½Ã½ºÅÛ ÇØÅ·

 1574, 6/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   vngkv123
   unlink¸ÅÅ©·Î¿¡¼­ P....

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1875 [º¹»ç]


P, Áï unlinkµÇ´Â chunk P¸¦ ¾î¶»°Ô Á¤ÀÇÇÏ´ÂÁö°¡ ±Ã±ÝÇÏ³×¿ë ¤Ì¤Ì

unlink°ËÁõ ·çƾ¿¡¼­ P->fd->bk = P °¡ µÇ¾î¾ß Çϴµ¥ unsafe unlink¸¦ °øºÎÇÏ°í Àִµ¥, ÀÌ P°¡ ¾î¶»°Ô Á¤ÀǵǴÂÁö°¡ ¤Ì

  Hit : 2228     Date : 2017/05/12 10:26



    
zer0water P->fd->bk = P->bk
P->bk->fd = P->fd ÀÌÁÒ
¿©±â¼­ Heap overflow°¡ »ý±â°ÔµÇ¾î PÀÇ fd,bk¸¦ º¯Á¶ÇÒ ¼ö ÀÖ´Ù¸é,
ƯÁ¤ ¸Þ¸ð¸®¿¡ °ªÀ» ¾²´Â°Ô °¡´ÉÇØÁö´Âµ¥¿ä.
Á˼ÛÇѵ¥ Àú´Â unlinkµÇ´Â chunk P°¡ ¾î¶»°Ô Á¤ÀǵdzĴ Áú¹®ÀÌ ¹ºÁö ÀÌÇØ°¡ µÇÁö ¾Ê³×¿ä
2017/05/12  
vngkv123 unlink °ËÁõ ·çƾ¿¡¼­ if(__builtin_expect(FD->bk != P | BK->fd != P, 0)ÀÌ ÂÊ ¸»Çϴ°ſ¡¿µ.
ÀϹÝÀûÀÎ binlist¿¡¼­ÀÇ chunk°¡ freeµÉ ¶©, P°¡ chunkÀÇ ½ÃÀۺκÐÀ» °¡¸®Å°±â ¶§¹®¿¡ ÀÌÇØÇϱ⠽¬¿îµ¥
unsafe unlink¿¡¼­ fake chunk¸¦ ±¸¼ºÇØÁÙ ¶§, ÀÌ fake chunkÀÇ Pµµ ¾Æ¸¶ heap¿µ¿ªÀÏÅÙµ¥, ÀÌ ·çƾÀ» ¿ìȸÇϱâ À§ÇØ bss¿µ¿ª¿¡ ÀúÀåµÇÀÖ´Â ÁÖ¼Ò·Î fake chunkÀÇ fd¿Í bk¸¦ ¼³Á¤ÇØÁØ´Ù´Â°Ô ÀÌÇØ°¡ ¾ÈµÇ³×¿ë.
2017/05/12  
vngkv123 À§ÀÇ 2¹ø° ÁÙ¿¡¼­ freeµÉ¶§°¡ ¾Æ´Ï¶ó unlinkµÉ ¶§¿ë ¤Ì¤Ð 2017/05/12  
ÇØÄð·¯ unlink¿¡¼­ p´Â
/* consolidate backward */
if (!prev_inuse(p)) {
prevsize = prev_size (p);
size += prevsize;
p = chunk_at_offset(p, -((long) prevsize));
unlink(av, p, bck, fwd);
}
ÀÌ·¸°Ô Á¤Àǵ˴ϴÙ
p - p->prev_size
2017/05/14  
vngkv123 °¨»çÇÕ´Ï´Ù ¤¾¤¾ 2017/05/14  
1474   uaf Ãë¾àÁ¡ ,¸Þ¸ð¸® ¸¯ °ü·Ã ¹®Á¦[2]     pkdo1030
07/15 2423
1473   r0pbabay ¸¦ Ǫ´Âµ¥....[1]     ewqqw
07/07 1934
1472   ½Ã½ºÅÛ ÇØÅ·°­Á 21°­ºÎÅÍ ÀÚ·á ºÎŹµå·Áµµ µÉ±î¿ä?     sexissports
06/23 2398
1471   c¾ð¾î ÇÔ¼ö Á¤ÀÇÁß¿¡...     vngkv123
06/20 2106
1470   checksec, ELF±â´É, ±×¿Ü Áú¹®....     vngkv123
06/14 2238
1469   pwnable°ú ½ÇÀü ½Ã½ºÅÛ ÇØÅ·ÀÇ Â÷ÀÌ[2]     choboKing
06/11 4365
1468   ret2kernel32? (À©µµ¿ì ret2libc)[3]     choboKing
06/11 2135
1467   ulimit -f °ü·ÃÇÏ¿© Áú¹®µå·Áº¾´Ï´ç     vngkv123
06/01 2060
1466   ½©Äڵ带 ÀÌ¿ëÇؼ­ bof ¸¦ ÇÒ¶§[4]     tkakr7458
05/22 2554
  unlink¸ÅÅ©·Î¿¡¼­ P....[5]     vngkv123
05/12 2227
1464   heap¿¡¼­ unsafe unlink°¡ Á¶±Ý ÀÌÇØ°¡ ¾ÈµÇ³×¿ë ¤Ð[6]     vngkv123
05/10 3954
1463   heap¿¡¼­ bin°ü·Ã[3]     vngkv123
04/30 2382
1462   codegate nuclear¹®Á¦ Áß libc leakÁú¹®..[3]     vngkv123
04/27 3045
1461   fgetsÇÔ¼ö¸¦ ÀÌ¿ëÇÑ ¹öÆÛ¿À¹öÇ÷ο젠   ewqqw
04/23 3792
1460   format string ¹öÆÛ¿À¹öÇ÷ο젠   ewqqw
04/22 2063
1459   angry_doraemon°°Àº ¹®Á¦ ·ÎÄõî·Ï..     vngkv123
04/22 2449
1458   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã[1]     ewqqw
04/21 2194
1457   ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ü·Ã[2]     ewqqw
04/20 2136
1456   format string bug + got overwite[3]     tkakr7458
04/19 2377
1455   python z3....[2]     vngkv123
04/19 3030
[1][2][3][4][5] 6 [7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org