214, 1/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   31337ÇØÄ¿½º
   ftz level5 --> level6¿¡¼­¿ä

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=157 [º¹»ç]


level5.tmp´Â /tmp µð·ºÅ丮¿¡ À־ . ¸¸¾à¿¡ level5.tmp¸¦ level5 À¯Àú°¡ °°Àº ÆÄÀÏÀ» ¸ÕÀú ¸¸µé¸é ±×°ÍÀ» level6(/usr/bin/level5) À¯ÀúÀÇ ÇÁ·Î±×·¥À» ½ÇÇàÇÏ¸é ¾î¶»°Ô level5.tmp°¡ Áö¿öÁú¼ö ÀÖÁö¿ä. ±×°Ç sticky bit°¡ °É¸° µð·ºÅ丮 Ư¼º¿¡ ¸ÂÁö ¾ÊÁú ¾Ê³ª¿ä?? ¼Ò½º¿¡´Â remove() ÇÔ¼ö°¡ »ç¿ëµÈ´Ù°í Çϴµ¥. À̰͵µ ´Ù¸¥ »ç¿ëÀÚ ÆÄÀÏÀ» Áö¿ï¼ö´Â ¾øÁö ¾Ê³ª¿ä?? ³»¿ëÀÌ È¤½Ã ÀÌÇØ°¡ µÇ½Ã´Â Áö. ¹°·Ð ¼ÒÇÁÆ® ¸µÅ© ½Ãµµ ÇÏ¸é ´äÀº ³ª¿ÀÁö¸¸ ÀÌ»óÇÏ°Ô level5 ¼ÒÀ¯ÀÇ level5. tmp °¡ »ç¶óÁö´Â Áö ÀÌÇØ°¡ ¾ÈµÇ¾î¼­¿ä. ÀÌ°ÍÀÇ ¼ÒÀ¯°¡ level 6 ·Î º¯°æÀÌ µÇ³ª¿ä?? (/usr/bin/level5) ½ÇÇàÈÄ¿¡.. fd() and write() ÇÔ¼ö ¸¦ ÀÌÇØÇØ¾ß Çϳª¿ä??

°í¼ö´Ôµé ´äÁ».. °¨»çÇÕ´Ï´Ù.

  Hit : 3286     Date : 2013/08/10 01:31



    
Chris Ruiel ¿¡...´äº¯µå¸±²²¿ä

level5->6À¸·Î °¡´Â¹®Á¦°¡..level6ÀÇ setuid¸¦ °¡Áö°íÀÖ´Â ÇÁ·Î±×·¥ ÀÌÁö¿ä...
Áï..level5°¡ ½ÇÇàÀ» ÇÏ°Ô µÇ´õ¶óµµ.. ÇÁ·Î±×·¥ÀÌ ½ÇÇàÀÌ µÉ¶§¿¡´Â level6ÀÇ ±ÇÇÑÀ» °®°Ô µÈ´ä´Ï´Ù.
¸»¾¸ÇϽŴë·Î ½ºÆ¼Å°ºñÆ®°¡ Àû¿ëÀÌ µÆÀ»¶§ level6ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄѵµ level5ÀDZÇÇÑÀÌ À¯ÁöµÈ´Ù¸é..
¿À·ù°ÚÁö¸¸ setuidÀÇ Æ¯¼ºÀ¸·Î ÀÎÇؼ­ ¹®Á¦°¡ ¾ø´ä´Ï´Ù.
2013/10/05  
214   ÆÄÆøÀÇ Â÷´Ü ±âÁØÀº ¹«¾ùÀΰ¡¿ä ?[1]     $Zero
03/11 3489
213   hackthissite.org ÀÇ basic 2¹ø¹®Á¦..[3]     $Zero
03/15 3199
212   Session º¯¼ö Á¶ÀÛ°ú IP ´ëÁ¶º¸¾È ÀÎÁõ Åë°ú°¡ °¡´ÉÇÑ°¡¿ä ?[1]     $Zero
03/24 3379
211   APMSETUP7À» ¼³Ä¡ÇÏ·Á°íÇϴµ¥..     0429njy
07/22 2417
  ftz level5 --> level6¿¡¼­¿ä[1]     31337ÇØÄ¿½º
08/10 3285
209     [re] Æ÷Æ®½ºÄµÀÌ ºÒ¹ýÀ̾ú³×¿ä;;     4irjuno
07/31 3442
208   À¥ ÇØÅ·À» ¹è¿ì°í½Í½À´Ï´Ù.     a12341z
04/05 3186
207   ÀÌ·±°Íµµ À¥ÇØÅ·Àΰ¡¿ä?[3]     aa136677
08/05 3847
206   À¥ÇØÅ· ¹¹ºÎÅÍ....[3]     abnavv
11/04 3529
205   À¥ÇØÅ· ¹è¿ï·Á°í ÇÕ´Ï´Ù[2]     aktrg1234
11/09 3192
204   Webhacking.kr ¹®Á¦¸¦ Ç®´Ù°¡..     alstnsms67
08/02 2702
203   À¥ÇØÅ· °øºÎ Áú¹®ÀÌ¿ä~[2]     ansqudfyd
05/02 3504
202   paros¸¦ ±¸µ¿ÇÑ »óÅ¿¡¼­ ¾î¶² À¥»çÀÌÆ®¸¦ µé¾î°¥ ¶§     asdwho
03/24 3705
201   wpe°°Àº ÇÁ·Î±×·¥ÀÇ ¿ø¸®¸¦ ÀÌÇØÇÏ·Á¸é..[1]     attainer
11/01 4346
200   À¥ÇØÅ·½Ã[1]     AutoFlow
10/24 3657
199   ¾È³çÇϼ¼¿ä. ÀÌ °Ô½ÃÆÇ¿¡ ¸ÂÁö ¾Ê´Â Áú¹®°°Áö¸¸ Áú¹®À» Çϳª Çغ¸·Á°í ÇÕ´Ï´Ù..[1]     Áú¹®ÀÚ
06/21 3499
198   À¥½© »ç¿ë¹ýÁ»[3]     À¥ÇØÅ·
12/30 15057
197   LibrettoCMS 2.2.2 - Arbitrary File Upload ¾Æ½Ã´ÂºÐ °è½Å°¡¿ä?     Á¦·Î½Ã
06/16 3373
196   ³×Æ®¿öÅ© °ü·Ã Áú¹®ÀÌ¿¡¿ä...[1]     babisss
02/23 3647
195   ÇØÄ¿ ¸ðÁý.»çÀÌÆ®´ç 600¸¸¿ø Áö±Þ, Ÿ°Ù 24°÷, ÀºÇà ¹× ±â°ü ¾Æ´Ô.[4]     bestloan
01/06 4313
1 [2][3][4][5][6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org