½Ã½ºÅÛ ÇØÅ·

 1574, 79/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   zipds
   http://forwardteam.byus.net
   ½©ÄÚµå Á¦ÀÛ¿¡ µµ¿òÀ» ¾ò°íÀÚ ÇÕ´Ï´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=11 [º¹»ç]


BOF °øºÎÁß¿¡ ½©ÄÚµå Á¦ÀÛÀ» Çغ¸°íÇ ¸¶À½¿¡ ¸î°¡Áö ÀڷḦ ã¾Æº¸°í Áú¹®ÇÕ´Ï´Ù.

NULL@ROOT¿¡¼­ willy´ÔÀÇ ½©ÄÚµåÁ¦ÀÛ°­ÁÂ¿Í 'hacker4uÀÇ ÇØÅ· º¸¾È³ëÆ®(ÀÌÇÏh4)'µÎ°³·Î °øºÎ¸¦ ÇÏ°í Àִµ¥...

¾î¼Àºí¸®¾î¸¦ ÀÍÈ÷Áö ¾ÊÀº Å¿¿¡ Á» Èûµç°¨ÀÌ ÀÖ½À´Ï´Ù.

-----------------------------------------------------
//¼Ò½º
#include <stdio.h>

void main()
{

        char *name[2];

        name[0]="/bin/bash";
        name[1]=0x0;

        execve(name[0],name,name[1]);
}
---------------------------------------------------
//gdb

(gdb) disassemble main
Dump of assembler code for function main:
0x8048400 <main>:       push   %ebp
0x8048401 <main+1>:     mov    %esp,%ebp
0x8048403 <main+3>:     sub    $0x8,%esp
0x8048406 <main+6>:     movl   $0x8048498,0xfffffff8(%ebp)
0x804840d <main+13>:    movl   $0x0,0xfffffffc(%ebp)
0x8048414 <main+20>:    sub    $0x4,%esp
0x8048417 <main+23>:    pushl  0xfffffffc(%ebp)
0x804841a <main+26>:    lea    0xfffffff8(%ebp),%eax
0x804841d <main+29>:    push   %eax
0x804841e <main+30>:    pushl  0xfffffff8(%ebp)
0x8048421 <main+33>:    call   0x80482d0 <execve>
0x8048426 <main+38>:    add    $0x10,%esp
0x8048429 <main+41>:    leave
0x804842a <main+42>:    ret
0x804842b <main+43>:    nop
0x804842c <main+44>:    nop
0x804842d <main+45>:    nop
0x804842e <main+46>:    nop
0x804842f <main+47>:    nop
End of assembler dump.
(gdb) disassemble execve
Dump of assembler code for function execve:
0x80482d0 <execve>:     jmp    *0x80495a0
0x80482d6 <execve+6>:   push   $0x8
0x80482db <execve+11>:  jmp    0x80482b0 <_init+24>
End of assembler dump.
(gdb)
------------------------------------------------------------------------
*¼Ò½ºÃâÀú´Â h4ÀÔ´Ï´Ù
*gdb·Î µð½º¾î¼Àºí ÇÑ °ÍÀº FTZ¿¡¼­ ÄÄÆÄÀÏÇؼ­ µð½º¾î¼Àºí ÇÑ°ÍÀÔ´Ï´Ù.
-----------------------------------------------------------------------
Ã¥¿¡ ³ª¿Â°Í°ú´Â Â÷ÀÌ°¡ ÀÖ½À´Ï´Ù.

Â÷ÀÌ°¡ ÀÖ´Â ÀÌÀ¯´Â ¹«¾ùÀΰ¡¿ä?

²À ¾î¼Àºí¸®¾î¸¦ ÀÍÇô¾ß Çմϱî? ÀÍÈ÷Áö ¾Ê°í¼­µµ Á¦ÀÛ°úÁ¤¸¸ ÀÍÇôµÎ¸é ½©Äڵ带 ¸¸µé ¼ö ÀÖÁö ¾ÊÀ»±î¿ä?

¾î¼Àºí¸®¾î¸¦ ÀÍÈ÷±â À§Çؼ­ Âü°íÇغ¼¸¸ÇÑ ¹®¼­°¡ ÀÖ´Ù¸é ÃßõÇØÁÖ¼ÌÀ¸¸é ÇÕ´Ï´Ù.

