http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1953 [º¹»ç]
dalgona ¹®¼ º¸¸é¼ shellcode ¸¸µé±â ¿¬½ÀÇÏ°í ÀÖ½À´Ï´Ù.
NULL Á¦°Å¸¦ À§ÇØ ´Ù½Ã ½©Äڵ带 Â¥´Â ºÎºÐ¿¡¼ ÀÌÇØ°¡ ¾È°¡¼ Áú¹®µå¸³´Ï´Ù.
xor %eax, %eax < 0 ´ë½Å eax»ç¿ëÇϱâ À§ÇØ
push %eax < NULL
push $0x68732f2f < //sh
push $0x6e69622f < /bin
mov %esp, %ebx < /bin//sh ÀÇ Æ÷ÀÎÅÍ
push %eax < NULL
push %ebx < /bin//sh ÀÇ Æ÷ÀÎÅÍ
mov %esp, %ecx < /bin//sh ÀÇ Æ÷ÀÎÅÍÀÇ Æ÷ÀÎÅÍ
-----------------------------------
mov %eax, %edx < ????
-----------------------------------
mov $0xb, %al < system call 11 À» Çϱâ À§ÇØ
int $0x80 < ÀÎÅÍ·´Æ® ( execve ½ÇÇà )
???? ºÎºÐ¿¡´Â Á¦°¡ ¾Ë±â·Ð execveÀÇ ÀÎÀÚµéÀ» push ÇؾߵǼ
push %eax < NULL
push %ecx < /bin//sh ÀÇ Æ÷ÀÎÅÍÀÇ Æ÷ÀÎÅÍ
push %ebx < /bin//sh ÀÇ Æ÷ÀÎÅÍ
¸¦ ÇØ¾ß Çϴµ¥ À̰͵éÀ» ½ï »©³õ°í
mov %eax, %edx
¸¸ µé¾î ÀÖ¾î¼ ´çȲ½º·´³×¿ä.
¿Ö ÀÎÀÚ¸¦ push ÇÏ´Â °úÁ¤ÀÌ ºüÁ³À¸¸ç edx¿¡ 0À» ³Ö´Â ÀÌÀ¯´Â ¹ºÁö ±Ã±ÝÇÕ´Ï´Ù. |
Hit : 1786 Date : 2018/12/22 11:34
|