½Ã½ºÅÛ ÇØÅ·

 1574, 6/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ygw0225
   ½ºÅÿ¡ ASLRÀÌ °É·ÁÀÖÀ¸¸é...???

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1726 [º¹»ç]


ftz±¸ÃàÇؼ­ ·¹º§12¹ø ¹®Á¦ Ç®°íÀִµ¥¿ä
gdb·Î ÁÖ¼Ò È®ÀÎÇÏ·Á°í Çϴµ¥
È®ÀÎÇÒ¶§¸¶´Ù esp°ªÀÌ °è¼Ó¹Ù²î¾î¼­ retÁÖ¼Ò¸¦ ¸øã°Ú½À´Ï´Ù...

Àú¿Í°°ÀººÐÀÇ ±ÛÀÌ À־ ´äº¯À»º¸´Ï ½ºÅÿ¡ ASLRÀÌ °É·ÁÀִ°Ͱ°´Ù°í Çϼ̴µ¥
ÀÌ·²°æ¿ì ¾î¶»°Ô Çؾߵdzª¿ä?;
°¡¶àÀ̳ª ½©ÄÚµå°ø°ÝÇϴ°͵µ À߸ô¶ó¼­ Ã¥º¸¸é¼­ µû¶óÇÏ°íÀִµ¥
Ã¥±×´ë·ÎÇصµ ¾ÈµÇ´Ï Áøµµ¸¦¸ø³ª°¡°Ú³×¿ä ¤Ð¤Ð¤Ð¤Ð


0x08048470 <main+0>:        push   %ebp
0x08048471 <main+1>:        mov    %esp,%ebp
0x08048473 <main+3>:        sub    $0x108,%esp
0x08048479 <main+9>:        sub    $0x8,%esp
0x0804847c <main+12>:        push   $0xc15
0x08048481 <main+17>:        push   $0xc15
0x08048486 <main+22>:        call   0x804835c <setreuid>
0x0804848b <main+27>:        add    $0x10,%esp
0x0804848e <main+30>:        sub    $0xc,%esp
0x08048491 <main+33>:        push   $0x8048538
0x08048496 <main+38>:        call   0x804834c <printf>
0x0804849b <main+43>:        add    $0x10,%esp
0x0804849e <main+46>:        sub    $0xc,%esp
0x080484a1 <main+49>:        lea    0xfffffef8(%ebp),%eax
0x080484a7 <main+55>:        push   %eax
0x080484a8 <main+56>:        call   0x804831c <gets>
0x080484ad <main+61>:        add    $0x10,%esp
0x080484b0 <main+64>:        sub    $0x8,%esp
0x080484b3 <main+67>:        lea    0xfffffef8(%ebp),%eax
0x080484b9 <main+73>:        push   %eax
0x080484ba <main+74>:        push   $0x804854c
0x080484bf <main+79>:        call   0x804834c <printf>
0x080484c4 <main+84>:        add    $0x10,%esp
0x080484c7 <main+87>:        leave  
0x080484c8 <main+88>:        ret    
0x080484c9 <main+89>:        lea    0x0(%esi),%esi
0x080484cc <main+92>:        nop    
0x080484cd <main+93>:        nop    
0x080484ce <main+94>:        nop    
0x080484cf <main+95>:        nop    
End of assembler dump.
(gdb) b *0x080484bf    <--ºê·¹ÀÌÅ© °ÉÀ½
(gdb) r   <--- ½ÇÇà
Starting program: /home/level12/tmp/attackme
¹®ÀåÀ» ÀÔ·ÂÇϼ¼¿ä.
AAAA    <--- °ª ÀÔ·Â
Breakpoint 1, 0x080484bf in main ()
(gdb) x/12x $esp   <---esp °ª È®ÀÎ
0xbfffdfb0:        0x0804854c        0xbfffdfc0        0xbfffdfe0        0x00000001
0xbfffdfc0:        0x41414141       0x00000000        0x00000000  0x078e530f
0xbfffdfd0:        0xbfffe070          0x40015a38        0x0029656e  0x00000000
(gdb) r         <--- ´Ù½Ã ½ÇÇà
The program being debugged has been started already.
Start it from the beginning? (y or n) y
Starting program: /home/level12/tmp/attackme
¹®ÀåÀ» ÀÔ·ÂÇϼ¼¿ä.
AAAA

Breakpoint 1, 0x080484bf in main ()
(gdb) x/12x $esp  (°ª ´Þ¶óÁü)
0xbfffe6b0:        0x0804854c       0xbfffe6c0          0xbfffe6e0        0x00000001
0xbfffe6c0:        0x41414141       0x00000000       0x00000000        0x078e530f
0xbfffe6d0:        0xbfffe770        0x40015a38        0x0029656e        0x00000000
(gdb)