  Hit : 6032     Date : 2003/09/13 10:37



    
indra 1. OS, ÄÄÆÄÀÏ·¯ µî¿¡ ȯ°æ¿¡ µû¶ó ¹ÙÀ̳ʸ® µð½º¾î¼Àºí °á°ú¿¡ Â÷ÀÌ°¡ ÀÖÀ»¼ö ÀÖ½À´Ï´Ù. 2003/09/13  
indra 2. ³×. ÀÍÇô¾ß ÇÕ´Ï´Ù. Á¦ÀÛ°úÁ¤¸¸ ÀÍÇôµÐ´Ù´Â ¸»Àº »§¿¡ ³Ö´Â ¿ø·á°¡ ¹ºÁöµµ ¸ð¸£¸é¼­ ¿Àºì¿¡ ±¸¿ì¸é »§ÀÌ µÈ´Ù°í »ý°¢Çϴ°Ͱú °°½À´Ï´Ù. 2003/09/13  
indra 3. ±¸±Û °Ë»ö ¿£ÁøÀ» È°¿ëÇÏ°í.. Á¦ÀÏ Áß¿äÇÑ°ÍÀº Á÷Á¢ ½Ç½ÀÇϴ°ÍÀÔ´Ï´Ù.. ½Ç¹«°æÇ躸´Ù ÁÁÀº ¸Å´º¾óÀº ¼¼»ó¿¡ ¾ø½À´Ï´Ù. 2003/09/13  
indra Âü°í·Î ¾î¼Àºí¸®¾î¸¦ ¿ÏÀüÈ÷ ´Ù ÀÍÈ÷Áö´Â ¾Ê¾Æµµ Àû¾îµµ ¿øÇÏ´Â °á°ú¹°À» ¸¸µé¾î ³¾¼ö ÀÖ¾î¾ß °ÚÁö¿ä. 2003/09/13  
¼ÒÀ¯ Àεå¶ó´Ô ¯~! 2003/09/14  
asdf Á¦ÀÛ°úÁ¤¸¸ ÀÍÇô¼­ ½©Äڵ带¸ðÇÏ·¯ ¸¸µå³ª¿ä? ÀÌ¹Ì ¸¸µé¾î³ëÀº ½©Äڵ尡 Àִµ¥.. ¾î¼ÀêÀ¸·Î °øºÎÇϴ°͵µ ÁÁ°í ¿ª¾î¼À Çϸ鼭 ÀÍÈ÷´Â°Íµµ.. -¤µ-;; 2003/09/14
aiurchar ¾î¼À °øºÎÇϼ¼¿ä.¤¾¤¾ 2003/09/14  
ÆíÁýÈı⠸޸𸮿¡´ëÇØ ¿¬±¸¸¦ Çغ¸½ÉÀÌ... 2003/09/23
14   root ºñ¹ø ¶§¹®¿¡[1]     kimjh22200
09/15 5197
13     [re] root ºñ¹ø ¶§¹®¿¡[4]     hkpco
09/16 5647
  ½©ÄÚµå Á¦ÀÛ¿¡ µµ¿òÀ» ¾ò°íÀÚ ÇÕ´Ï´Ù.[8]     zipds
09/13 6031
11   win 2000 professional log on lock°É¸°°Í Ç®¼öÀÖ³ª¿ä?[3]     cougar
09/13 4539
10     [re] win 2000 professional log on lock°É¸°°Í Ç®¼öÀÖ³ª¿ä?     ´õºíº£À̽º
09/20 4337
9   º¯¼öÇü¿¡ µû¶ó¼­ bof ÇϱⰡ ´Þ¶óÁö³ª¿ä?[1]     yl
09/12 5534
8     [re] º¯¼öÇü¿¡ µû¶ó¼­ bof ÇϱⰡ ´Þ¶óÁö³ª¿ä?     hkpco
09/13 4674
7   localÀº ¹¹¿¡¿ä.. ±×¸®°í localhost´Â ¹¹¿¡¿ä?[4]     jgminam
09/11 6705
6     [re] localÀº ¹¹¿¡¿ä.. ±×¸®°í localhost´Â ¹¹¿¡¿ä?     ¼ÒÀ¯
09/13 6558
5   Àúµµ bof ±¸Á¶ °ü·Ã Áú¹® ÀÔ´Ï´Ù.     jgminam
09/10 5937
4     [re] Àúµµ bof ±¸Á¶ °ü·Ã Áú¹® ÀÔ´Ï´Ù.[3]     oread99
09/11 5136
3     [re] Àúµµ bof ±¸Á¶ °ü·Ã Áú¹® ÀÔ´Ï´Ù.[1]     hkpco
09/10 4733
2     [re] Àúµµ bof ±¸Á¶ °ü·Ã Áú¹® ÀÔ´Ï´Ù.[2]     ¼ÒÀ¯
09/10 5168
1   bof°ü·Ã ¹öÆÛ±¸Á¶ Áú¹®ÀÓ´Ù.(Ãʺ¸)[10]     esang72
09/04 6765
[1]..[71][72][73][74][75][76][77][78] 79

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org