·¹º§ ÇØÅ·

 2844, 3/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   zmmx019
   ftz level 20 Áú¹®ÀÌ¿¡¿ä ..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3319 [º¹»ç]


Æ÷¸Ë½ºÆ®¸µ¹ö±× °ø°ÝÀ» °øºÎÇÏ´Â ÇлýÀä ..

(perl -e 'print "aaaa\x98\x95\x04\x08aaaa\x9a\x95\x04\x08%8x%8x%8x%65045c%n%49602c%n"';cat) | ./attackme
¿©±â¿¡¼­ (perl -e 'print " ~ "' ; cat) | ½ÇÇàÆÄÀÏ
À̺κÐÀÌ ¿Ö ¾²´Â°ÇÁö ÀÌ°É ¾²¸é ¾î¶»°Ô µÇ´ÂÁö Àß ¸ð¸£°Ú½À´Ï´Ù ..
»ó¼¼È÷ ¾Ë·ÁÁֽǺРÀÖ³ª¿ä ¤Ð

  Hit : 2895     Date : 2014/03/27 02:18



    
letmeln °£´ÜÈ÷´Â attackme ÇÁ·Î±×·¥¿¡ ÀÔ·ÂÀ» Àü´ÞÇÏ·Á°í »ç¿ëµÈ´Ù°í ÇÒ ¼ö ÀÖÀ» °Í °°¾Æ¿ä

attakme ¼Ò½ºÄڵ忡 ¾î¶² ÇÔ¼ö°¡ »ç¿ë‰ç´ÂÁö ¸ð¸£°ÚÁö¸¸ strcpy(buf, argv[1]) ó·³ ÇÁ·Î±×·¥ ÀÎÀÚ¸¦ ¹öÆÛ¿¡ ¹Þ´Â°Ô ¾Æ´Ï°í ¹öÆÛ¿¡ ½ºÆ®¸²À» Àо º¹»çÇÏ´Â Ãë¾à ÇÔ¼ö°¡ »ç¿ë‰çÀ» °Çµ¥¿ä

