main()
{
char * name[2] ;
name[0] = "/bin/sh";
name[1] = NULL ;
execve(name[0] , name, NULL) ;
}
À§ÀÇ °ÍÀ» ¿ª¾î¼À ÇÏ¿© execve ÇÔ¼ö¿¡ °üÇÑ Äڵ带 »Ì¾Æ ³»¾ú°í..
eax,ebx,ecx,edx ¿¡ µé¾î°¡¾ß Çϴ°͵éÀ» °áÁ¤Çؼ
±×°ÍµéÀ» ¾î¼ÀÄÚµå·Î ´Ù½Ã ÀÛ¼ºÁßÀε¥...
.global main
main :
jmp strings
start: popl %esi
movb $0x00, 0x7(%esi)
movl %esi , 0x8(%esi)
movl $0x00, 0xc(%esi)
movl $0x0b, %eax
movl %esi, %ebx
leal 0x8(%esi), %ecx
movl 0xc(%esi), %edx
int $0x80
movl $0x01, %eax
movl $0x00, %ebx
int $0x80
strings: call start
.string "/bin/sh"
Áö±Ý±îÁöÀÇ °úÁ¤Àº ÀÚÀ¯°Á¿¡ ÀÖ´Â Willy´ÔÀÇ ¹®¼¸¦ µû¶óÇÏ¸é¼ °øºÎÁßÀε¥
À§Ã³·³ ÄÚµùÇÏ¿© ½ÇÇà½ÃÄ×´õ´Ï '¼¼Å©¸àÅ×ÀÌ¼Ç ¿À·ù'°¡ ¶ß³×¿ä..
¸î¹øÀ» µé¿©´Ùº¸¾Æµµ À߸øµÈ °÷À» ãÁö ¸øÇÏ¿´°í..
¹®¼¿Í ºñ±³¸¦ ÇÏ¿©º¸¾Æµµ ´Ù¸¥Á¡ÀÌ ¾ø¾î¼ ÀÌ·¸°Ô Áú¹®µå¸³´Ï´Ù..
¹«¾ùÀÌ À߸øµÈ °ÍÀÎÁö¿ä....;;
±×¸®°í 0x08 °ú 0x8 Àº °°Àº°ÍÀ¸·Î Ãë±ÞµÇ´Â °ÍÀÌ ¸Â³ª¿ä?
ÀüÀÇ ·¹º§º¸´Ù ·¹º§11¿¡¼´Â ¸¹ÀÌ °øºÎÇÏ°Ô µÇ³×¿ä..^^
±×·³ À̸¸..
ps . ½±°Ô ³Ñ¾î°¥ »ý°¢¸»¶ó±¸! °íÀÛ ±×°Í¸¸ ¾Ë°í ³Ñ¾î°¡´Â¼ÀÀÌÀݾÆ! |