/17  
rocket07 gate/gate Á¢¼ÓÀÌ ¾ÈµÇ´Âµ¥¿ä ..?

root /hackerschool ·Î µé¾î°¡¼­ netconfig Çغôµ¥ netconfig ¼³Á¤Ç϶ó´Â°Ô ¹«½¼¶æÀΰ¡¿ä?

°Å±â´Ù°¡ Àڱ⠾ÆÀÌÇÇ ÀûÀ¸¸éµÇ³ª¿ä?
2012/01/21  
ehit À̹ÌÁö°¡ ¾È¹Þ¾ÆÁ®¿ä¤Ì¤Ì


work.hackerschool.org¿¡ ¿¬°áÇÒ ¼ö ¾ø½À´Ï´Ù.


·¡¿ä? ¤Ì¤Ì
2012/12/01  
kkd927 ´Ù¿îÀÌ ¾È¹Þ¾ÆÁ®¿ä ¤Ð¤Ð 2013/09/30  
namjmnam ºÎÆÃÀÌ... ¿µ¿øÈ÷ ¾È µÇ³×¿ä... 2013/12/25  
buga0205 ºÎÆÃÀÌ ¾ÈµÈ´Ù ¤Ð 2014/02/06  
¸Û¸Û vmware »óÀ§ ¹öÀü¿¡¼­ ºÎÆà ¾È µÇ´Â ¿À·ù¸¦ ¼öÁ¤ÇÏ¿© ´Ù½Ã ¿Ã·È½À´Ï´Ù.
http://hackerschool.org/TheLordofBOF/TheLordOfTheBOF_redhat_bootable.zip
2014/07/12  
eraseZEROne ÇØÄ¿½ºÄð °ü°èÀÚ ¿©·¯ºÐµéÀÇ ³ë°í¿¡ °¨»çµå¸³´Ï´Ù. (_ _) 2019/01/06  
43   [°øÁö] ¿¬±¸¼Ò 1Â÷ ÇÕ°ÝÀÚ ¹ßÇ¥ ¾È³»ÀÔ´Ï´Ù.[12]     ¸Û¸Û
06/10 9591
42   [°øÁö] Á¦ 2ȸ ÇØÄð °ø°³ ¼¼¹Ì³ª ¾È³»ÀÔ´Ï´Ù.[2]     ¸Û¸Û
08/11 6814
41   [°øÁö] º¸¾È ¼Ò½ÄÅë ÀÛ¼º ±ÇÇÑ º¯°æ ¾È³»[2]     ¸Û¸Û
08/15 6801
40   [°øÁö] ÇØÄð °ø±¸Æ¼ ½Åû ¹Þ½À´Ï´Ù.[52]     ¸Û¸Û
08/15 7663
39   [°øÁö] hacking camp, coming soon![52]     ¸Û¸Û
08/16 8336
38   [°øÁö] ÇØÅ· Ä·ÇÁ °ü·Ã![5]     ¸Û¸Û
09/06 8273
37   [°øÁö] Á¦ 3ȸ ÇØÅ· Ä·ÇÁ Âü°¡ÀÚ ¿©·¯ºÐµé ¼ö°íÇϼ̽À´Ï´Ù![23]     ¸Û¸Û
09/13 7957
  [°øÁö] BOF ¿øÁ¤´ë ¼­ºñ½º¸¦ ¿ÀÇÂÇÕ´Ï´Ù.[19]     ¸Û¸Û
09/23 80715
35   [°øÁö] Á¦ 3ȸ °ø°³ ¼¼¹Ì³ª Âü°¡ ½Åû ¹Þ½À´Ï´Ù.[20]     ¸Û¸Û
09/16 7937
34   [Ä·ÆäÀÎ] ´ñ±ÛÀº °ü½ÉÀÌÀÚ ¿¹ÀÇÀÌÀÚ ¼¾½ºÀÔ´Ï´Ù.[60]     ¸Û¸Û
08/15 8110
33   [°øÁö] ÀÚ±â¼Ò°³ ±â´ÉÀÌ Ãß°¡µÇ¾ú½À´Ï´Ù.[3]     ¸Û¸Û
10/20 7637
32   [°øÁö] Áú¹®°ú ´äº¯ °Ô½ÃÆÇÀÌ ¾÷µ¥ÀÌÆ® µÇ¾ú½À´Ï´Ù.[1]     ¸Û¸Û
11/28 7087
31   [°øÁö] ºñ¹ø ã±â ±â´ÉÀÌ º¹±¸µÇ¾ú½À´Ï´Ù.[6]     ¸Û¸Û
12/03 8135
30   [°øÁö] ÇØÅ· Ä·ÇÁ ¹× Á¦ 4ȸ °ø°³¼¼¹Ì³ª °ü·ÃÀÔ´Ï´Ù.[13]     ¸Û¸Û
02/15 8334
29   [±ä±Þ] 2011.03.04 DDoS¿¡ ´ëÇÑ Àü¿ë ¹é½ÅÀÔ´Ï´Ù.[8]     ¸Û¸Û
03/04 8728
28   [°øÁö] ¼­¹ö ±³Ã¼ ÀÛ¾÷ÀÌ ÀÖ¾ú½À´Ï´Ù.[22]     ¸Û¸Û
03/18 8865
27   Á¦ 4Â÷ °ø±¸Æ¼ ¾ÆÀ̵ð¾î Á¦¾È¹Þ½À´Ï´Ù~[15]     ¸Û¸Û
03/17 8313
26   Á¦ 5ȸ °ø°³¼¼¹Ì³ª Âü°¡ÀÚ ½Åû ¹Þ½À´Ï´Ù~[10]     ¸Û¸Û
03/17 8574
25   [°øÁö] ÇØÄ¿½ºÄð ¸ÞÀϸµ ¸®½ºÆ® ¼­ºñ½º°¡ ½ÃÀ۵˴ϴÙ.[16]     ¸Û¸Û
04/06 9111
24   [°øÁö] ÇØÄ¿½ºÄð ¹ø¿ªÆÀÀ» ¸ðÁýÇÕ´Ï´Ù.[30]     ¸Û¸Û
04/26 11673
[1][2] 3 [4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org