½Ã½ºÅÛ ÇØÅ·

 1574, 2/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   RTL Áú¹® ÀÔ´Ï´Ù

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1955 [º¹»ç]


Ubuntu 18.04 LTS ¹öÀü¿¡¼­ RTL ¿¬½À°íÀÖ½À´Ï´Ù.

RTL À̱⶧¹®¿¡ ½ºÅÿ¡ ½ÇÇà±ÇÇѸ¸ »©°í ³ª¸ÓÁö º¸È£±â¹ýÀº ÇØÁ¦Çß°í, 32bit ÄÄÆÄÀÏ Çß½À´Ï´Ù.
ASLRµµ ÇØÁ¦Çß½À´Ï´Ù. ( /proc/sys/kernel/randomize_va_space = 0 )
system ÇÔ¼ö ÁÖ¼Ò, /bin/sh ÀÇ ½ÃÀÛÁÖ¼Òµµ ã°í RTL ±â¹ýÀ¸·Î Á¦°¡¸¸µç Ãë¾àÇÑ ÇÁ·Î±×·¥ ÀͽºÇ÷ÎÀÕÀ» Çϸé Segmentation Fault ¿¡·¯°¡ ¶å´Ï´Ù.

Ȥ½Ã ÀÌ·± °æÇè Çغ¸½Å ¼±»ý´Ôµé °è½Ã¸é Á¶¾ðÁ» ºÎŹµå¸³´Ï´Ù. ¤Ð¤Ð

  Hit : 2732     Date : 2019/01/11 10:17



    
qw3709 32bit RTl½Ã¿¡´Â buff | ebp | ret ¿¡¼­ ret¿¡ systemÀ»¾²°í ´ÙÀ½ 4byte´Â ´ÙÀ½ÇÔ¼ö¿¬°è¸¦À§ÇÑ rop_gadgetÀ̳ª exit()ÇÔ¼ö¸¦ ¾²½Ã°í ±×´ÙÀ½ 4byteºÎÅÍ /bin/sh ÀÎÀÚ¸¦³Ö¾îÁÖ¸éµË´Ï´Ù. system("/bin/sh")¸¸ ½ÇÇàÇϽDz¨¸é ret´ÙÀ½ 4byte´Â±×³É 0À¸·Î ºñ¿ì¼ÅµµµÇ¿ä 2019/01/14  
turttle2s gdb·Î ±îº¸´Ï±î ¸¶Áö¸· ÁÙ¿¡

leave
lea esp, [ecx-0x4] << ?????
ret

ÀÌ·¸°Ô µÇÀÖ¾ú½À´Ï´Ù. ecx¿¡´Â systemÇÔ¼ö ´ÙÀ½ 4¹ÙÀÌÆ®¿¡ ³ÖÀº 'aaaa'°ªÀÌ µé¾îÀִµ¥ ÀÌ ¸í·ÉÀÌ
-fno-builtin ¿É¼ÇÀ» ÁÖ¸é ¾ø¾îÁö³×¿ä.
ÀÌ°Ô ¹¹ÇÏ´Â ¸í·ÉÀΰ¡¿ä?
2019/01/18  
turttle2s Àú°Å¶§¹®¿¡ °è¼Ó Áß°£¿¡ Segmentation Fault ¶ß´Âµ¥...
-fno-builtin ¿É¼ÇÀ» Á༭ Àú ¸í·ÉÀ» ¾ø¾Ö¸é RTLÀÌ µË´Ï´Ù.
2019/01/18  
qw3709 -fno-buiiltinÀÌ ¶óÀ̺귯¸®¶û ¸µÅ©¾ÈµÇ°ÔÇϴ°ǵ¥
Àú°Å´Â ±×³É leaveÀü¿¡ ºê·¹ÀÌÅ©Æ÷ÀÎÅ͸¦ °É¾î¼­ ¸Þ¸ð¸®È®ÀÎÇغ¸½Ã°í ecx-0x4À§Ä¡¿¡ systemÀ̵é¾î°¡°Ô ÇϽøéµÇ¿ä.
2019/01/22  
1554   [LOB Redhat] succubus -> nightmare[3]     turttle2s
09/26 1649
1553   read()·Î got leakÀÌ °¡´ÉÇÑ°¡¿ä?[1]     turttle2s
09/26 1651
1552   pwntools ¾²½Ã´Â ºÐµé ~[6]     turttle2s
09/17 1865
1551   system("/bin/sh") ¿Í execve("/bin/sh",0,0)[2]     turttle2s
09/16 2374
1550   ROP Áú¹®ÀÔ´Ï´Ù[2]     turttle2s
09/09 2104
1549   BOF¸¦ ÇÏ´Â ÀÌÀ¯°¡ ¹«¾ùÀΰ¡¿ä?[7]     turttle2s
09/03 2353
1548   rop ´ÙÀ½¿¡ ¹¹¸¦ °øºÎÇÏ´Â°Ô ÁÁÀ»±î¿ä?[1]     tloet
08/26 1991
1547   [ LOB ] skeleton -> golem[3]     turttle2s
08/21 1548
1546   Á¦°¡ ½Ã½ºÅÛ ÇØÅ·ÂÊÀ¸·Î °¡º¸·Á ÇÕ´Ï´Ù.[3]     gun7935
08/01 1977
1545   PLT GOT Áú¹®[3]     turttle2s
07/30 1491
1544   setreuidÇÔ¼ö¿Í setuidºñÆ® °ü°è[1]     park345601
07/26 1332
1543   lob remote bof[6]     park345601
07/25 1422
1542   pwntools ¸¦ ÀÌ¿ëÇÑ exploit ÄÚµå Áú¹®[3]     turttle2s
06/07 1498
1541   Á»ºñ ¹ÙÀÌ·¯½º ¹®ÀÇ °Ç[1]     kirr2
04/14 1819
1540     [re] Á»ºñ ¹ÙÀÌ·¯½º ¹®ÀÇ °Ç     ÇѽÂÀç
05/23 1380
1539   ¹é½Å¿ìȸÁú¹®µå¸³´Ï´Ù (¾Ç¿ë¸ñÀû¾Æ´Ï¿¡¿ë)[3]     kangyung0447
03/01 2018
1538   pythonÀ¸·Î ÀÎÀÚ¸¦ ³ÖÀ» ¶§[1]     turttle2s
02/23 1558
1537   GOT Overwrite[6]     turttle2s
01/31 1840
  RTL Áú¹® ÀÔ´Ï´Ù[4]     turttle2s
01/11 2731
1535   iptime a3004nd uart¸¦ ÅëÇÑ ½© Á¢±Ù ½Ãµµ Áú¹®µå¸³´Ï´Ù.[1]     cho6206
12/30 3971
[1] 2 [3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org