http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=3 [º¹»ç]
>bof¿¡¼ RETºÎºÐ¿¡´Ù°¡ ½©ÀÌ À§Ä¡ÇÑ °æ·Î¸¦ ¾²¶ó°í µé¾ú´Âµ¥¿ä.
>
>RETºÎºÐ¿¡´Â 4¹ÙÀÌÆ® ¹Û¿¡ ¾µ¼ö°¡ ¾øÀݾƿä.
>
>±Ùµ¥ ¾î¶»°Ô ½©ÀÌ À§Ä¡ÇÑ °æ·Î¸¦ ¾µ¼ö°¡ ÀÖ´ÂÁö ±Ã±ÝÇÕ´Ï´Ù.
>
>Ȥ½Ã °æ·Î°¡ /bin/bash/ABCshell.c ÀÌ·±½ÄÀÌ ¾Æ´Ï¶ó ¹«½¼ ´Ù¸¥½ÄÀÇ °æ·Î°¡ µû·Î ÀÖ´Â
>
>Áö..
>
>Á¦°¡ bof¿¡ °üÇØ À߸ø ÀÌÇØÇÏ°í Àִ°Š°°Àºµ¥..
>
>¾Æ¹«Æ° ¾î¶»°Ô ÇؾߵŴÂÁö ¾Ë·ÁÁÖ¼¼¿ä.
±×°Í(=shellcode)¸¦ ¸¸µé±â À§ÇÑ ¹æ¹ýÀ» ¹è¿ì±â À§ÇØ ÇÊ¿äÇÑ °ÍÀº ´ÙÀ½°ú °°´Ù:
- -static flag¸¦ »ç¿ëÇÏ¿© ÇÁ·Î±×·¥À» ÄÄÆÄÀÏ ÇØ¾ß ÇÑ´Ù.
- gdb¸¦ ¿¾î¼ "disassemble main"À̶ó´Â ¸í·É¾î¸¦ »ç¿ëÇÑ´Ù.
- ¸ðµç ÇÊ¿äÇÑ ÄÚµåºÎºÐÀ» °¡Á®¿Â´Ù.(¹®¼ ¿ÀŸ °°À½: unnecessary°¡ necessary°¡
µÇ¾ß Çϴ°Š°°À½)
- ±×°ÍÀ» ASMÀ¸·Î ´Ù½Ã ÀÛ¼ºÇÑ´Ù.
- ÄÄÆÄÀÏ ÇѵÚ, gdb·Î½á ±×°ÍÀ» ¿°í "disassemble main"À̶õ ¸í·É¾î¸¦ »ç¿ëÇÑ´Ù.
- ¸í·É¾î ÁÖ¼Ò¿¡ x/bx ¸í·É¾î¸¦ »ç¿ëÇÏ°í hex-code¸¦ °¡Á®¿Â´Ù.
XXXXXXXXXXX
X WAKE UP X
XXXXXXXXXXX
ÀÌ·± ½©Äڵ带 ¾òÀ» ¼ö ÀÖÀ» ²¯ÀÌ´Ù.
char shellcode[]=
"\xeb\x1f\x5e\x89\x76\x08\x31\xc0\x88\x46\x07\x89\x46\x0c\xb0\x0b"
"\x89\xf3\x8d\x4e\x08\x8d\x56\x0c\xcd\x80\x31\xdb\x89\xd8\x40\xcd"
"\x80\xe8\xdc\xff\xff\xff/bin/sh";
|
Hit : 5169 Date : 2003/09/10 03:05
|