½Ã½ºÅÛ ÇØÅ·

 1574, 5/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   pkdo1030
   http://h00ker.tistory.com
   Æ÷¸Ë½ºÆ®¸µ °³³ä Á¦´ë·Î ¼³¸íÇØÁֽǺÐ

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1888 [º¹»ç]


Á¤¸®ÇسõÀº ±ÛÀ» ºÁµµ Á¦´ë·Î ÀÌÇØ°¡ ¾ÈµÇ³×¿ä;; ¿¹Àü¿¡µµ Æ÷¸Ë½ºÆ®¸µ °ü·Ã ¹®Á¦¿´´ø ftz level11µµ °á±¹ ¸øÇ®¾ú¾ú´Âµ¥ À̹ø ±âȸ¿¡ °³³äÁ» È®½ÇÈ÷ Àâ¾Æ³õÀ¸·Á±¸¿ä

  Hit : 2297     Date : 2017/07/24 09:50



    
±è´äº¯ Æ÷¸Ë½ºÆ®¸µ¹ö±×´Â °¡º¯ÀÎÀÚ°¡ ¾î¶»°Ô 󸮵Ǵ°¡¸¦ ÀÌÇØÇÏ½Ã¸é µË´Ï´Ù
°¡º¯ÀÎÀÚ¸¦ »ç¿ëÇÏ´Â ÇÔ¼ö´Â ó¸®ÇÒ ÀÎÀÚÀÇ ½ÃÀÛ°ú ³¡À» ¾Ë ¼ö ÀÖ¾î¾ß Çϴµ¥
printf¿¡¼­´Â ù¹ø° ÀÎÀÚÀÇ ¹®ÀÚ¿­¿¡ µé¾î¿Â Æ÷¸Ë½ºÆ®¸µÀÇ °¹¼ö¸¦ ÀÎÀÚÀÇ °¹¼ö·Î ¾Ë°í ó¸®ÇÕ´Ï´Ù
±×·¯´Ï±î printf¿¡ ÀÎÀÚ¸¦ ½ÇÁ¦·Î ¸î°³¸¦ ³Ö¾úµç °£¿¡ Æ÷¸Ë½ºÆ®¸µÀÇ °¹¼ö°¡ 2000°³¶ó¸é printf¾ÈÀÇ Æ÷¸Ë½ºÆ®¸µ Çڵ鷯µµ 2000¹ø ½ÇÇàµÇ´Â °ÍÀÌÁÒ
±×¸®°í ÀÎÀÚ´Â ½ºÅÃÀ» ÅëÇØ Àü´ÞµË´Ï´Ù(32ºñÆ® stdcall, cdecl ±âÁØ)
printf("%x %x %x %x", 65, 66, 67, 68);
À» Çϸé
41 42 43 44 °¡ Ãâ·Â µÇ°ÚÁö¸¸
printf("%x %x %x %x");
À» Çϸé
½ºÅþÈÀÇ ³×°³ÀÇ µ¥ÀÌÅÍ°¡ º¸¿©Áö°Ô µË´Ï´Ù(¸Þ¸ð¸® ¸¯)
±×¸®°í ±× ³×°³ÀÇ µ¥ÀÌÅÍ´Â ½ºÅû󿡼­ Æ÷¸Ë½ºÆ®¸µ(fmt) ÀÎÀÚ°¡ À§Ä¡ÇÑ ±× ´ÙÀ½ºÎÅÍ 4¹ÙÀÌÆ®¾¿ ³×°³°¡ ±×´ë·Î º¸¿©Áö°Ô µË´Ï´Ù. gdb·Î printf È£Ãâ Á÷Àü¿¡ ºê·¹ÀÌÅ©Æ÷ÀÎÆ®¸¦ °É¾î È®ÀÎÇÏ¸é µË´Ï´Ù x/4wx $esp
printfÁ÷Àü¿¡ x/4wx $esp¸¦ ÇÑ°Í°ú printf¿¡¼­ Ãâ·ÂÇÏ´Â°Ô °°´Ü°É ¾Æ½Ç ¼ö ÀÖÀ» °Ì´Ï´Ù
±×·±µ¥ vsprintf¿¡´Â ÀÌ»óÇÏ°Ôµµ %nÀ̶ó´Â, Ãâ·ÂÀÌ¾Æ´Ñ ¾²±â¸¦ ÇÏ´Â Æ÷¸Ë½ºÆ®¸µÀÌ ÀÖ½À´Ï´Ù
±×·³ °á±¹ printf·Î´Â ¸Þ¸ð¸® Àб⠾²±â ¸ðµÎ°¡ µÇ´Â °ÍÀÌÁÒ
