214, 5/11 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   31337ÇØÄ¿½º
   ftz level5 --> level6¿¡¼­¿ä

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_Web&no=157 [º¹»ç]


level5.tmp´Â /tmp µð·ºÅ丮¿¡ À־ . ¸¸¾à¿¡ level5.tmp¸¦ level5 À¯Àú°¡ °°Àº ÆÄÀÏÀ» ¸ÕÀú ¸¸µé¸é ±×°ÍÀ» level6(/usr/bin/level5) À¯ÀúÀÇ ÇÁ·Î±×·¥À» ½ÇÇàÇÏ¸é ¾î¶»°Ô level5.tmp°¡ Áö¿öÁú¼ö ÀÖÁö¿ä. ±×°Ç sticky bit°¡ °É¸° µð·ºÅ丮 Ư¼º¿¡ ¸ÂÁö ¾ÊÁú ¾Ê³ª¿ä?? ¼Ò½º¿¡´Â remove() ÇÔ¼ö°¡ »ç¿ëµÈ´Ù°í Çϴµ¥. À̰͵µ ´Ù¸¥ »ç¿ëÀÚ ÆÄÀÏÀ» Áö¿ï¼ö´Â ¾øÁö ¾Ê³ª¿ä?? ³»¿ëÀÌ È¤½Ã ÀÌÇØ°¡ µÇ½Ã´Â Áö. ¹°·Ð ¼ÒÇÁÆ® ¸µÅ© ½Ãµµ ÇÏ¸é ´äÀº ³ª¿ÀÁö¸¸ ÀÌ»óÇÏ°Ô level5 ¼ÒÀ¯ÀÇ level5. tmp °¡ »ç¶óÁö´Â Áö ÀÌÇØ°¡ ¾ÈµÇ¾î¼­¿ä. ÀÌ°ÍÀÇ ¼ÒÀ¯°¡ level 6 ·Î º¯°æÀÌ µÇ³ª¿ä?? (/usr/bin/level5) ½ÇÇàÈÄ¿¡.. fd() and write() ÇÔ¼ö ¸¦ ÀÌÇØÇØ¾ß Çϳª¿ä??

°í¼ö´Ôµé ´äÁ».. °¨»çÇÕ´Ï´Ù.

  Hit : 3250     Date : 2013/08/10 01:31



    
Chris Ruiel ¿¡...´äº¯µå¸±²²¿ä

level5->6À¸·Î °¡´Â¹®Á¦°¡..level6ÀÇ setuid¸¦ °¡Áö°íÀÖ´Â ÇÁ·Î±×·¥ ÀÌÁö¿ä...
Áï..level5°¡ ½ÇÇàÀ» ÇÏ°Ô µÇ´õ¶óµµ.. ÇÁ·Î±×·¥ÀÌ ½ÇÇàÀÌ µÉ¶§¿¡´Â level6ÀÇ ±ÇÇÑÀ» °®°Ô µÈ´ä´Ï´Ù.
¸»¾¸ÇϽŴë·Î ½ºÆ¼Å°ºñÆ®°¡ Àû¿ëÀÌ µÆÀ»¶§ level6ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄѵµ level5ÀDZÇÇÑÀÌ À¯ÁöµÈ´Ù¸é..
¿À·ù°ÚÁö¸¸ setuidÀÇ Æ¯¼ºÀ¸·Î ÀÎÇؼ­ ¹®Á¦°¡ ¾ø´ä´Ï´Ù.
2013/10/05  
134   ¾ÆÀÌÇÇ ¿ìȸ Á¢¼Ó Áú¹®ÀÔ´Ï´Ù[1]     crankdat
02/08 4132
133   passward cracking Áú¹®ÀÖ½À´Ï´Ù[2]     °æ³²123
01/27 3357
132   ÇØÄ¿ ¸ðÁý.»çÀÌÆ®´ç 600¸¸¿ø Áö±Þ, Ÿ°Ù 24°÷, ÀºÇà ¹× ±â°ü ¾Æ´Ô.[4]     bestloan
01/06 4283
131   ¸ÅÁ÷ÄõÅÍ ¿ìȸ ¹æ¹ý¿¡ ´ëÇØ Áú¹®µå¸³´Ï´Ù.[1]     tpdbs953
10/17 4843
130   À¥ÇØÅ· ¹× ¹æ¾î °øºÎ ¾î¶²°Å ºÎÅÍ ÇÏ¿©¾ß Çϳª¿ä?[1]     jobs7
10/17 3738
129   ÇØÄ¿ °í¼öºÐµé ¼³¸íÁ» ºÎŹµå¸³´Ï´Ù.¤Ð¤Ð wpe-pro ÅäÅ©¿Â[2]     tjrqo12
10/13 7832
128   vbscript·Î Ŭ¶óÀ̾ðÆ® ½Å·ÚÇÒ ¼ö ÀÖ´Â »çÀÌÆ® µî·Ï ÇÏ´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù     lekel09
10/10 4726
127   À¥ ÇØÅ·¿¡ °ü½ÉÀÖÀ¸½ÅºÐ...[2]     hyunmin8
10/02 4107
126   file upload Ãë¾àÁ¡ Áú¹®ÀÔ´Ï´Ù.[5]     hyunmin8
09/25 4166
125   sql injection Áú¹®ÀÖ½À´Ï´Ù ¿ìȸ°ü·Ã[1]     Qwed_na
09/04 3443
124   À¥ ÇØÅ· ȨÆäÀÌÁö[3]     xkdlrjxkdltm
08/28 3767
123   Odysseus ¶ó´Â ÇÁ·Î±×·¥¿¡ ´ëÇØ ¿©ÂÞ¾î º¾´Ï´Ù.     ygh159
08/18 3594
  ftz level5 --> level6¿¡¼­¿ä[1]     31337ÇØÄ¿½º
08/10 3249
121   ÀÌ·±°Íµµ À¥ÇØÅ·Àΰ¡¿ä?[3]     aa136677
08/05 3805
120   ¾È³çÇϼ¼¿ä À̹ø¿¡ ¾Èµå·ÎÀ̵å sql¼­¹ö¸¦ ±¸ÃàÇÏ°Ô µÇ¾ú´Âµ¥¿ä..[2]     ±î¹³´Ù¸£³¢
07/18 4318
119   À¥¼­¹ö ÇØÅ·¹× º¸¾È¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[2]     laysiankim
07/15 3246
118   Æķνº ±ò¾Æ¼­ ½ÇÇà½ÃÄ״µ¥ ¿ÖÀÌ·¯ÁÒ?(»çÁøêó)[1]     ygh159
07/13 4276
117     Æķνº     zen0c1de
07/18 3210
116   SQL Injection °ø°Ý±â¹ý Áú¹®µå¸³´Ï´Ù.[3]     kmc8724
07/03 4704
115   ¿î¿µÁßÀÎ À¥»çÀÌÆ®ÀÇ DBÁ¤º¸ ÇØÅ·[2]     cameo305
07/01 8709
[1][2][3][4] 5 [6][7][8][9][10]..[11]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org