35, 1/2 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   trynerr
   [ÆĵµÄÜ2011] karma200 Áú¹® ¹× ³ÌµÎ¸®

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_CTF&no=5 [º¹»ç]


°è¼Ó »ðÁúÇÏ´Ù°¡ ´ëȸ³¡³ª±â 1½Ã°£ Àü¿¡ ¹®µæ »ý°¢Çس½ ¹æ¹ýÀÌ ¸ùÀÌÇüÀÌ ¸»¾¸ÇϽŠ±×ºÎºÐÀ̱¸¿ä;;
libc.6.so¿¡¼­ ãÀº°ÍÀÌ
add 10xx, esp
add 20xx, esp
´ëÃæÀÌ·¯Çѵ¥ ÀÌ°É ÀÌ¿ëÇؼ­ esp È帧Àº ´ëÃæ Àâ¾Ò°í¿ä...
ȯ°æº¯¼ö¿¡ ¹Ú¾Æ³õÀº payload·Î Á¡ÇÁ¶Ù¾î¼­ ret ½½¶óÀ̵ù ÈÄ¿¡ execlÇÔ¼ö È£ÃâÇÏ°Ô ÇØ ³õ¾Ò°Åµç¿ä;;
(ÇöÀç espÀ§Ä¡¿Í ȯ°æº¯¼ö±îÁöÀÇ °Å¸®°¡ 1000 Á¤µµ µÇ´Â°Å °°´õ¶ó±¸¿ä
retÁÖ¼Ò°¡ -> 0x12345678ÀÏ떄

add 20xx, esp ½ÇÇàÈÄ retÀ¸·Î ÀÎÇØ eip°¡  ¹ÚÈ÷´Â °ªÀÌ

0x12345678 0x12345678 0x12345678 0x12345678 0x12345678
         |              |
      esp°¡ ¿©±æ·Î ¹ÚÇô¿ä

°á±¹ eip´Â 5678 0x1234 ºÎºÐÀ» °¡¸®ÄѼ­  segmentation fault ¶¸¾ú½À´Ï´Ù;; ´çÃé ¹¹°¡ ¹®Á¦Àϱî¿ä;; ÈåÀ½;;
¸ÂÃ纸·Á°í ¾Õ¿¡ A³ª AA°°Àº °ªÀ» ³Ö¾îºÃ´Âµ¥µµ °°Àº À§Ä¡¸¦ ÂüÁ¶Çϴµ¥
add operationÀ» ´Ù¸¥°ÍÀ¸·Î Àâ¾Æ¾ßÇÒ±î¿ä;;

¹¹¸¦ À߸ø »ý°¢ÇÑ °É±î¿ä~~~;;
ÀÌ·²ÁÙ ¾Ë¾ÒÀ¸¸é ¹Ì¸®¹Ì¸® °øºÎÇÒ °É ±×·¨½À´Ï´Ù.;;¤Ð¤Ð
°°ÀÌ ÃâÀüÇÑ ÆÀ¿øµéÇÑÅ× ¾ó±¼À» µé°í ´Ù´Ò¼ö°¡ ¾ø³×¿ä;;

¼ö°íÇϽʽÿÀ °¨»çÇÕ´Ï´Ù.

