·¹º§ ÇØÅ·

 2844, 3/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   kumi123
   http://blog.naver.com/kumik12
   ±×·³, Æäµµ¶ó ÀÌ»ó±Þ¿¡¼­´Â ( ; , | ) ¸¦ ÀÌ¿ëÇÑ ¿ìȸ°¡ ºÒ°¡´É ÇÑ°¡¿ä?

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3315 [º¹»ç]


suid°¡ °É·ÁÀÖ°í,

ÇÁ·Î±×·¥³»ºÎ¿¡¼­, systemÇÔ¼ö¿¡ ÀԷ¹®ÀÚ¸¦ ¹Þ¾Æ ½ÇÇàÇÏ´Â °æ¿ì

·¹µåÇÞ9 ÀÌÇÏ¿¡¼­´Â ±ÇȯÇ϶ô ¹®Á¦°¡ ¾øÀ¸¹Ç·Î »ó°ü¾øÁö¸¸,

Æäµµ¶ó ÀÌ»ó±Þ¿¡¼­´Â, systemÇÔ¼ö´Â ±ÇȯÇ϶ôÀÌ µÇ¹Ç·Î,

; , | detour¸¦ °á±¹ »ç¿ëÇÒ ¼ö ¾ø´Âµ¥..

¹º°¡ ¿ìȸ ¾ÆÀ̵ð¾î°¡ Á¸Àç Çϳª¿ä?

-------------

¿¹¸¦µé¾î,

int main()
{
char buf[20];
gets(buf);
system(buf);
}

./a
/bin/sh
id ( ´©¸¦½Ã, ±Çȯ»ó½ÂÇÒ ¾ÆÀ̵ð¾î)

  Hit : 2217     Date : 2014/02/03 03:49



    
cd80 Ȥ½Ã system(argv[1]); °°Àº°Å ¸»¾¸ÇϽô°Ÿé
/bin/sh ¿¡ -p ¿É¼Ç ³Ö¾îÁÖ½Ã¸é µË´Ï´Ù~
2014/02/04  
kumi123 À§¿¡ Ãß°¡ÇÑ ¹æ¹ýÀ¸·Î ÇÁ·Î±×·¥À» §´ÙÀ½, /bin/sh -p ¿É¼ÇÀ» ³ÖÀ¸´Ï.. euid º¯È­°¡ ¾ø½À´Ï´Ù. ¤Ð

system ÇÔ¼ö°¡ ³»ºÎ¿¡¼­ ÀÌ¹Ì ±ÇÈ­Ç϶ôÀ» ½ÃŲ´ÙÀ½, ÀÛµ¿Çϱ⠋š¹®¿¡ -p°¡ ¼Ò¿ë¾ø¾î º¸ÀÌ³×¿ä ¤Ð

ÀÌ·¸°Ô ÀÛµ¿Çؼ­ °°Àºµ¥¿ä.. ¤Ð
2014/02/04  
kumi123 execl ÇÔ¼ö·Î ÇÒ°æ¿ì¿¡´Â, ¹Ù·Î euid°¡ ÀâÈ÷³×¿ä ¤Ð¤Ð.

Àú »óÅ¿¡¼­ ¿ìȸ¹æ¹ýÀº ÀÌÁ¦ ¸·Èù°Ç°¡¿ä?
2014/02/04  
cd80 ¾î.. Ȥ½Ã ÇÁ·Î±×·¥»ý¼ºÀÌ °¡´ÉÇÑ È¯°æÀ̸é
main(){
setreuid(geteuid(), geteuid());
system("cp /bin/bash /tmp/bash");
system("chmod +s /tmp/bash");
}
ÇϽŴÙÀ½¿¡ Àú ÇÁ·Î±×·¥À» system()ÀÌ ½ÇÇàÇÏ°Ô ÇÏ°í
/tmp/bash -p ·Î ½ÇÇà½ÃÄѺ¸½Ã¸é µÉ°Í°°¾Æ¿ä
À̰͵µ ¾ÈµÇ³ª..
2014/02/04  
kumi123 ¾ÈµË´Ï´Ù..

systemÇÔ¼ö ½ÇÇà Àü ±ÇȯÇ϶ô -> setreuid ±Çȯ»ó½Â ( °á±¹ µ¿ÀÏ) -> »ý¼º ( »ç¿ëÀÚ id )