  Hit : 3825     Date : 2014/01/17 06:36



    
Deferto FTZ ±¸ÃàÀ» ³ôÀº Ä¿³Î ¹öÁ¯¿¡¼­ ÇϽŠ¸ð¾çÀÔ´Ï´Ù. ´ë·« 2.6ÀÌ»óÀÇ Ä¿³Î ¹öÁ¯¿¡¼­ºÎÅÍ ASLRÀÌ °É¸®¹Ç·Î ±× ÀÌÇÏ¿¡ Ä¿³Î¹öÀüÀ» °¡Áö°í ÀÖ´Â ¸®´ª½º·Î ±¸ÃàÇØÁÖ¼¼¿ä. ·¹µåÇÞ 6.2¸¦ ±¸ÇÏ½Ã¸é µÉ°Å °°½À´Ï´Ù. 2014/01/17  
cd80 /proc/sys/kernel/randomize_va_space ÆÄÀÏÀÌ ÀÖÀ¸¸é
echo 0 > /proc/sys/kernel/randomize_va_space¸¦ ÇÏ°í Çغ¸¼¼¿ä
2014/01/17  
ygw0225 ¿©±âȨÆäÀÌÁö¿¡ÀÖ´ø À̹ÌÁö¸¦ ¹Þ¾Æ¼­ ±¸ÃàÇß¾ú´Âµ¥ ¾Ë°íº¸´Ï ·¹µåÇÞ9.0ÀÌ´õ±º¿ä..
6.2·Î ´Ù½Ã ±¸ÃàÇß´õ´Ï Á¦´ë·Î µÇ³×¿ä^^ °¨»çÇÕ´Ï´Ù
2014/01/18  
1474   ¾È³çÇϼ¼¿ä ÀÌ·±°Íµµ°¡´ÉÇÑ°¡¿ä?[5]     dydghd
10/15 3155
1473   ¾È³çÇϼ¼¿ä ..·Î±× ÆÄÀÏ »èÁ¦ ¿¡ ´ëÇÑ ..[2]     cisconet
03/25 3621
1472   ¾È³çÇϼ¼¿ä     kw89105
04/29 3113
1471   ¾È³çÇϼ¼¿ä[1]     unhacking
01/10 3258
1470   ¾È³çÇϼ¼¿ä[3]     wjdgml191
08/10 3242
1469   ¾ËÁýegg ÆÄÀÏ¿¡ ¾ÏÈ£[6]     kdj2244
08/25 15347
1468   ¾Ç¼ºÄÚµå ºÐ¼®...[1]     dreadlo
09/27 2893
1467   ¾Ç¼º ÄÚµå °ü·Ã Áú¹®Àε¥..[3]     kimtaeun0106
08/26 3591
1466   ½º¸¶Æ®ÆùÇØÅ·ÀÌ °¡´ÉÇÑ°¡¿ä?[8]     kkkk4321
06/10 4029
1465   ½º¸¶Æ®ÆùÇØÅ·[3]     ykoy1577
06/16 3879
1464   ½º´ÏÇÎ ÇÒ¶§     kjwon15
08/07 3213
1463   ½ºÄµÅ½Áö¿¡ ´ëÇÑ Áú¹®ÀÔ´Ï´Ù..[2]     soarrr
07/03 3203
1462   ½ºÆÄÀÌ ¾ÆÀÌ ¿Í Á¦¿ì½º¸¦ ¾Æ½Ã³ª¿ä?     gkswls123
11/04 2765
1461   ½ºÅ¸Å©·¡ÇÁÆ® ¹èƲ³Ý °ü·Ã Áú¹®¿Ã¸³´Ï´Ù..[5]     ¼ðÄ«¿¤
03/21 4074
1460   ½ºÅ¸ÀÇ ¸ÊÇÙÀÇ ¿ø¸®°¡ ¹¹ÁÒ?[2]     jinugi77
05/10 5591
1459   ½ºÅÿ¡ µ¥ÀÌÅÍ ³ÖÀ» ¶§ SIGSEGV[4]     turttle2s
02/04 1438
1458   ½ºÅÿ¡ ´ëÇؼ­[2]     GTzad
10/20 3008
  ½ºÅÿ¡ ASLRÀÌ °É·ÁÀÖÀ¸¸é...???[3]     ygw0225
01/17 3824
1456   ½ºÅÿÀ¹öÇ÷οì Áú¹®.[7]     sktleh
08/15 3279
1455   ½ºÅø޸𸮿¡¼­ ¸ÞÀÎ ÀÌ¿ÜÀÇ ÇÔ¼ö¸¦ ½ÇÇàÀÌ ³¡³ª°í ¹ÝȯÇÒ ¶§[2]     6¿ù
02/26 3287
[1][2][3][4][5] 6 [7][8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org