  Hit : 3918     Date : 2011/01/20 02:57



    
¸Û¸Û add·Î ´õÇÑ °ªÀÌ 4ÀÇ ¹è¼ö°¡ ¾Æ´Ñ°¡º¸³×~ 4ÀÇ ¹è¼öÀÎ °ÍÀ» ´Ù½Ã ã°Å³ª..
±×°É ã±â°¡ ¾î·Á¿ì¸é ret ½½¶óÀ̵ù ³¡¿¡ add 2, esp / ret °°Àº °É Çѹø ³Ö¾îÁà
¿¨ ±Ùµ¥ ±×³ªÀú³ª ret ½½¶óÀ̵ùÀº Àß µÅ? =_= ÀÌ»óÇÏ³× ¤¾¤¾
±×¸®°í ȯ°æº¯¼ö¿¡ ¿Ã¸° payloadµéÀ» 2¹ÙÀÌÆ®¾¿ shift½ÃÄѵµ µÉ °Í °°Àºµ¥.. Çغôٰí? ¿Ö ¾ÈµÉ±î..
µð¹ö±ëÇÑ ³»¿ëÀÌ¶óµµ º¹»çÇؼ­ ¿Ã·ÁÁàºÁ~
2011/01/21  
trynerr ¾È±×·¡µµ À̹ø¿¡ ¹®Á¦Á» ´Ù½Ã Ç®¾îº¸·Á°í ÇÕ´Ï´Ù.
°°ÀºÈ¯°æ¿¡¼­ ÇؾßÇϴµ¥ VMÀ̹ÌÁöÁ» ¾òÀ»¼ö ÀÖÀ»±î¿ä?
¾Æ´Ô fedora°¡ libc¿¡ ´ëÇÑ aslrÀÌ ¾È°É·Á Àִ°Š°°Àºµ¥
¾îµð¼­ ¾òÀ»¼ö ¾ø³ª¿ä???
2011/01/21  
¸Û¸Û Fedora 14 ¼³Ä¡ ÈÄ ÇÏ¸é µÉ °Í °°»ï.. ±Û°í ´ëȸ ¼­¹ö¿¡¼­µµ ASLR ¾È °É·ÁÀÖ¾ú¾î~
FedoraÀÇ Æ¯Â¡ÀÌ Ã³À½ ¼³Ä¡ ÈÄ 2½Ã°£ Á¤µµ°¡ Áö³ª¸é ASLRÀÌ Ç®·Á¹ö¸®´õ¶ó°í-_-
2011/01/24  
trynerr Çä!! Á¤¸»¿ä??
¹¹ ±×·± -_-a Àü ´ç¿¬È÷ °É·ÁÀÖÁÙ ¾Ë¾Ò°í À̹ø ´ëȸ¼­¹ö¿¡¼­´Â ¹®Á¦¶§¹®¿¡ ÀϺη¯ disable ½ÃŲÁÙ ¾Ë¾Ò¾î¿ä~~~
2011/01/24  
¸Û¸Û ±×·¯°Ô~ ¤¾¤¾ 2011/02/25  
35   ÇöÀç ÇØÅ· ´ëȸ°¡ ³¡³µ³ª ¾È³¡³µ³ª ¸ð¸£°Ù´Âµ¥ ÀÌ Áú¹®Àº °øÁ¤¼º¿¡´Â ¹ÌÄ¡Áö ¾Ê½À´Ï´Ù.[3]     Àü»ç
01/04 3851
34   [ÆĵµÄÜ2011] karma100 °ú goe200 Áú¹®ÀÔ´Ï´Ù.[6]     I'm Not GoN
01/17 4544
33   [ÆĵµÄÜ2011] fc4 ÀÌÈķκÎÅÍ bof ±â¹ý..[2]     µÎ·ç¹¶¼ú
01/17 5224
  [ÆĵµÄÜ2011] karma200 Áú¹® ¹× ³ÌµÎ¸®[5]     trynerr
01/20 3917
31   [ÄÚµå°ÔÀÌÆ®2011] ÄÚµå°ÔÀÌÆ® 2011 À»º¸°í...[4]     asdwho
03/06 4062
30   [ÄÚµå°ÔÀÌÆ®2011] ÄÚµå°ÔÀÌÆ® ¹®Á¦..[5]     µÎ·ç¹¶¼ú
03/06 5423
29   [ÄÚµå°ÔÀÌÆ®2011] Æ÷·»½Ä100 Áú¹®[5]     W.H.
03/06 4477
28   [ÄÚµå°ÔÀÌÆ®2011] crypto 300[2]     xzvsda
03/07 4034
27   [ÄÚµå°ÔÀÌÆ®2011] network100 ¹®Á¦ Áú¹®ÀÌ ÀÖ½À´Ï´Ù.!!¤¾[2]     BkeMan
03/07 3777
26   [ÄÚµå°ÔÀÌÆ®2011] vuln 100 ¹¹ÁÒ;;;[1]     supershop
03/07 3864
25   [ÄÚµå°ÔÀÌÆ® 2011] issue 3¹ø¹®Á¦..[3]     asdwho
03/08 4218
24   ´ëȸ¶õ..............................[3]     akwjs566
03/14 3817
23   [ÄÚµå°ÔÀÌÆ® 2011] binary 100¹®Á¦¿¡¼­..[1]     asdwho
03/18 4609
22   pCTF ¿¡¼­¿ä. 2¹ø¹®Á¦.[4]     Ǭ¼ö¿ÕÀÚ
04/27 4098
21   ÇØÅ·´ëȸ[2]     ¿­Á¤
05/14 3963
20   Çѱ¹Á¤º¸¿Ã¸²ÇǾƵå[6]     alswovkdlxj
05/20 4619
19   ÇØÅ·´ëȸ...[5]     rudwo4685
06/17 4705
18 ºñ¹Ð±ÛÀÔ´Ï´Ù  2012 µ¿°è ÇØÅ·Ä·ÇÁ ¹®Á¦¿¡¼­..[1]     asdwho
02/23 2
17   ÇØÄ¿½ºÄð ¸ÞÀο¡ ¿Ã¶ó¿ÍÀÕ´Â ÄÚµå°ÔÀÌÆ® 2012 ¹æ¾î±â¼ú¾ÆÀ̵ð¾î ÄÁÅ×½ºÆ®¿¡ ´ëÇؼ­..Áú¹®[1]     windowhan
03/11 3735
16   ÇØÅ·´ëȸ¸¦ ³ª°¡·Á°í ÇÕ´Ï´Ù[3]     anona
03/15 4049
1 [2]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org