# (echo "1234";cat) | binary

Á¦°¡ óÀ½ (echo "";cat)|binary ¿ä·± ¸í·ÉÀ» ºÃÀ» ¶§´Â À§ °°Àº ¿¹¿¡¼­ echo ÇÁ·Î±×·¥ÀÇ "1234" Ãâ·ÂÀ» cat ÇÁ·Î±×·¥ÀÌ binary stdin ½ºÆ®¸²¿¡ ¿¬°áÇØÁشٰí ÀÌÇØÇÏ°í ´õ ¾È¾Ë¾ÆºÃ´ø °Í °°¾Æ¿ä.
´õ »ó¼¼ÇÏ°í Á¤È®ÇÏ°Ô´Â °è¼Ó °øºÎÇÏ½Ã¸é ¾îµò°¡¿¡¼­ ¾Ë ¼ö ÀÖ°Ô µÇ°ÚÁÒ¤¾¤¾
2014/03/27  
letmeln À§Å°Çǵð¾Æ Use case¿¡ cat ¸í·ÉÀÌ "As cat simply catenates streams of bytes, it can be also used to concatenate binary files, where it will just concatenate sequence of bytes." ¿ä·¸°Ô ¼³¸íµÇ³×¿ä 2014/03/27  
zmmx019 Á¤¸» °¨»çµå¸³´Ï´Ù ¤Ì¤Ì 2014/03/27  
cd80 ÆÄÀÌÇÁ´Â ¿ÞÂÊÇÁ·Î±×·¥ÀÇ Ãâ·ÂÀ» ¿À¸¥ÂÊÇÁ·Î±×·¥ÀÇ ÀÔ·ÂÀ¸·Î º¸³»ÁÖ´Â ¿ªÇÒÀ» ÇÕ´Ï´Ù
±×·¡¼­ perlÀÌ Ãâ·ÂÇѰ͵éÀÌ ¿À¸¥ÂÊ ÇÁ·Î±×·¥ÀÇ ÀÔ·ÂÀ¸·Î ³Ñ¾î°£µÚ¿¡
¿À¸¥ÂÊ¿¡¼± ½©À» ½ÇÇàÇϴµ¥ ¿ÞÂÊ¿¡¼­ ´õÀÌ»ó º¸³»ÁÖ´Â ¹®ÀÚ°¡ ¾øÀ¸¸é EOF¸¦ ¸¸³ª ½©ÀÌ ¹Ù·Î Á¾·áµÇ¹ö¸³´Ï´Ù
±×·¡¼­ °è¼Ó ÀÎDzÀ» º¸³»ÁÙ¼ö ÀÖµµ·Ï catÀ» ºÙ¿©Áִ°ÍÀÔ´Ï´Ù
catÀº ÀԷ°ªÀ» ±×´ë·Î Ãâ·ÂÇÕ´Ï´Ù
2014/03/27  
letmeln ¾Æ¸Â´Ù ¡è ÀÌ°Ô ¸Â´Â ´äº¯ÀÔ´Ï´Ù. ½©¿¡¼­ ÀԷ¾øÀ¸¸é Á×´Â ÀÌÀ¯·Î cat ¾²´Â°Å¿¡¿ä ¤»¤» ±¦È÷ ³ª´ñ³×¤»¤» 2014/03/28  
2804   FTZ Level11 Áú¹®[1]     $Zero
06/05 2794
  ftz level 20 Áú¹®ÀÌ¿¡¿ä ..[5]     zmmx019
03/27 2894
2802   ¾ÆÀÌÇǸ¦ ¾î‰F°Ô Á¤È®ÇÏ°Ô Ã£À»¼ö ÀÖÀ»°¡¿ä ?[1]     haohao123
03/03 2126
2801   ftz ¼­¹ö ½ºÅÃÁÖ¼Ò°ü·ÃÇؼ­ ¹®ÀÇ µå¸³´Ï´Ù.[1]     socks
03/02 1995
2800   ±×·³, Æäµµ¶ó ÀÌ»ó±Þ¿¡¼­´Â ( ; , | ) ¸¦ ÀÌ¿ëÇÑ ¿ìȸ°¡ ºÒ°¡´É ÇÑ°¡¿ä?[6]     kumi123
02/03 2216
2799   level1 µµÁß Áú¹® ÀÖ¾î¿ä![3]     rein1685
01/23 1990
2798   lob ÁÖ¼Ò Áú¹®!![1]     chtod77
12/24 2573
2797   À©µµ¿ì7 »ç¿ëÇÏ°íÀִµ¥ ftzÁ¢¼ÓÀÌ ¾ÈµÇ¿ä.[1]     akros
11/30 2775
2796   À©µµ¿ì 8¿¡¼­ putty¸¦ ´Ù¿î¹Þ¾Æ¼­ ½ÇÇàÇß´õ´Ï network error : connection timed out À̶ó°í ¶ß³×¿ä...     tlswjdtlr12
11/15 3558
2795   ¹®Á¦ Ç®ÀÌ·Î ¹è¿ì´Â ½Ã½ºÅÛ ÇØÅ· Å×Å©´Ð 1°­¿¡¼­.....     bestaman
11/07 2674
2794   ´Ôµé ¿ÞÂÊ ´Ù¿î·Îµå°¡ ¾ÈµÇ´Âµ¥¿ä Ȥ½Ã. Æäµµ¶ó the lord of BOF À̹ÌÁö ÆÄÀÏ ÀÖÀ¸¸é ¾÷Á» ºÎŹµå¸³´Ï´Ù. ¾Æ´Ï½Ã¸é ÀúÀÇ ¸ÞÀÏ·Î..[6]     31337ÇØÄ¿½º
09/23 4627
2793   The lord of BOF ´Ù ³¡³»°í ¸á ¾î¶»°Ô º¸³»¾ß Çϳª¿ä? °£´ÜÇÑ Ç®ÀÌ ¹ýµµ º¸³»¾ß Çϳª¿ä? ¾îµð´Ù°¡ ¾î¶»°Ô.. ±×¸®°í ¿ÞÂÊ ¸Þ´º¿¡ ´Ù¿î·Îµå°¡ Çϳªµµ      31337ÇØÄ¿½º
09/21 2616
2792   FTZ ·¹º§¾÷ÀÌ ¾ÈµË´Ï´Ù ¤Ð¤Ð     dowoon7280
09/03 2480
2791   LOB Goblin(level4)¹®Á¦ Áú¹®[7]     Spero
07/28 2040
2790   War game ·¹º§ Áú¹®ÀÌ¿ä...     choisol0729
07/26 2081
2789   level1 ¹®Á¦¿¡¼­¿ä~ find ¸í·É¾î Áú¹®~[1]     ½Ã¾ÆS2
07/17 2148
2788   LOB redhat nightmare ¹®Á¦     kumi123
07/09 1757
2787   level5     benkim
06/08 1992
2786   putty ±Ó¸»º¸³»´Â°Å ÀÌ·¸°ÔÇÏ¸é µÇ³ª¿ä?[1]     tmrlgkfk
06/08 2049
2785   ¿ö°ÔÀÓÀ» À§ÇØ ÇؾßÇÒ °øºÎ??[2]     ShipLight
05/31 3430
[1][2] 3 [4][5][6][7][8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org