97, 4/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   spe
   dll ¸®¹ö½Ì ÇÒ ¶§ ÁÖ¼Ò °è»ê¹ý Áú¹®ÀÌ¿ä¤Ð!

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Reversing&no=86 [º¹»ç]


¾È³çÇϼ¼¿ä~

¸®¹ö½º ¿£Áö´Ï¾î¸µ ¹ÙÀ̺í·Î °øºÎÇÏ´Ù°¡ ±Ã±ÝÇÑ Á¡ÀÌ »ý°å´Âµ¥ ¿©±â ¹Û¿¡ Áú¹®ÇÒ °÷ÀÌ ¾ø¾î¼­ ±ÛÀ» ½áº¾´Ï´Ù¤Ð!

dll ¸®¹ö½Ì ÇÒ ¶§ dllÀÌ ·ÎµåµÇ´Â Àå¼Ò°¡ °ãÄ¡°Ô µÇ¸é imagebase°¡ ´Þ¶óÁö±â ¶§¹®¿¡, ÁÖ¼Ò¸¦ °£´ÜÇÑ °ø½ÄÀ» ÀÌ¿ëÇØ¼­ ±¸ÇØ¾ß ÇÑ´Ù°í ÀÌÇØ¸¦ Çߴµ¥¿ä,

¿©±â¼­ ÁÖ¼Ò¸¦ ±¸ÇÒ ¶§...
base address + base of code¸¦ Ç϶ó´Â µ¥ ¹«½¼ ¸»ÀÎÁö ¸ð¸£°Ú¾î¿ä;;
ÀÎÅͳݿ¡ ã¾Æº¸¾Ò´õ´Ï imagebase + rva = va¶õ ¸»µµ ³ª¿À´Âµ¥
µÎ °ø½ÄÀÌ °°Àº °ø½ÄÀΰ¡¿ä? ±×¸®°í

°¢ °ø½ÄÀÇ base address, base of code, imagebase, rva, va´Â ¹«½¼ ¶æÀÎÁö ¾Æ´Âµ¥ Àú °ø½ÄÀÌ ÀǹÌÇÏ´Â °ÍÀÌ ¹«¾ùÀÎÁö ¸ð¸£°Ú¾î¿ä¤Ð¤Ð

