http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1506 [º¹»ç]
Á¦°¡ ÇØÄ¿½ºÄ𠼿ÄÚµå ¸¸µé±â °Á Áß ÇϳªÀΰŰ°Àº°Å¸¦ º¸°í µû¶ó°¡´Âµ¥..
(ÁÖ¼Ò : http://research.hackerschool.org/Datas/Research_Lecture/sc_making.txt)
½©ÄÚµå ¸¸µé±â ºÎºÐ¿¡¼ ¾î¼ÀÀ¸·Î ÀÛ¼ºÇÏ´Â ºÎºÐ Áï
1 .globl main
2 main :
3 jmp come_here
4 func :
5 movl $0x0b, %eax
6 popl %ebx
7 movl %ebx, (%esi)
8 movl $0x00, 0x4(%esi)
9 leal (%esi), %ecx
10 movl $0x00, %edx
11 int $0x80
12
13 movl $0x01, %eax
14 movl $0x00, %ebx
15 int $0x80
16 come_here :
17 calll func
18 .string "/bin/sh\00"
À̺κР¤Ì¤Ì
±× °Á¿¡ ³ª¿Â ±×´ë·Î Ãƴµ¥
¼¼±×ÆúÀÌ ¶ß´õ¶ó°í¿ä..
±×·¡¼ gdb·Î ¾îµð¼ ¶ß´ÂÁö ºÃ´õ´Ï
7 movl %ebx, (%esi)
ÀÌ ºÎºÐ¿¡¼ ¶ß±æ·¡ info reg esi Çؼ ºÃ´õ´Ï esiÀÇ ÁÖ¼Ò°¡ ³ÎÀΰŰ°¾Ò¾î¿ä..
(±¸±Û¿¡¼ info reg º¸´Â¹ý¿¡ ´ëÇؼ °Ë»öÇغôµ¥ Àß ¸øã°Ú´õ¶ó°í¿ä ¤Ì¤Ì)
±×·¡¼ movlÀ» ÀÌ¿ëÇؼ esi¿¡ ÁÖ¼Ò¸¦ ³Ö¾îÁÖ°í ÇØ”f´Âµ¥µµ ¾ÈµÅ°í..
Á¦¹ß ¾Ë·ÁÁÖ¼¼¿ä ¤Ì¤Ì À̰Ŷ§¸Å ´ä´äÇØ ¹ÌÄ¡°Ú¾î¿ä..
|
Hit : 2705 Date : 2011/07/24 03:38
|