½Ã½ºÅÛ ÇØÅ·

 1574, 7/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   vngkv123
   aslr ȯ°æ¿¡¼­...

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1854 [º¹»ç]


64ºñÆ® µ¿Àû¸µÅ·»óÅ¿¡¼­, Äڵ尡 Á¤¸» readÇÔ¼ö¿Í return 0¸¸ Á¸ÀçÇÏ°í ¾î¶°ÇÑ Ãâ·ÂÇÔ¼ö°¡ Á¸ÀçÇÏÁö¾ÊÀ»¶§(16¹ÙÀÌÆ® ¹öÆÛ¿¡ 0x400¸¸Å­ read), read@got ¿£Æ®¸®¿¡ ÀÖ´Â °¡Á®¿Â readÁÖ¼Ò 1¹ÙÀÌÆ®¸¦ ÇÔ¼ö³» syscall·Î overwriteÇÏ¿© eax³ª rax·¹Áö½ºÅÍ¿¡ 1À» ³Ö°í  writeÇÔ¼ö¸¦ È£ÃâÇÏ´Â°Ô ÀÖ´øµ¥ Ȥ½Ã ÀÌ ¹æ¹ý¿¡ ´ëÇØ ¾Æ½Ã´Â ºÐ ÀÖ³ª¿ë?

libc¸¦ ¸ð¸£´Âȯ°æ¿¡¼­ ¾î¶»°Ô ÇØ´ç syscallÀÇ À§Ä¡¸¦ ¾Ë¾Æ¼­ 1¹ÙÀÌÆ® ¿À¹ö¶óÀÌÆ®¸¦ ÇÏ°í eax³ª rax(µÑ ´Ù ¾îÂ÷ÇÇ °ÅÀÇ °°Áö¸¸)¿¡ 1À» ³Ö¾îÁÖ´ÂÁö ¸ð¸£°Ú³×¿ä ... °¡Á¬µµ ¾ø´Â°Å °°´øµ¥..

https://devcraft.io/posts/2017/04/09/start-hard-asis-ctf-quals-2017.html

Àǹ®Á¡À» Ç°Àº asis 2017 start_hard¶ó´Â ¹®Á¦ÀÇ ¶óÀÌÆ®¾÷Àε¥ Ȥ½Ã ´äÇØÁÖ½Ç ¼ö ÀÖ´Â ºÐ °è¼ËÀ¸¸é ÁÁ°Ú½À´Ï´Ù ¤Ð

¶ÇÇÑ, ASLRȯ°æ¿¡¼­ ºÐ¸í libcÁÖ¼Òµµ ¹Ù²î¾î got entry¿¡ ¿Ã¶ó°¡´Â ÇÔ¼ö ÁÖ¼Òµµ Ç×»ó ¹Ù²ð°ÍÀε¥ ¿Ö gdb»ó¿¡¼­
got entry¸¦ run¹Ýº¹Çϸ鼭 º¸¸é ÁÖ¼Ò°¡ °è¼Ó ±×´ë·Î´øµ¥ ¿Ö±×·±°ÅÁÕ

  Hit : 2518     Date : 2017/04/12 04:31



    
vngkv123 syscallÀ» read·Î 1¹ÙÀÌÆ® ¿À¹ö¶óÀÌÆ® Çҽÿ¡ readÇÔ¼ö°¡ Å©±â¸¦ ¹ÝȯÇϱ⶧¹®¿¡ 1ÀÌ ¹ÝȯµÇ¼­ eax¿¡ 1ÀÌ ÀÖ´Â°Ç ¾Ë¾Ò½À´Ï´ç !! 2017/04/12  
ÇØÄð·¯ gdb¿¡¼­ ASLRÀ» ²ö »óÅ·Π½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù
https://outflux.net/blog/archives/2010/07/03/gdb-turns-off-aslr/
ÄÑÁø»óÅ¿¡¼­ µ¹¸®°í½ÍÀ¸½Ã¸é À§ ¸µÅ© Âü°íÇÏ½Ã¸é µË´Ï´Ù
2017/04/13  
1454   ¹öÆÛ¿À¹öÇÃ·Î¿ì °ü·Ã Áú¹®..[1]     ewqqw
04/17 2319
1453   ubuntu 16.04 UAF¹ö±×..[10]     vngkv123
04/16 3096
1452   gdb ºÐ¼® disas[5]     ewqqw
04/16 2122
1451   pwntools ¸¦ ÀÌ¿ëÇÑ Àͽº Áú¹®[6]     tkakr7458
04/16 7234
1450   ¹öÆÛ¿À¹öÇ÷οì Áú¹®....[2]     ewqqw
04/16 2272
1449   IDA¿¡¼­ ¼Ò½ºÄڵ带 º¹¿øÇßÀ»¶§[5]     vngkv123
04/13 3516
  aslr ȯ°æ¿¡¼­...[2]     vngkv123
04/12 2517
1447   asis CTF ¹®Á¦Ç®´Ù°¡....[4]     vngkv123
04/12 2233
1446   pwnable kr OTP¹®Á¦...[2]     vngkv123
04/09 2755
1445   64bit elfÆÄÀÏ µð¹ö±ë½Ã[6]     vngkv123
04/08 2485
1444   gdb¿¡¼­...[2]     vngkv123
04/05 2140
1443   ¹®Á¦ ¹æÇ⼺...[11]     vngkv123
04/04 2404
1442   2013 plaid ctf rop ..[14]     vngkv123
04/02 2454
1441   python Æä1À̷εå ÀÛ¼º½Ã[1]     vngkv123
04/02 1894
1440   ¿ë¾îµé Áú¹®..[6]     vngkv123
04/01 2338
1439   strippedµÈ ¹ÙÀ̳ʸ®ÆÄÀÏÀ» µð¹ö±ëÇÒ¶§...[5]     vngkv123
04/01 2511
1438   fc10 fc14...[1]     vngkv123
04/01 2043
1437   gdb¿¡¼­ callÀÌÈÄ ºê·¹ÀÌÅ©¸¦ °É¾úÀ»¶§..[10]     vngkv123
03/31 2003
1436   ¸®ÅÏ°ú °ü·ÃÇÑ Áú¹®....[9]     vngkv123
03/30 1938
1435   rop gadgetãÀ» ¶§....[1]     vngkv123
03/30 2111
[1][2][3][4][5][6] 7 [8][9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org