½Ã½ºÅÛ ÇØÅ·

 1574, 3/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   in_reason
   ftz level11¹ø ¹®Á¦¿¡ ´ëÇÑ Áú¹®ÀÌ ÀÖ½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1937 [º¹»ç]


ftz levvel11¹ø¿¡ ´ëÇÑ ±Ã±ÝÁòÀÌ ÀÖ¾î Áú¹®À» ÇÏ°Ô µÇ¾ú½À´Ï´Ù.
gdb¸¦ ÅëÇÏ¿© level11ÀÇ attackme¸¦ µð¹ö±ë Çغ¸¸é

Dump of assembler code for function main:
0x08048470 <main+0>:    push   ebp
0x08048471 <main+1>:    mov    ebp,esp
0x08048473 <main+3>:    sub    esp,0x108
0x08048479 <main+9>:    sub    esp,0x8
0x0804847c <main+12>:   push   0xc14
0x08048481 <main+17>:   push   0xc14
0x08048486 <main+22>:   call   0x804834c <setreuid>
0x0804848b <main+27>:   add    esp,0x10
0x0804848e <main+30>:   sub    esp,0x8
0x08048491 <main+33>:   mov    eax,DWORD PTR [ebp+12]
0x08048494 <main+36>:   add    eax,0x4
0x08048497 <main+39>:   push   DWORD PTR [eax]
0x08048499 <main+41>:   lea    eax,[ebp-264]
0x0804849f <main+47>:   push   eax
0x080484a0 <main+48>:   call   0x804835c <strcpy>
0x080484a5 <main+53>:   add    esp,0x10
0x080484a8 <main+56>:   sub    esp,0xc
0x080484ab <main+59>:   lea    eax,[ebp-264]
0x080484b1 <main+65>:   push   eax
0x080484b2 <main+66>:   call   0x804833c <printf>
0x080484b7 <main+71>:   add    esp,0x10
0x080484ba <main+74>:   leave
0x080484bb <main+75>:   ret
0x080484bc <main+76>:   nop
0x080484bd <main+77>:   nop
0x080484be <main+78>:   nop
0x080484bf <main+79>:   nop
End of assembler dump.

ÀÌ·¸°Ô ¶ß°Ô µÇ´Âµ¥, ¿©±â¼­ ´Ù¸¥ »ç¶÷µéÀÇ ±ÛÀ» º¸¸é main+30ºÎºÐÀÌ SFP¿Í RET¸¦ °¢°¢ 4byte¸¸Å­ ¼±¾ðÇØ ÁØ´Ù°í ³ª¿ÍÀִµ¥ SFP¿Í RETÀÎÁö ¾î¶»°Ô ±¸ºÐÇÏ´ÂÁö ±Ã±ÝÇÕ´Ï´Ù.

±×¸®°í Á¦°¡ ¾Æ´Â Áö½ÄÀ¸·Î´Â ¸ðµç ÇÔ¼ö´Â »ç¿ëÇÒ ¶§ ret¸¦ ¼±¾ðÇÏ°í ½ÇÇàÇϴ°ÍÀ¸·Î ¾Ë°íÀִµ¥ ¿©±â¼­ setreuid´Â ÇÊ¿äÇÏ°í strcpy´Â ±×·¸°Ô Áß¿äÇÏÁö ¾Ê¾Æ¼­ strcpyÀÇ ret°ªÀ» ÀÌ¿ëÇؼ­ ½©À» Å»ÃëÇϴ°ǰ¡¿ä?

±×·¸´Ù¸é printf¿Í setreuid¿¡µµ SFP¿Í ret°ªÀÌ ¼±¾ðµÇ´Â°Ç°¡¿ä?


Áú¹® Á¤¸®
1. SFP¿Í RETÀÎÁö ¾Æ´Ï¸é ÀÏ¹Ý subÀÎÁö ±¸ºÐÇÏ´Â ¹æ¹ý
2. ¸ðµç ÇÔ¼ö¿¡ ret°ªÀÌ ÀÖ´ÂÁö ¾ø´ÂÁö
    ÀÖ´Ù¸é printfÀÇ ret°ª¿¡¼­µµ ½© Å»Ãë°¡ °¡´ÉÇÑÁö

°í¼ö´ÔµéÀÇ ´äº¯ÀÌ ÇÊ¿äÇÕ´Ï´Ù.

  Hit : 1877     Date : 2018/09/10 11:40



    
gihacker ¸ðµç ÇÔ¼ö¸¦ ½ÇÇàÇÒ¶§´Â ½ºÅÿ¡ ret¸¦ Ǫ½¬ÇÕ´Ï´Ù call ¸í·É¾î´Â »ç½Ç Ãà¾àµÈ ¸í·É¾î±¸¿ä 2018/09/10  
dc4458 call À» Çϸé ret ÁÖ¼Ò°¡ Ǫ½¬µÇ°í ¼­ºê·çƾ¾È¿¡¼­ sfp°¡ Ǫ½¬µË´Ï´Ù.
¸»¾¸ÇϽŠsub´Â ±×³É °ø°£È®º¸ÀÎ°Í °°³×¿ä. ¹®¸Æ»óÀ¸·Î´Â setreuid°¡ ret Çѵڿ¡ setreuid°¡ »ç¿ëÇÑ ½ºÅÃÀ» add ¿Í sub·Î Á¤¸®ÇØÁØ°Í °°½À´Ï´Ù.

