97, 1/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   healer
   Á¦¸ñ_¾øÀ½.png (0 Byte), Download : 16     [¿À¸¥ÂÊ ¹öÆ° ´­·¯ ´Ù¿î ¹Þ±â]
   ¸®¹ö½Ì __security_cookie

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Reversing&no=111 [º¹»ç]



00EA16BE ºÎÅÍ 00EA16CB ±îÁö ³ë¶û»ö ¹Ú½º¿¡¼­
ÀÌÀ¯°¡ ±Ã±ÝÇÕ´Ï´Ù.

1. EAX¿¡´Ù°¡ __security_cookieÀÌ°É ³Ö´Â ÀÌÀ¯
2. ±×¸®°í XOR EAX, EBP¸¦ XORÇÏ´Â ÀÌÀ¯
3. MOV EBP-4, EAX  ¿Ö EBP-4¿¡´Ù°¡ EAX¸¦ ³Ö´Â ÀÌÀ¯
4. LEA EAX, EBP-14ÀÇ ÁÖ¼Ò¸¦ ³Ö´Â ÀÌÀ¯
5. EAX¸¦ ³Ö´Â ÀÌÀ¯

  Hit : 3563     Date : 2017/07/17 12:27



    
healer 00EA16A0 > 55 PUSH EBP ; IsPasswordOK()
00EA16A1 8BEC MOV EBP,ESP
00EA16A3 81EC DC000000 SUB ESP,0DC
00EA16A9 53 PUSH EBX
00EA16AA 56 PUSH ESI
00EA16AB 57 PUSH EDI
00EA16AC 8DBD 24FFFFFF LEA EDI,DWORD PTR SS:[EBP-DC]
00EA16B2 B9 37000000 MOV ECX,37
00EA16B7 B8 CCCCCCCC MOV EAX,CCCCCCCC
00EA16BC F3:AB REP STOS DWORD PTR ES:[EDI]
00EA16BE A1 0490EA00 MOV EAX,DWORD PTR DS:[__security_cookie]
00EA16C3 33C5 XOR EAX,EBP
00EA16C5 8945 FC MOV DWORD PTR SS:[EBP-4],EAX
00EA16C8 8D45 EC LEA EAX,DWORD PTR SS:[EBP-14]
00EA16CB 50 PUSH EAX

»çÁøÀÌ ¾È¿Ã¶ó°¡³×¿ä óÀ½À̶ó¼­...
2017/07/17  
pwnnnt bof ¹æÁö°°³×¿ä. 2017/07/18  
sTRAYdOG 1. EAX¿¡´Ù°¡ __security_cookieÀÌ°É ³Ö´Â ÀÌÀ¯
2¹ø XOR ¿¬»êÀ» À§Çؼ­.
2. ±×¸®°í XOR EAX, EBP¸¦ XORÇÏ´Â ÀÌÀ¯
¾Ë¼ö¾øÁÒ. ¿¬»ê°á°ú EAX¸¦ ³ªÁß¿¡ »ç¿ëÇÏ°ÚÁÒ.
3. MOV EBP-4, EAX ¿Ö EBP-4¿¡´Ù°¡ EAX¸¦ ³Ö´Â ÀÌÀ¯
[EBP-4]´Â Áö¿ªº¯¼öÁÒ. ¿©±â´Ù ÀúÀåÇϳªº¸ÁÒ. ³ªÁß¿¡ ÇÔ¼ö¸¦ ³ª°¡¸é ÀÌ°Ô ¹ÝȯµÉÁöµµ.
4. LEA EAX, EBP-14ÀÇ ÁÖ¼Ò¸¦ ³Ö´Â ÀÌÀ¯
[EBP-14]¿¡ ¸ð°¡ ÀÖ´ÂÁö ¼Ò½º¸¸À¸·Î ¾Ë ¼ö ¾ø¾î¿ä
5. EAX¸¦ ³Ö´Â ÀÌÀ¯
½ºÅÿ¡ ³Ö´Â°ÍÀε¥ ³ªÁß¿¡ ²¨³¾¶ó´Â °ÍÀÌÁÒ.

Á¦°¡º¸±â¿£ Äڵ常º¸¸é 3¹ø XoR¿¬»êÀÌ ÇÔ¼öÀÇ ÁÖ¸ñÀûÀ̶ó°í º¸ÀÔ´Ï´Ù.
2017/07/30  
97   angr¿¡¼­ ½ºÅà ÁÖ¼Ò ±¸Çϱâ[3]     turttle2s
05/24 1720
96   ¾Æ½ºÅ° ¹üÀ§ ¹Û ÆäÀ̷εå Àü¼Û ½Ã, 0xc2°¡ ºÙ´Â Çö»ó[7]     turttle2s
05/11 1655
95   angr Áú¹®[2]     turttle2s
04/24 1725
94   ¸®¹ö½Ì Çٽɿø¸®¸¦ °øºÎÇÏ´Ù°¡ ¸·Çû½À´Ï´Ù.     aaasss445
06/12 2089
93   quickbms ÀÇ ¿ø¸®°¡ ±Ã±ÝÇÕ´Ï´Ù.     sa0814
05/10 1875
92   ÄݽºÅÿ¡ ¾Æ¹«°Íµµ ¾øÀ» °æ¿ì¿¡´Â ¾î¶»°Ô ÇؾßÇϳª¿ä..[2]     mij9929
01/14 1669
91   ollydbg 64bit ½ÇÇà ºÒ°¡ ¿Ö ÀÌ·±°ÅÁÒ? ¤Ð[4]     4ru4ka
04/24 3878
90   º¯¼ö ¼±¾ð½Ã ½ºÅÿ¡¼­ÀÇ À§Ä¡[5]     turttle2s
11/13 2083
89   Äڵ忣Áø Basic 02¿¡¼­     healer
04/08 2135
88   win32 api ¹× Áø·Î..?[2]     user0
02/26 3430
87   ¸Þ¸ð¸® ÁÖ¼Ò º¯°æ µÇ´Â ¹®Á¦¿¡ °üÇØ Áú¹®ÇÕ´Ï´Ù.[2]     jjunici
12/17 3454
86   ida¿¡¼­ ºÐ¼®ÇÒ ¶§,,,[3]     vngkv123
11/30 2287
85   ¸®¹ö½Ì-µð½º¾î¼Àºí¸®-µð¹ö°Å¿¡ ¹®ÀÇÁ»..     leonardo6
10/13 2506
84   dumpcode Çì´õÆÄÀÏ ¸»Àä..[1]     ys200209
07/20 2427
  ¸®¹ö½Ì __security_cookie[3]     healer
07/17 3562
82   ´Ü¼ø ¸®¹ö½Ì °ü·Ã Áú¹®[8]     ewqqw
06/11 2930
81   elf ¹ÙÀ̳ʸ® ÆÐÄ¡ Áú¹®...[2]     vngkv123
06/07 3242
80   IDA hexray·Î º¸¾ÒÀ» ¶§...[2]     vngkv123
05/29 2767
79   µð½º¾î¼ÀºíµÈ ÄÚµåµé Áß¿¡¼­..[2]     vngkv123
05/14 2841
78   °ÔÀÓ º¸¾È (½ÎÀÎÄÚµå, X-Trap, °ÔÀÓ°¡µå) ºÐ¼® ¹ý·ü ±Ã±ÝÇÕ´Ï´Ù![4]     ¼È·Ï38
03/17 3989
1 [2][3][4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org