µµ¿òºÎʵ右´Ï´Ù¤Ð¤Ð

  Hit : 4588     Date : 2014/12/26 01:16



    
kyj9206 base address´Â ÀÏÁ¾ÀÇ ±âÁØÁ¡À̶ó »ý°¢ÇÏ½Ã¸é µË´Ï´Ù. base of code´Â ±× ±âÁØÁ¡¿¡¼­ Äڵ尡 ¾ó¸¶¸¸Å­ ¶³¾îÁ® ÀÖ³Ä(offsetÀ̶ó°íµµ ÇÏÁÒ)¸¦ ÀǹÌÇÕ´Ï´Ù.
base of code = rva, base address = imagebase ÀÌ·¸°Ô µË´Ï´Ù. va´Â ÇÁ·Î±×·¥ÀÌ ½ÃÀÛ ÇÏ°í ³­ ÈÄ µ¿ÀÛ ÇÒ¶§ Äڵ尡 ¿Ã¶ó°¡ ÀÖ´Â ½ÇÁ¦ ÁÖ¼Ò¸¦ ¶æÇÕ´Ï´Ù.
2014/12/27  
cd80 dllÀ̵ç ÇÁ·Î±×·¥ ÀÚüµç ÇÁ·Î¼¼½º¿¡ ¿Ã¶ó°¥¶§ ÆÄÀÏÀÌ ÇѲ¨¹ø¿¡ ƯÁ¤ ±âÁØÁÖ¼ÒºÎÅÍ ¿Ã¶ó°¡´Âµ¥
ÆÄÀÏ »ó¿¡¼­ÀÇ ¿ÀÇÁ¼ÂÀÌ ¸»¾¸ÇϽŠbase of code, rva°í
ƯÁ¤ ±âÁØÁÖ¼Ò°¡ base address
±× ±âÁØÁÖ¼ÒºÎÅÍ ÆÄÀÏÀÌ ´Ù µé¾î°¡ÀÖÀ¸´Ï±î ±× ±âÁØÁÖ¼Ò + ÆÄÀϻ󿡼­ÀÇ ¿ÀÇÁ¼ÂÀÌ
½ÇÁ¦ ¸Þ¸ð¸®¿¡ µé¾î°£ ±× ¿ÀÇÁ¼ÂÀÌ µÇ°í ÀÌ°Ô va¿¡¿ä
2014/12/28  
spe ¾Ë·ÁÁּż­ °¨»çÇÕ´Ï´Ù~ °£´ÜÇÑ °Å¿´³×¿ä! 2015/01/06  
37   ¸®¹ö½Ì Ãʺ¸ÀÔ´Ï´Ù. IDA¿¡ ´ëÇÑ Áú¹®ÀÖ½À´Ï´Ù.[3]     shdac
10/29 4457
36   ¾È³çÇϼ¼¿ä. ¸®¹ö½Ì¿¡ °üÇÏ¿© Áú¹® ÀÖ½À´Ï´Ù.[2]     ksh1003
06/30 4470
35   ¸®¹ö½º ¿£Áö´Ï¾î¸µÀ¸·Î ¾î´ÀÁ¤µµ±îÁö º¹¿øÀÌ °¡´ÉÇѰ¡¿ä?[3]     ÀüÀÚ°øÇеµ
07/09 4493
34   ¸Þ¸ð¸® ÁÖ¼Ò º¯°æ µÇ´Â ¹®Á¦¿¡ °üÇØ Áú¹®ÇÕ´Ï´Ù.[2]     jjunici
12/17 4522
33   win32 api ¹× Áø·Î..?[2]     user0
02/26 4556
32   Äڵ忣Áø RCE 10¹ø¹®Á¦ Áú¹®ÀÔ´Ï´Ù.     W.H.
01/31 4580
  dll ¸®¹ö½Ì ÇÒ ¶§ ÁÖ¼Ò °è»ê¹ý Áú¹®ÀÌ¿ä¤Ð![3]     spe
12/26 4587
30   ¸®¹ö½Ì __security_cookie[3]     healer
07/17 4589
29   ¸®¹ö½º ¿£Áö´Ï¾î¸µÀÌ ¹¹¿¡¿ä?[3]     qkreoghks00
01/23 4609
28   ¸®¹ö½Ì ÀÔ¹®ÇÏ°í ½Í¾î¼­ Áú¹®µå¸³´Ï´Ù.[2]     shdac
09/27 4624
27   ¾ðÆÐÅ· °ü·Ã Áú¹®ÀÔ´Ï´Ù2     spe
11/09 4631
26   °ÔÀÓ Æ®·¹ÀÌ³Ê °°Àº°Ç ¸®¹ö½Ì ÇØ¼­ ¸¸µç°ÍÀΰ¡¿© ?[1]     nouna12
05/23 4685
25   ¸®¹ö½Ì ÇÏ·Á¸é À©µµ¿ì ÇÁ·Î±×·¡¹Öµµ ¹è¿ö¾ß Çϳª¿ä?[2]     cji2
05/20 4774
24   ¸®¹ö½Ì ¿£Áö´Ï¾î¸µ °øºÎ??[3]     GaOnNuRI
04/30 4808
23   ¸®¹ö½Ì, Å©·¢¹Ì ±îºÃ´õ´Ï¡¦ Ãæ°Ý[1]     creeper
12/01 4811
22   »çÀÌÆ®¿¡ Á¢¼ÓÇØ¼­ °ü¸®ÀÚ °èÁ¤ ¾ò±â[2]     ±Ã±Ýµ¸³×
01/24 4812
21   entry point alert ¿¡·¯Á» ¾Ë·ÁÁÖ¼¼¿ä..     psy2815
12/28 4873
20   ¸®¹ö½º¿£Áö´Ï¾î¸µ ¼±Çà Áú¹®ÀÌ¿ä[1]     Ãʺ¸
01/18 4877
19   ÆÄÀÏÀ» ºÐ¼®ÇÏ°í ½Í¾î¿ä[6]     tmchojo
11/22 4878
18   ¸®¹ö½Ì¿¡ Á» ¹°¾îº¾´Ï´Ù[1]     ±×ÀúÁú¹®
01/19 4892
[1][2][3] 4 [5]

Copyright 1999-2026 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org