ÀÌ°É ÀÌ¿ëÇØ ¸Þ¸ð¸®¸¦ Àоî ÇÊ¿äÇÑ ¶óÀ̺귯¸® ÁÖ¼Ò¸¦ ¾Ë¾Æ³»°í GOT OverwriteµîÀ» ÅëÇØ ÀÓÀÇ ½ÇÇàÈ帧 º¯Á¶°¡ °¡´ÉÇÕ´Ï´Ù
2017/08/07  
1494   ¹è¿­ »çÀÌÀÇ ´õ¹Ì[2]     ka0r1
12/14 1930
1493   Google ChromeÀ» ºÐ¼®ÇÒ·ÁÇϴµ¥...     vngkv123
12/11 2003
1492   BOF ÇÚµåºÏ ½Ã½ºÅÛ ÇØÅ· ¸¶Áö¸·¹®Á¦ Áú¹®ÀÔ´Ï´Ù[1]     deccj97
11/28 2093
1491   ¸®¹ö½ÌÈ­¸éÀÌ ÀÌ»óÇÏ°Ô¶°¿ä[1]     qw3709
11/16 2004
1490   ÇÔ¼ö Á¾·á¿Í ½ºÅà °ü·Ã Áú¹®[1]     you88311
11/05 1947
1489   FTZ level11 °ü·Ã Áú¹® ÀÖ½À´Ï´Ù.[4]     you88311
09/27 2410
1488   ptraceÇÔ¼ö¸¦ ÅëÇØ µð¹ö°Å¸¦ ±¸ÇöÇϴµ¥...     vngkv123
09/25 2120
1487   fuzzer¸¦ ±¸ÇöÇÏ°í½ÍÀºµ¥...[3]     vngkv123
08/25 3842
1486   Áö±Ý ftz ÆÄÀÏ»ý¼º µÇ½Ã³ª¿ä??¤Ð¤Ð[1]     waijeies
08/22 2423
1485     [re] Áö±Ý ftz ÆÄÀÏ»ý¼º µÇ½Ã³ª¿ä??¤Ð¤Ð     ÇѽÂÀç
08/18 2548
1484   remote exploit½Ã¿¡ ¾ÈµÇ´Â°Å ÀÌÀ¯ ¾Ë ¼ö ÀÖÀ»±î¿ä,..[2]     vngkv123
08/13 2274
1483   arena ÀÇ ¶æ...     choboKing
08/09 3779
1482   heap exploit ±â¹ý °øºÎ ¹æ¹ý....     choboKing
08/09 2218
1481   ÃֽŠglibc¿¡¼­ »ç¿ë °¡´ÉÇÑ heap exploit ±â¹ý     choboKing
08/09 1998
1480   ITºÐ¾ß·Î Áø·Î°í¹ÎÀ̳ª,Ãë¾÷,ÀÌÁ÷°í¹ÎÀ¸·Î ±Ã±ÝÇÑÁ¡µéÀÌ ¸¹À¸½ÃÁÒ~?     koreais0
08/08 2211
1479   libc-db¿¡¼­ main_arena ¾î¶»°Ô ãÁÒ?     vngkv123
07/30 2318
  Æ÷¸Ë½ºÆ®¸µ °³³ä Á¦´ë·Î ¼³¸íÇØÁֽǺÐ[1]     pkdo1030
07/24 2296
1477   pwnable.kr uaf ¹®Á¦ Áú¹®ÀÖ½À´Ï´Ù     pkdo1030
07/22 2256
1476   FTZ - Level12..[1]     ys200209
07/19 2093
1475   hex ray Áú¹®[2]     wwwlk
07/16 2138
[1][2][3][4] 5 [6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org