½Ã½ºÅÛ ÇØÅ·

 1574, 5/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ka0r1
   argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë°í ½Í½À´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1942 [º¹»ç]


[wolfman@localhost wolfman]$ ls
darkelf  darkelf.c
[wolfman@localhost wolfman]$ cat darkelf.c
/*
        The Lord of the BOF : The Fellowship of the BOF
        - darkelf
        - egghunter + buffer hunter + check length of argv[1]
*/

#include <stdio.h>
#include <stdlib.h>

extern char **environ;

main(int argc, char *argv[])
{
        char buffer[40];
        int i;

        if(argc < 2){
                printf("argv error\n");
                exit(0);
        }

        // egghunter
        for(i=0; environ[i]; i++)
                memset(environ[i], 0, strlen(environ[i]));

        if(argv[1][47] != '\xbf')
        {
                printf("stack is still your friend.\n");
                exit(0);
        }

        // check the length of argument
        if(strlen(argv[1]) > 48){
                printf("argument is too long!\n");
                exit(0);
        }

        strcpy(buffer, argv[1]);
        printf("%s\n", buffer);

        // buffer hunter
        memset(buffer, 0, 40);
}
[wolfman@localhost wolfman]$









argv[1]ÀÌ 48ÀÌ ³Ñ¾î°¡¹ö¸®¸é ÇÁ·Î±×·¥ÀÌ Á¾·á°¡ µÇ´Â ÇÁ·Î±×·¥À̳׿ä.
Á¦°¡ ¹®¶à »ý°¢³µ´Âµ¥ argv[2]ÀÇ ÀÎÀÚ·Î ½©Äڵ带 ¿Ã¸®°í
argv[1][44]~argv[1][47]·Î argv[2]ÀÇ ÁÖ¼Ò¸¦ ³ÖÀ¸¸é µÇÁö ¾ÊÀ»±î?¶ó´Â ¾ÆÀ̵ð¾î°¡ ¶°¿Ã¶ú½À´Ï´Ù.
±×·±µ¥ °ø±³·Ó°Ôµµ... argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë ¼ö ÀÖ´Â ¹æ¹ýÀ» ¸ð¸¨´Ï´Ù.
gdb·Î µð¹ö±ëÇÏ¸é ¾Ë ¼öµµ Àְڴµ¥...
¾î¶»°Ô ÇÏ¸é ¾Ë ¼ö ÀÖ³ª¿ä?

  Hit : 2364     Date : 2018/09/23 04:19



    
ka0r1 ½º½º·Î ´äÀ» ã¾Ò½À´Ï´Ù.
(gdb) r `python -c 'print "A"*47+"\xbf"` `python -c 'print "B"*1000'`
±×¸®°í x/1000x $esp ÀÌ·±½ÄÀ¸·Î Çϸé argv[2]ÀÇ ÁÖ¼Ò°¡ º¸ÀÌ±ä º¸À̳׿ä.
Ŭ¸®¾î ¿Ï·á!
2018/09/23  
±ºÀÎ start, main ½ÃÀÛ µÇ´Â ºÎºÐ¿¡ bp ¹Ù·Î °É°í º¸¼Åµµ µË´Ï´Ù.... 2018/10/20  
1494   ÀÏ¹Ý À¥¼­¹ö°°Àº À©µµ¿ì¼­¹ö..[3]     ggh646
07/28 3953
1493   ÀÏ¹Ý PCÄÄÇ»ÅÍ ¿ø°Ý Á¢¼Ó ¹æ¹ýÁ»...[1]     ggew2000
05/22 5002
1492   ÀÏ¹Ý ÆÛ½º³Î ÄÄÇ»ÅÍ¿¡¼­ ´Ù¸¥ ÄÄÇ»ÅÍ·Î ÅÚ³Ý Á¢¼ÓÀÌ...[4]     jin1055
10/11 3714
1491   ÀϹÝÀûÀÎ ±Ã±Ý¿¡ ÀÇÇÑ Áú¹®ÀÔ´Ï´Ù^^[5]     PoS
08/10 3051
1490   ÀϹÝÀ¥»çÀÌÆ®¿¡¼­ ¼Ò½ºº¸±â¸¦ Çã¿ëÇÏ´Â ÀÌÀ¯°¡ ¹«¾ùÀԴϱî?[4]     Crucial
07/13 3187
1489   À̹ø¿¡ ¿î¿µÃ¼Á¦¿¡ ´ëÇØ °øºÎÇغ¸·Á Çϴµ¥¿ä... Áú¹®Çϳª¸¸ ÇÏ°Ú½À´Ï´Ù.[4]     boxlug
01/08 3014
1488   ÀÌ»óÇÑ ¾ÏÈ£¸ÞÀÏ??     as1as
05/22 4166
1487   angry_doraemon°°Àº ¹®Á¦ ·ÎÄõî·Ï..     vngkv123
04/22 2503
1486   ÀÔ¹®ÀÚÀε¥ droidjack , spynote Áú¹®     jwjw9900
12/19 3159
1485   API°ü·Ã ÇÔ¼ö Áú¹® ÀÔ´Ï´Ù.. [1]     BLu2Scr22n
02/05 3250
1484   arena ÀÇ ¶æ...     choboKing
08/09 3813
  argv[2]ÀÇ ÁÖ¼Ò¸¦ ¾Ë°í ½Í½À´Ï´Ù.[2]     ka0r1
09/23 2363
1482   argvºÎºÐ¿¡ ½©ÄÚµå ¿Ã¸®´Â Áú¹®ÀÔ´Ï´Ù.     aiurchar
11/01 4768
1481   arp¿¡ °üÇÑ Áú¹®ÀÔ´Ï´Ù.[2]     junli
01/28 3334
1480   ascii armor °ü·Ã Áú¹®[1]     evernick
01/19 5407
1479 ºñ¹Ð±ÛÀÔ´Ï´Ù  asdad[6]     knightpop
12/07 855
1478   asis CTF ¹®Á¦Ç®´Ù°¡....[4]     vngkv123
04/12 2259
1477   aslr ȯ°æ¿¡¼­...[2]     vngkv123
04/12 2551
1476   ASLRÀÌ °É·ÁÀÖÀ»¶§ ret¿¡ ROPÀ¸·Î jmp %espÀ» »ç¿ëÇÑ °æ¿ì.[3]     lMaxl04
06/29 1145
1475   Àú .. Á˼ÛÇѵ¥¿ä .. À̱ÛÁ» ²¿¿Á ºÁÁÖ¼¼¿ä .[4]     psd4d
02/21 3861
[1][2][3][4] 5 [6][7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org