¸ðµç ¼­ºê·çƾÀº ret ÇÕ´Ï´Ù.
´ç¿¬È÷ printf¿¡µµ ret¸í·É¾î°¡ ÀÖ±¸¿ä ¾î¶² ¹æ¹ýÀ» »ç¿ëÇؼ­ ret ÁÖ¼Ò¸¦ µ¤¾î¾º¿î´Ù¸é ¿øÇÏ´Â Äڵ带 ½ÇÇà½Ãų¼ö°¡ ÀÖ°ÚÁÒ.
2018/09/27  
dc4458 ÇÏÁö¸¸ ¹®Á¦¿¡¼­´Â printf³ª strcpyÀÇ retÁÖ¼Ò°ªÀ» µ¤¾î¾º¿ï ¼ö °¡ ¾ø½À´Ï´Ù.

¹®ÀÚ¿­ÀÌ Ä«ÇÇµÉ °ø°£ÀÇ ÁÖ¼Ò°¡ ¸ÕÀú ¼±¾ðµÇ°í ÈÄ¿¡ ÇÔ¼öµéÀÌ ÄݵDZ⠶§¹®¿¡
À§ ÇÔ¼öµéÀÇ ret °ªµéÀº ¹®ÀÚ¿­ÀÌ Ä«ÇÇµÉ °ø°£ÀÇ ÁÖ¼Òº¸´Ù Ç×»ó ³·Àº ÁÖ¼Ò¿¡ À§Ä¡ÇÏ°Ô µÇ¹Ç·Î ¾î¶² ¹®ÀÚ¿­À» Àü´ÞÇØÁ൵ ret°ªÀ» µ¤¾î¾º¿ï ¼ö °¡ ¾ø½À´Ï´Ù.

strcyp°¡ ÄÝÀÌ µÈ Á÷ÈÄÀÇ ½ºÅÃÀ» ±×¸®¸é ´ÙÀ½°ú °°½À´Ï´Ù.

strcpyÀÇ retÁÖ¼Ò - strcpyÀÇ ÀÎÀÚ1 - strcpyÀÇ ÀÎÀÚ2 - ¹®ÀÚ¿­ÀÌ Ä«ÇÇµÉ °ø°£ - ¸ÞÀÎÀÇ SFP - ¸ÞÀÎÀÇ retÁÖ¼Ò - ¸ÞÀο¡ Àü´ÞµÈ ÀÎÀÚµé...

¼ø¼­±â ¶§¹®¿¡ ¹®ÀÚ¿­ÀÌ Ä«Çǵɰø°£¿¡ ¾î¶² ¹®ÀÚ¿­ÀÌ µé¾î°¡µµ µÚ¿¡ ³ª¿À´Â ¸ÞÀÎÀÇ SFP ³ª ¸ÞÀÎÀÇ RET Áּҵ鸸 µ¤¾î ¾º¿ï ¼ö ÀÖ½À´Ï´Ù.
2018/09/27  
1534   shell code ÀÛ¼º[3]     turttle2s
12/22 1786
1533   ½Ã½ºÅÛ ÇØÅ· Æ÷Æ®Æ÷¿öµù Áú¹®[5]     qwaszx587
12/20 2038
1532   '½Ã½ºÅÛ ÇØÅ·' À̶ó´Â ¿ë¾î¿¡ ´ëÇؼ­[2]     choboKing
12/15 2049
1531   pwnable.kr bof ¹®Á¦!!![2]     hackxx123
12/12 2503
1530   ÅøÅ°µð °ü·Ã Áú¹Ã[2]     qwaszx587
12/03 2038
1529   ½Ã½ºÅÛ ÇØÅ· : ¸®´ª½º ±âÃÊÆí(¾ÆÀÌÇǺ¸´Â¹ý)[1]     rjsdn1578
11/03 3341
1528   FTZ level4 Áú¹®[8]     turttle2s
11/02 1892
1527   RTLÁú¹®![1]     Sp4wn
10/20 2112
1526   LOB ¼¼±×¸ÕÆ® µðÆúÆ® ¿À·ù.. Á» ¾Ë·ÁÁÖ¼¼¿ä ¤Ð[2]     qustkdrn
10/06 1676
1525   argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë°í ½Í½À´Ï´Ù.[2]     ka0r1
09/23 2336
1524   LOB °íºí¸° Ŭ¸®¾î Çß½À´Ï´Ù¸¸ ±Ã±ÝÇÑ°Ô Àֳ׿ä.[3]     ka0r1
09/23 1911
1523   F.T.Z 14´Ü°è[4]     ka0r1
09/21 1961
1522   L.O.B goblin[1]     ka0r1
09/16 1939
1521   Æ÷¸Ë½ºÆ®¸µ Ãë¾àÁ¡ Áú¹®[1]     bufferover
09/14 2794
  ftz level11¹ø ¹®Á¦¿¡ ´ëÇÑ Áú¹®ÀÌ ÀÖ½À´Ï´Ù.[3]     in_reason
09/10 1876
1519   ftz level4 ÆÄÀÏÀÌ ¾È¸¸µé¾îÁý´Ï´Ù..[1]     m914
08/20 1781
1518   ftz level5 ¸µÅ©¿À·ù?     don1004
08/09 1849
1517   ¼¾Å佺¿¡¼­ ¸Æ ¿ø°ÝÁ¢¼Ó     ig0102
07/21 1998
1516   FTZ level4¹ø ¹®Á¦ ±Ã±ÝÇÑ Á¡ÀÌ ÀÖ¾î Áú¹® µå¸³´Ï´Ù.     in_reason
07/18 1744
1515   ftz ¸ÆÀ¸·Î ssh Á¢¼Ó [1]     bunggl
06/30 2363
[1][2] 3 [4][5][6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org