¸®´ª½º

 3923, 195/197 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ewqqw
   setuid¸¦ ÀÌ¿ëÇÑ ±ÇÇÑ »ó½Â

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_linux&no=4453 [º¹»ç]


./rc ¸¦ ½ÇÇà½ÃÅ°¸é¼­ ÀÌ ÇÁ·Î±×·¥ÀÇ fget ÇÔ¼ö¸¦ ¹ßµ¿½Ãų ¼ö ÀÖ´Â ¹æ¹ýÀÌ ¾ø³ª¿ä?

./rc ¸¸ ½ÇÇà½ÃÅ°¸é ±×³É /tmp/RC¸¸ »ç¶óÁö°í ³¡³³´Ï´Ù¸¸...

#include <stdio.h>
#include <stdlib.h>

int main() {
        FILE *fp,*fo;
        char key[40];
        
        
        system("rm /tmp/RC");

        fo=fopen("/home/rc/flag","r");
        fp=fopen("/tmp/RC","w");
        
        if(!fo)
                printf("failed to open flag ask to admin\n");
        if(!fp)
                printf("failed to open RC file ask to admin\n");

        fgets(key,40,fo);
        fprintf(fp,"%s\n",key);

        fclose(fp);
        fclose(fo);
        
        system("rm /tmp/RC");

        return 0;
}

  Hit : 2368     Date : 2017/03/29 02:14



    
ÇØÄð·¯ fgetsÀÇ ¼¼¹ø°ÀÎÀÚ°¡ fpÀε¥ fp¿¡ stdinÀÌ ¾Æ´Ï¶ó fopen("flag")°¡ µé¾î°¬ÁÒ
Ç÷¡±×ÆÄÀÏÀ» ¸¸µé°í Å°¸¦ ¾²°í Áö¿ì±â¸¦ ¹Ýº¹Çϴ°̴ϴÙ
Ç÷¡±×°¡ /home/rc/flag¿¡ ¿øº»ÀÌ ÀÖ°í ÀÌ°É °è¼Ó /tmp/RC¿¡ ¾²°í »èÁ¦ÇÏ°í ¾²°í »èÁ¦ÇÏ°í Çϴ°ÅÁÒ
ÀüÇüÀûÀÎ ·¹À̽ºÄÁµð¼Ç ¹®Á¦Àε¥
while [ 1 ] ; do ./rc; done À» ÇسõÀ¸½Ã°í
Çϳª¿¡¼­´Â
while [ 1 ] ; do cat /tmp/RC; done À» ÇسõÀ¸½Ã¸é µÎ¹ø° Å͹̳ο¡¼­ Ç÷¡±×°¡ ³ª¿É´Ï´Ù
2017/03/29  
ewqqw µÎ ¸í·É¹®ÀÇ Â÷À̸¦ ÆÄ°íµé¾î¼­ setuid¸¦ ¾ò´Â °ÍÀ̱º¿ä.... °¨»çÇÕ´Ï´Ù 2017/03/29  
43   Æäµµ¶ó25 system-confi ¸í·É¾î     tkdansg
01/13 2896
42   ¿ìºÐÅõ ftz µµ¿ò ºÎŹµå¸³´Ï´Ù.[1]     javatutorials
01/19 2650
41     [re] Mac OS X F.T.Z °ü·Ã     willwayy
02/15 1666
40   Mac OS X F.T.Z °ü·Ã[2]     willwayy
02/15 3014
39   ¸®´ª½ºÀÇ ±âÃÊÁ»[1]     ½ºÄ«ÀÌ·¹ÀÎ
02/22 2359
38   ¿ìºÐÅõ¶û Æäµµ¶óÁß¿¡ ÇØÅ·Çϴµ¥ ÁÁÀº°Í°°³ª¿ä?[5]     jsryu1031
03/01 3701
37   ¸®´ª½º ¾î´ÀÁ¤µµ ¹è¿ü´Âµ¥, ÀÌÁ¦ À©µµ¿ì·Î ÇØÅ·¹è¿öµÇ¿ä?[4]     jsryu1031
03/04 2852
36   SETUID¸¦ ÀÌ¿ëÇÑ ±ÇÇÑ ¾ò±â ¼Ò½º ºÐ¼® ºÎŹ µå¸³´Ï´Ù[3]     ewqqw
03/07 1899
35   PYTHONÀ» ÀÌ¿ëÇÑ È¯°æº¯¼ö¿¡ °ª³Ö±â[2]     ewqqw
03/09 2303
34     [re] PYTHONÀ» ÀÌ¿ëÇÑ È¯°æº¯¼ö¿¡ °ª³Ö±â     ewqqw
03/09 1558
33   ¼Ò½º ºÐ¼® ºÎŹµå¸³´Ï´Ù.[3]     ewqqw
03/10 2676
32   setuid ¸¦ ÀÌ¿ëÇÑ ±ÇÇѾò±â ¼Ò½º[1]     ewqqw
03/11 2920
31   ¸®´ª½º ½© ¸í·É°ü·Ã...[2]     vngkv123
03/21 2819
30   ÆÄÀ̽㠼³Ä¡ °ü·Ã ¹®Á¦°¡ ¹ß»ýÇÏ¿© Áú¹® ¿Ã·È½À´Ï´Ù..[1]     dndud1346
03/28 2303
  setuid¸¦ ÀÌ¿ëÇÑ ±ÇÇÑ »ó½Â[2]     ewqqw
03/29 2367
28   Brute force ¸¦ ÀÌ¿ëÇÑ °ø°Ý[2]     ewqqw
03/30 3144
27   ¸®´ª½º ŸÀӾƿô ¹®Á¦[1]     hktaehyung
04/02 2500
26   µ¥½ºÅ©Å¾¿¡ ¿ìºÐÅõ¸¦ ±î´Âµ¥...[3]     vngkv123
04/03 2388
25   bash 418 ¹öÀü ¼öÁ¤ÇÏ´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù[2]     seongkeunkim
05/30 3868
24   Å͹̳ο¡¼­ ¿ÍÀÌÆÄÀÌ ¿¬°á dhclient°¡ ¾ÈµÅ¿ä     dnlelstem96
06/17 2963
[1]..[191][192][193][194] 195 [196][197]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org