½Ã½ºÅÛ ÇØÅ·

 1574, 11/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   dudgb2380
   FSBÁú¹®ÀÌ¿ä

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1754 [º¹»ç]


pwnable ¹®Á¦¸¦ Ç®°íÀִµ¥


#include <stdio.h>
#include <alloca.h>
#include <fcntl.h>

unsigned long long key;
char buf[100];
char buf2[100];

int fsb(char** argv, char** envp){
        char* args[]={"/bin/sh", 0};
        int i;

        char*** pargv = &argv;
        char*** penvp = &envp;
        char** arg;
        char* c;
        for(arg=argv;*arg;arg++) for(c=*arg; *c;c++) *c='\0';
        for(arg=envp;*arg;arg++) for(c=*arg; *c;c++) *c='\0';
        *pargv=0;
        *penvp=0;

        for(i=0; i<4; i++){
                printf("Give me some format strings(%d)\n", i+1);
                read(0, buf, 100);
                printf(buf);
        }

        printf("Wait a sec...\n");
        sleep(3);

        printf("key : \n");
        read(0, buf2, 100);
        unsigned long long pw = strtoull(buf2, 0, 10);
        if(pw == key){
                printf("Congratz!\n");
                execve(args[0], args, 0);
                return 0;
        }

        printf("Incorrect key \n");
        return 0;
}

int main(int argc, char* argv[], char** envp){

        int fd = open("/dev/urandom", O_RDONLY);
        if( fd==-1 || read(fd, &key, 8) != 8 ){
                printf("Error, tell admin\n");
                return 0;
        }
        close(fd);

        alloca(0x12345 & key);

        fsb(argv, envp); // exploit this format string bug!
        return 0;
}

À§ÀÇ printf(buf)ºÎºÐÀ» °ø°ÝÇϴ°Š°°Àºµ¥ ÀÎÅͳÝÀ» µ¹¾Æ´Ù´Ï¸é¼­ ¹è¿î°ÍµéÀº ÀüºÎ AAAA%x%x%x.....ÀÌ·±½ÄÀ¸·Î ÀÔ·ÂÀ» ³Ö¾î¼­ ¸î¹ø° Æ÷¸ËÀÎÀÚ°¡ ¸Ç¾ÕÀÇ ½ºÆ®¸µÀ» ¹Þ´ÂÁö È®ÀÎÇÑ ÈÄ¿¡ °Å±â¿¡ ÁÖ¼Ò°ªÀ» ³Ö°í °ø°ÝÀ» Çϴµ¥ buf°¡ Àü¿ªº¯¼ö¶ó Á» ´Ù¸£°Ô ³ª¿À´õ¶ó±¸¿ä.. Àü¿ªº¯¼öÀÏ °æ¿ì¿¡´Â ¾î¶²½ÄÀ¸·Î ÇؾßÇϳª¿ä

  Hit : 3947     Date : 2014/07/14 11:17



    
letmeln Áú¹®¿¡ ´ëÇÑ ´äº¯Àº Àúµµ ¸ô¶ó¼­ ¸»¾¸ ¸ø µå¸®Áö¸¸ À§¿¡ Äڵ带 10ÁÙ Á¤µµ·Î ÁÙ¿©¼­ µð¹ö°Å·Î º¸¸é¼­ Á÷Á¢ Å×½ºÆ®ÇÏ½Ã¸é ¾Æ¸¶µµ ±Ý¹æ ÀÌÇØÇÏ½Ç ¼ö ÀÖ¾î¿ä¤¾¤¾ 2014/07/25  
1374   bof Áú¹® µå¸®°Ú½À´Ï´Ù     kiete1
07/26 2851
  FSBÁú¹®ÀÌ¿ä[1]     dudgb2380
07/14 3946
1372   ´ëÇб³ ½Ã½ºÅÛÇØÅ·Æí ¸Þ¸ð¸®°ª º¯Á¶¿¡ °üÇؼ­[4]     swl90809
05/21 3620
1371   Áú¹®ÀÖ½À´Ï´Ù~     blgf6190
04/24 3004
1370   ¹öÆÛ¿À¹öÇÃ·Î¿ì ±âÃÊ¿¡ ´ëÇØ º¸±â ½ÃÀÛÇÕ´Ï´Ù. [¸Æ os»ç¿ëÀÚ¿¡ °üÇÑ Áú¹®]     segost
04/14 3094
1369   process profiling?     h@cking2013
04/13 3287
1368   ½Ã½ºÅÛ ÇØÅ· Linux Ãʺ¸¿¡¼­ dumpÄڵ忡¼­ ¸·Çô¼­ Áú¹®µå¸³´Ï´Ù ¤Ð[1]     yelohair354
03/31 3875
1367   ½Ç½À os¿¡ °üÇؼ­ .... ±ÞÇÕ´Ï´Ù.[2]     dnjs7292
03/28 3850
1366   ÇØÅ· °ø°ÝÀÇ ¿¹¼úÀ̶ó´Â Ã¥À¸·Î °øºÎÇϴµ¥¿ä     kang010330
03/22 3218
1365   ¾Æ½Ã´Â ºÐ ´äº¯ºÎŹ¿ä. Lord of BOF(fedora)¿¡´Â ¾î¶»°Ô???[1]     hack31337
03/18 3480
1364   putty»ç¿ë °ü·Ã Áú¹®ÀÔ´Ï´Ù.[2]     sogang1528
02/20 2906
1363   backtrack5 , Local IP Áú¹®[1]     fangdol888
02/18 3574
1362   @@@@@@ ¼­¹ö Á¢¼Ó¾ÆÀÌÇÇ ±â·Ï »èÁ¦Çϴ¹æ¹ýÁ» ¾Ë·ÁÁÖ¼¼¿ä @@@@@@     k201113
02/17 3975
1361   =====¼­¹ö Á¢¼Ó¾ÆÀÌÇÇ ±â·Ï »èÁ¦Çϴ¹æ¹ýÁ» ¾Ë·ÁÁÖ¼¼¿ä*****     k201113
02/17 2829
1360   =====¼­¹ö Á¢¼Ó¾ÆÀÌÇÇ ±â·Ï »èÁ¦Çϴ¹æ¹ýÁ» ¾Ë·ÁÁÖ¼¼¿ä=====     k201113
02/17 3318
1359   ¼­¹ö Á¢¼Ó ¾ÆÀÌÇÇ »èÁ¦ÇÏ´Â ¹æ¹ýÁ» ¾Ë·ÁÁÖ¼¼¿ä~~     k201113
02/16 2825
1358   x86-64bit ½ºÅÿÀ¹öÇÃ·Î¿ì ¸·¸·Çϳ׿ä...¤Ð[3]     kumi123
02/15 4625
1357   window2008 r2¿¡ ¿ø°Ýµ¥½ºÅ©Å¾ Á¢¼ÓÈÄ ·Î±×±â·Ï¸¸ »èÁ¦Çϸé ÈçÀûÀÌ ¿ÏÀüÈ÷ Áö¿öÁö³ª¿ä??     k201113
02/14 2999
1356   À©µµ¿ì8 ¹éÆ®·¢     wolves2810
02/13 2998
1355   BOF ¿Õ±âÃÊÆí Áú¹®ÀÌ¿ä[1]     0ri0nalpha
02/10 3360
[1].. 11 [12][13][14][15][16][17][18][19][20]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org