97, 1/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   angr¿¡¼­ ½ºÅà ÁÖ¼Ò ±¸Çϱâ

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Reversing&no=129 [º¹»ç]


angr¿¡¼­ ½ºÅÃÀ¸·Î ¸®ÅÏÇÏ´Â ½ºÅ©¸³Æ®¸¦ ¸¸µé·Á°íÇÕ´Ï´Ù.
(aslrÀº ²¨Á®ÀÖ½À´Ï´Ù.)
±×·±µ¥ ±âº»ÀûÀ¸·Î angr¿¡¼­ sp¶û gdb·Î È®ÀÎÇßÀ» ¶§ sp¶û Â÷À̰¡ ³³´Ï´Ù.

[ === angr ÄÚµå === ]
# base.py
import angr, claripy
import code
import sys
from angr import sim_options as so

def main():
    proj = angr.Project("./t2",load_options={"auto_load_libs":False})
    extras = {so.REVERSE_MEMORY_NAME_MAP, so.UNICORN_TRACK_STACK_POINTERS}
    main_addr = proj.loader.find_symbol("main").rebased_addr
    st = proj.factory.call_state(main_addr, add_options=extras)
    print(st.regs.pc)
    print(st.regs.sp)
    #sm = proj.factory.simulation_manager(st)

#    code.interact(local=locals())

if __name__ == "__main__":
    main()

[ === angr°á°ú === ]
$python base.py
<BV32 0x8049162>
<BV32 0x7ffefffc>


[ == gdb == ]
gdb-peda$ b *main
Breakpoint 1 at 0x8049162
gdb-peda$ r
gdb-peda$ p/x $eip
$2 = 0x8049162
gdb-peda$ p/x $esp
$3 = 0xffffd51c
gdb-peda$



angr¿¡¼­´Â 0x7f·Î ½ÃÀÛÇÏÁö¸¸, gdb¿¡¼­ È®ÀÎÇØº¸¸é 0xff·Î ½ÃÀÛÇÕ´Ï´Ù.
angr¿¡¼­´Â ¹ÙÀ̳ʸ®¸¦ cle°¡ µû·Î ·ÎµåÇϱ⠶§¹®¿¡ ½ÇÁ¦ ½ºÅà ÁÖ¼Ò¶û ´Ù¸¦ °ÍÀ̶ó°í ¿¹»óÀº ÇÏÁö¸¸, ¹®Á¦´Â À̴̰ϴÙ.
angr¿¡¼­ Ãë¾àÇÑ »óŸ¦ ã°í ½ºÅÃÀ¸·Î ¸®ÅÏÇÏ´Â ÀͽºÇ÷ÎÀÕÀ» »ý¼ºÇÏ·Á¸é ÁÖ¼Ò¸¦ ¾Ë¾Æ¾ßÇϴµ¥, angr¸¸À¸·Î´Â ºÒ°¡´ÉÇѰǰ¡¿ä?

  Hit : 3006     Date : 2021/05/24 12:35



    
turttle2s ½ºÅÃÀº º¯µ¿ÀÌ Ä¿¼­ angr¿¡¼­´Â ´Ù·çÁö ¾Ê´Â´Ù³×¿ä 2021/05/26  
±ºÀÎ ÇØ°á¿Ï·á 2021/05/31  
somass ÅÃÀº º¯µ¿ÀÌ Ä¿¼­ angr¿¡¼­´Â ´Ù·çÁö ¾Ê´Â´Ù³×¿ä 2022/09/16  
97   ÀÇ·ÚÁ» ºÎʵ叱·Á±¸ ÇÕ´Ï´Ù.     vbvb92
05/14 3521
96   À̰Š¿ÖÀִ°Å¡?[2]     creeper
11/21 3499
95   and esp, 0fffffff8[3]     choboKing
01/21 3602
94   angr Áú¹®[2]     turttle2s
04/24 2858
  angr¿¡¼­ ½ºÅà ÁÖ¼Ò ±¸Çϱâ[3]     turttle2s
05/24 3005
92   ÀÚ±â¾ÐÃà½ÇÇàÈ­ÀÏ?? IDA³ª ¿Ã¸®µð¹ö±×·Î ±î¸é ¿£Æ®¸®Æ÷ÀÎÆ®°¡ ¾ø´Ù°í³ª¿É´Ï´Ù[4]     kywoo81
09/16 3888
91   Ã¥ ȤÀº ¹®¼­ Ãßõ Á» ÇØÁÖ¼¼¿ä~     likewinds
01/11 3404
90   Á¦°¡ ¸®¹ö½Ì °øºÎÁ» ÇÏ·Á°í Çϴµ¥ À̰ŠºÐ¼®Á» ÇØÁֽǼö ÀÖ³ª¿ä     majesty7
11/11 3652
89   À©µµ¿ì ¸®¹ö½Ì°ú ¾Èµå·ÎÀÌµå ¸®¹ö½Ì..[1]     hallohackers
01/26 3958
88   ÇÁ·Î±×·¥ ƯÁ¤ ¿µ¿ª ½ÇÇà °¨Áö.[2]     Einsteins
08/24 4131
87   Ǫ¸¥ÇϴôԲ² °³ÀÎÁú¹®....[2]     creamitation
06/20 3802
86   dll ¸®¹ö½Ì ÇÒ ¶§ ÁÖ¼Ò °è»ê¹ý Áú¹®ÀÌ¿ä¤Ð![3]     spe
12/26 4626
85   dll ¸®¹ö½ÌÁú¹®.     stares
12/21 6821
84   dumpcode Çì´õÆÄÀÏ ¸»Àä..[1]     ys200209
07/20 3345
83   DWORD PTR SS ¿Í DWORD PTR DS[1]     skyclad1975
01/24 6651
82   elf ¹ÙÀ̳ʸ® ÆÐÄ¡ Áú¹®...[2]     vngkv123
06/07 4233
81   entry point alert ¿¡·¯Á» ¾Ë·ÁÁÖ¼¼¿ä..     psy2815
12/28 4911
80   gdb ¿¡¼­ display·Î º¯¼ö¸¦ º¸´Â °Í¿¡ ´ëÇÑ Áú¹®[1]     skyclad1975
12/11 3679
79   IDA 64ºñÆ® ¿î¿µÃ¼Á¦¿¡¼­ µ¹¸®´Â ¹æ¹ý ¾ø³ª¿ä ??[3]     7evenLeaf
04/20 5071
78   IDA hexray·Î º¸¾ÒÀ» ¶§...[2]     vngkv123
05/29 3683
1 [2][3][4][5]

Copyright 1999-2026 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org