¸®´ª½º

 3923, 2/197 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ewqqw
   setuid¸¦ ÀÌ¿ëÇÑ ±ÇÇÑ »ó½Â

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_linux&no=4453 [º¹»ç]


./rc ¸¦ ½ÇÇà½ÃÅ°¸é¼­ ÀÌ ÇÁ·Î±×·¥ÀÇ fget ÇÔ¼ö¸¦ ¹ßµ¿½Ãų ¼ö ÀÖ´Â ¹æ¹ýÀÌ ¾ø³ª¿ä?

./rc ¸¸ ½ÇÇà½ÃÅ°¸é ±×³É /tmp/RC¸¸ »ç¶óÁö°í ³¡³³´Ï´Ù¸¸...

#include <stdio.h>
#include <stdlib.h>

int main() {
        FILE *fp,*fo;
        char key[40];
        
        
        system("rm /tmp/RC");

        fo=fopen("/home/rc/flag","r");
        fp=fopen("/tmp/RC","w");
        
        if(!fo)
                printf("failed to open flag ask to admin\n");
        if(!fp)
                printf("failed to open RC file ask to admin\n");

        fgets(key,40,fo);
        fprintf(fp,"%s\n",key);

        fclose(fp);
        fclose(fo);
        
        system("rm /tmp/RC");

        return 0;
}

  Hit : 2334     Date : 2017/03/29 02:14



    
ÇØÄð·¯ fgetsÀÇ ¼¼¹ø°ÀÎÀÚ°¡ fpÀε¥ fp¿¡ stdinÀÌ ¾Æ´Ï¶ó fopen("flag")°¡ µé¾î°¬ÁÒ
Ç÷¡±×ÆÄÀÏÀ» ¸¸µé°í Å°¸¦ ¾²°í Áö¿ì±â¸¦ ¹Ýº¹Çϴ°̴ϴÙ
Ç÷¡±×°¡ /home/rc/flag¿¡ ¿øº»ÀÌ ÀÖ°í ÀÌ°É °è¼Ó /tmp/RC¿¡ ¾²°í »èÁ¦ÇÏ°í ¾²°í »èÁ¦ÇÏ°í Çϴ°ÅÁÒ
ÀüÇüÀûÀÎ ·¹À̽ºÄÁµð¼Ç ¹®Á¦Àε¥
while [ 1 ] ; do ./rc; done À» ÇسõÀ¸½Ã°í
Çϳª¿¡¼­´Â
while [ 1 ] ; do cat /tmp/RC; done À» ÇسõÀ¸½Ã¸é µÎ¹ø° Å͹̳ο¡¼­ Ç÷¡±×°¡ ³ª¿É´Ï´Ù
2017/03/29  
ewqqw µÎ ¸í·É¹®ÀÇ Â÷À̸¦ ÆÄ°íµé¾î¼­ setuid¸¦ ¾ò´Â °ÍÀ̱º¿ä.... °¨»çÇÕ´Ï´Ù 2017/03/29  
3903   ITºÐ¾ß·Î Áø·Î°í¹ÎÀ̳ª,Ãë¾÷,ÀÌÁ÷°í¹ÎÀ¸·Î ±Ã±ÝÇÑÁ¡µéÀÌ ¸¹À¸½ÃÁÒ~?     koreais0
08/08 2709
3902   Æнº¿öµå°¡ ¾ø´Â °èÁ¤ Á¢¼Ó¹æ¹ý[1]     dohyng200
08/04 2959
3901   ¸®´ª½º ¾ÈµÇ¿ä[2]     ÃÖÇö¿ì
08/02 2580
3900   Å͹̳ο¡¼­ ¿ÍÀÌÆÄÀÌ ¿¬°á dhclient°¡ ¾ÈµÅ¿ä     dnlelstem96
06/17 2896
3899   bash 418 ¹öÀü ¼öÁ¤ÇÏ´Â ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù[2]     seongkeunkim
05/30 3730
3898   µ¥½ºÅ©Å¾¿¡ ¿ìºÐÅõ¸¦ ±î´Âµ¥...[3]     vngkv123
04/03 2351
3897   ¸®´ª½º ŸÀӾƿô ¹®Á¦[1]     hktaehyung
04/02 2468
3896   Brute force ¸¦ ÀÌ¿ëÇÑ °ø°Ý[2]     ewqqw
03/30 3082
  setuid¸¦ ÀÌ¿ëÇÑ ±ÇÇÑ »ó½Â[2]     ewqqw
03/29 2333
3894   ÆÄÀ̽㠼³Ä¡ °ü·Ã ¹®Á¦°¡ ¹ß»ýÇÏ¿© Áú¹® ¿Ã·È½À´Ï´Ù..[1]     dndud1346
03/28 2265
3893   ¸®´ª½º ½© ¸í·É°ü·Ã...[2]     vngkv123
03/21 2763
3892   setuid ¸¦ ÀÌ¿ëÇÑ ±ÇÇѾò±â ¼Ò½º[1]     ewqqw
03/11 2810
3891   ¼Ò½º ºÐ¼® ºÎŹµå¸³´Ï´Ù.[3]     ewqqw
03/10 2627
3890   PYTHONÀ» ÀÌ¿ëÇÑ È¯°æº¯¼ö¿¡ °ª³Ö±â[2]     ewqqw
03/09 2269
3889     [re] PYTHONÀ» ÀÌ¿ëÇÑ È¯°æº¯¼ö¿¡ °ª³Ö±â     ewqqw
03/09 1533
3888   SETUID¸¦ ÀÌ¿ëÇÑ ±ÇÇÑ ¾ò±â ¼Ò½º ºÐ¼® ºÎŹ µå¸³´Ï´Ù[3]     ewqqw
03/07 1869
3887   ¸®´ª½º ¾î´ÀÁ¤µµ ¹è¿ü´Âµ¥, ÀÌÁ¦ À©µµ¿ì·Î ÇØÅ·¹è¿öµÇ¿ä?[4]     jsryu1031
03/04 2771
3886   ¿ìºÐÅõ¶û Æäµµ¶óÁß¿¡ ÇØÅ·Çϴµ¥ ÁÁÀº°Í°°³ª¿ä?[5]     jsryu1031
03/01 3657
3885   ¸®´ª½ºÀÇ ±âÃÊÁ»[1]     ½ºÄ«ÀÌ·¹ÀÎ
02/22 2329
3884   Mac OS X F.T.Z °ü·Ã[2]     willwayy
02/15 2958
[1] 2 [3][4][5][6][7][8][9][10]..[197]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org