°á±¹ ºÒ°¡´ÉÀ̳׿ä.. systemÇÔ¼ö ÀÌÀü¿¡ setuid() ¸¦ Àû¿ë½ÃÅ°Áö ¸øÇÏ´Â ÀÌ»óÀº,

ÇÏÁö¸¸, ¸®¸ðÆ®¾îÅÃ(À¥ÇØÅ·) À̶ó¸é, °¡´ÉÇÒ °ÍÀ̶ó »ý°¢ÇÕ´Ï´Ù.
2014/02/05  
cd80 ¾î ±×·¸³×¿ä ¤»¤» 2014/02/05  
2804   FTZ Level11 Áú¹®[1]     $Zero
06/05 2795
2803   ftz level 20 Áú¹®ÀÌ¿¡¿ä ..[5]     zmmx019
03/27 2895
2802   ¾ÆÀÌÇǸ¦ ¾î‰F°Ô Á¤È®ÇÏ°Ô Ã£À»¼ö ÀÖÀ»°¡¿ä ?[1]     haohao123
03/03 2127
2801   ftz ¼­¹ö ½ºÅÃÁÖ¼Ò°ü·ÃÇؼ­ ¹®ÀÇ µå¸³´Ï´Ù.[1]     socks
03/02 1996
  ±×·³, Æäµµ¶ó ÀÌ»ó±Þ¿¡¼­´Â ( ; , | ) ¸¦ ÀÌ¿ëÇÑ ¿ìȸ°¡ ºÒ°¡´É ÇÑ°¡¿ä?[6]     kumi123
02/03 2216
2799   level1 µµÁß Áú¹® ÀÖ¾î¿ä![3]     rein1685
01/23 1991
2798   lob ÁÖ¼Ò Áú¹®!![1]     chtod77
12/24 2573
2797   À©µµ¿ì7 »ç¿ëÇÏ°íÀִµ¥ ftzÁ¢¼ÓÀÌ ¾ÈµÇ¿ä.[1]     akros
11/30 2776
2796   À©µµ¿ì 8¿¡¼­ putty¸¦ ´Ù¿î¹Þ¾Æ¼­ ½ÇÇàÇß´õ´Ï network error : connection timed out À̶ó°í ¶ß³×¿ä...     tlswjdtlr12
11/15 3558
2795   ¹®Á¦ Ç®ÀÌ·Î ¹è¿ì´Â ½Ã½ºÅÛ ÇØÅ· Å×Å©´Ð 1°­¿¡¼­.....     bestaman
11/07 2674
2794   ´Ôµé ¿ÞÂÊ ´Ù¿î·Îµå°¡ ¾ÈµÇ´Âµ¥¿ä Ȥ½Ã. Æäµµ¶ó the lord of BOF À̹ÌÁö ÆÄÀÏ ÀÖÀ¸¸é ¾÷Á» ºÎŹµå¸³´Ï´Ù. ¾Æ´Ï½Ã¸é ÀúÀÇ ¸ÞÀÏ·Î..[6]     31337ÇØÄ¿½º
09/23 4628
2793   The lord of BOF ´Ù ³¡³»°í ¸á ¾î¶»°Ô º¸³»¾ß Çϳª¿ä? °£´ÜÇÑ Ç®ÀÌ ¹ýµµ º¸³»¾ß Çϳª¿ä? ¾îµð´Ù°¡ ¾î¶»°Ô.. ±×¸®°í ¿ÞÂÊ ¸Þ´º¿¡ ´Ù¿î·Îµå°¡ Çϳªµµ      31337ÇØÄ¿½º
09/21 2617
2792   FTZ ·¹º§¾÷ÀÌ ¾ÈµË´Ï´Ù ¤Ð¤Ð     dowoon7280
09/03 2481
2791   LOB Goblin(level4)¹®Á¦ Áú¹®[7]     Spero
07/28 2040
2790   War game ·¹º§ Áú¹®ÀÌ¿ä...     choisol0729
07/26 2081
2789   level1 ¹®Á¦¿¡¼­¿ä~ find ¸í·É¾î Áú¹®~[1]     ½Ã¾ÆS2
07/17 2150
2788   LOB redhat nightmare ¹®Á¦     kumi123
07/09 1757
2787   level5     benkim
06/08 1993
2786   putty ±Ó¸»º¸³»´Â°Å ÀÌ·¸°ÔÇÏ¸é µÇ³ª¿ä?[1]     tmrlgkfk
06/08 2049
2785   ¿ö°ÔÀÓÀ» À§ÇØ ÇؾßÇÒ °øºÎ??[2]     ShipLight
05/31 3431
[1][2] 3 [4][5][6][7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org