½Ã½ºÅÛ ÇØÅ·

 1574, 5/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ±ÀèÀÌ
   http://jack2.tistory.com
   [BOF] Hackerschool Handbook#1 BOF ¿Õ±âÃÊÆí p.121¿¡¼­

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1589 [º¹»ç]


½Ç½À ³»¿ëó·³ RET(¸®ÅÏ ¾îµå·¹½º)¸¦ 0xdeadbeef·Î ¹Ù²Ù·Á°í ÇÕ´Ï´Ù.
¼Ò½ºÄÚµå´Â ¾Æ·¡¿Í °°½À´Ï´Ù.

Jack2@SchoolPC ~/BOF/12
$ cat ex3.c
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include "dumpcode.h"

int main(int argc, char *argv[])
{
        char buffer[20] = {0,};         //0À¸·Î ÃʱâÈ­
        int *pointer_to_ret = (int *)(buffer+24);       //ret¸¦ Ãâ·ÂÇϱâ À§ÇÑ Æ÷ÀÎÅÍ

        if(argc < 2)
        {
                printf("argument error\n");
                exit(-1);
        }

        //dumpcode·Î ¸Þ¸ð¸® ´ýÇÁ
        dumpcode(buffer, 28);
        printf("[+] BEFORE : the return address is 0x%08x\n\n", *pointer_to_ret);

        //buffer overflow ¹ß»ý!!
        strcpy(buffer, argv[1]);

        //dumpcode·Î ¸Þ¸ð¸® ´ýÇÁ
        dumpcode(buffer, 28);
        printf("[+] AFTER : the return address is 0x%08x\n\n", *pointer_to_ret);
}


¸·»ó 0xdeadbeef·Î ¹Ù²Ù·Á°í Çϴµ¥ ¾Æ·¡¿Í °°Àº °á°ú°¡ ³ªÅ¸³³´Ï´Ù.
Jack2@SchoolPC ~/BOF/12
$ ./ex3 aaaaaaaaaaaaaaaaaaaaaaaa`python -c 'print "\xef\xbe\xad\xde"'`
0x0022ac78 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0x0022ac88 00 00 00 00 90 ac 22 00 2f 00 00 00               ......"./...
[+] BEFORE : the return address is 0x0000002f

0x0022ac78 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61  aaaaaaaaaaaaaaaa
0x0022ac88 61 61 61 61 61 61 61 61 ef be ad de               aaaaaaaa....
Segmentation fault (core dumped)


Áï , printf("[+] AFTER : the return address is 0x%08x\n\n", *pointer_to_ret);
ÀÌ Äڵ尡 ½ÇÇàµÇÁö ¾Ê´Âµ¥¿ä...

Ȥ½Ã³ª ÇÏ´Â »ý°¢¿¡ ftz ¼­¹ö¿¡ Á¢¼ÓÀ» ÇÑ µÚ °°Àº ¼Ò½ºÄڵ带 ÄÄÆÄÀÏ ÇÑ °á°ú

[guest@ftz practice]$ ./ex3 aaaaaaaaaaaaaaaaaaaaaaaa`python -c 'print "\xef\xbe\xad\xde"'`
0xbffffa90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
0xbffffaa0 00 00 00 00 04 fb ff bf b8 fa ff bf               ............
[+] BEFORE : the return address is 0xbffffab8

0xbffffa90 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61 61  aaaaaaaaaaaaaaaa
0xbffffaa0 61 61 61 61 61 61 61 61 ef be ad de               aaaaaaaa....
[+] AFTER : the return address is 0xdeadbeef

´ÙÀ½°ú °°ÀÌ Àß ³ªÅ¸³³´Ï´Ù.

Á¦°¡ ½Ç½ÀÇÑ È¯°æÀÌ windows xp cygwin ȯ°æ¿¡¼­ ÄÄÆÄÀÏÀ» Çß½À´Ï´Ù.
±×·¡¼­ ¹®Á¦°¡ »ý±ä°Í °°Àºµ¥
ÀÚ¼¼ÇÑ ¿øÀÎ ¾Æ½Ã´Â ºÐ ÀÖÀ¸½Ã¸é ´äº¯ Á» ºÎŹµå¸±²²¿ä

  Hit : 3363     Date : 2012/06/27 01:55



    
cd80 ÄÚ¾îÆÄÀÏ¿¡¼­ È®ÀÎÇغ¸¼Å¾ß ÇÒ °Í °°³×¿ä
¼¼±×ÆúÀÌ ÀϾÀ»¶© printfÇÔ¼ö°¡ ½ÇÇàÁßÀÏÅ×´Ï ÀÏ´Ü ÄÚ¾îÆÄÀÏ¿¡¼­ ½ºÅÿ¡ ¹¹°¡ Ǫ½¬µÆ³ª º¸½Å Èľȳª¿Â´Ù ½ÍÀ¸¸é gdb·Î Á÷Á¢ ½ÇÇà½ÃÅ°¸é¼­ printf ÀÇ ÀÎÀÚ·Î ¹¹°¡ Ǫ½¬µÇÀÖ³ª È®ÀÎÇغ¸¼¼¿ä
2012/06/28  
1494     ¿¹Àü¿¡..     awsedr45
03/31 3896
1493     [re] À¥ÇØÅ· ½ÎÀÌÆ® ÀÖ³ª¿ä?[1]     awsedr45
03/31 5841
1492   IpÁ¢¼Ó?[1]     axd0074
10/04 3311
1491   ¾ÆÀÌÇÇÁÖ¼Ò¸¸À¸·Î ÇØÅ·ÀÌ °¡´ÉÇմϱî???[1]     Àü°ú¹ü
11/01 4778
1490   ±×·¸´Ù¸é ¾ÆÀÌÇÇ°ü·Ã ÀçÁú¹®ÀÔ´Ï´Ù.[5]     Àü°ú¹ü
11/02 3266
1489   ÀÌ·±°Íµµ ¹öÆÛ ¿À¹öÇ÷οì¶ó°í ÇÒ ¼ö ÀÖ³ª¿ä?[4]     Àý´ë³»°ø
12/12 3128
1488   ¾È³çÇϼ¼¿ä. ¼Ò½º Ãë¾àÇÑ »çÀÌÆ®¿¡ ´ëÇØ ¹®Àǵ帳´Ï´Ù     Âä±¹³ðÇØÅ·ÇÏÀÚ
08/23 3611
1487   ²À Á» ÀоîÁÖ½Ã°í µµ¿ò ¸»¾¸ ºÎŹµå¸±²²¿ä...     ÃÖ¹ÎÁÖ
06/23 5420
1486   ÇØÅ·ÇÏ´Â ¹æ¹ý?[2]     ÃÖ¼±È£
12/08 5990
1485   ¹öÆÛ ¿À¹öÇ÷Π    ÃÖ¼±È£
12/08 3365
1484       [re] [re] ¹öÆÛ ¿À¹öÇ÷Î[2]     ÃÖ¼±È£
12/09 3352
1483   Buffer Overflow ÇÏ´Â ¹æ¹ý[2]     ÃÖ¼±È£
12/09 4217
1482   [BOF] Hackerschool Handbook#1 BOF ¿Õ±âÃÊÆí¿¡¼­...[1]     ±ÀèÀÌ
06/21 3443
  [BOF] Hackerschool Handbook#1 BOF ¿Õ±âÃÊÆí p.121¿¡¼­[1]     ±ÀèÀÌ
06/27 3362
1480   µµ½º ¸í·É¾îÁ» ¾Ë·ÁÁÖ¼¼¿ä.[7]     õÀçÇØÄ¿7
10/26 3961
1479   ¼Ò½ºÆÄÀÏ¿¡¼­ ½ÇÇàÆÄÀϱîÁö Áú¹®ÀÌ¿ä!!![1]     õÀçÇØÄ¿7
11/08 3608
1478   ´Ù¸¥»ç¶÷ ÄÄÅÍ IP ¾î¶»°Ô ¾Ë¾Æ³»ÁÒ??[5]     Á¶ÀÌÄÚ
01/07 4638
1477   ÇØÅ· °øºÎ ¾î¶»°Ô ÇؾßÇÏÁ¶ ?[3]     a¹ö¼­Å©a
07/18 3434
1476   ÀÚ°Ô¿¡ ¿Ã·È´Âµ¥ ´äº¯ÀÌ ¾øÀ¸¼Å¼­.. ´Ù½Ã¿Ã¸³´Ï´Ù[1]     ÀººØ¾î
02/02 3295
1475   level1 Áú¹®[1]     baleen37
05/15 2978
[1][2][3][4] 5 [6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org