½Ã½ºÅÛ ÇØÅ·

 1574, 9/79 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ygw0225
   ½ºÅÿ¡ ASLRÀÌ °É·ÁÀÖÀ¸¸é...???

http://www.hackerschool.org/HS_Boards/zboard.php?id=QNA_system&no=1726 [º¹»ç]


ftz±¸ÃàÇؼ­ ·¹º§12¹ø ¹®Á¦ Ç®°íÀִµ¥¿ä
gdb·Î ÁÖ¼Ò È®ÀÎÇÏ·Á°í Çϴµ¥
È®ÀÎÇÒ¶§¸¶´Ù esp°ªÀÌ °è¼Ó¹Ù²î¾î¼­ retÁÖ¼Ò¸¦ ¸øã°Ú½À´Ï´Ù...

Àú¿Í°°ÀººÐÀÇ ±ÛÀÌ À־ ´äº¯À»º¸´Ï ½ºÅÿ¡ ASLRÀÌ °É·ÁÀִ°Ͱ°´Ù°í Çϼ̴µ¥
ÀÌ·²°æ¿ì ¾î¶»°Ô Çؾߵdzª¿ä?;
°¡¶àÀ̳ª ½©ÄÚµå°ø°ÝÇϴ°͵µ À߸ô¶ó¼­ Ã¥º¸¸é¼­ µû¶óÇÏ°íÀִµ¥
Ã¥±×´ë·ÎÇصµ ¾ÈµÇ´Ï Áøµµ¸¦¸ø³ª°¡°Ú³×¿ä ¤Ð¤Ð¤Ð¤Ð


0x08048470 <main+0>:        push   %ebp
0x08048471 <main+1>:        mov    %esp,%ebp
0x08048473 <main+3>:        sub    $0x108,%esp
0x08048479 <main+9>:        sub    $0x8,%esp
0x0804847c <main+12>:        push   $0xc15
0x08048481 <main+17>:        push   $0xc15
0x08048486 <main+22>:        call   0x804835c <setreuid>
0x0804848b <main+27>:        add    $0x10,%esp
0x0804848e <main+30>:        sub    $0xc,%esp
0x08048491 <main+33>:        push   $0x8048538
0x08048496 <main+38>:        call   0x804834c <printf>
0x0804849b <main+43>:        add    $0x10,%esp
0x0804849e <main+46>:        sub    $0xc,%esp
0x080484a1 <main+49>:        lea    0xfffffef8(%ebp),%eax
0x080484a7 <main+55>:        push   %eax
0x080484a8 <main+56>:        call   0x804831c <gets>
0x080484ad <main+61>:        add    $0x10,%esp
0x080484b0 <main+64>:        sub    $0x8,%esp
0x080484b3 <main+67>:        lea    0xfffffef8(%ebp),%eax
0x080484b9 <main+73>:        push   %eax
0x080484ba <main+74>:        push   $0x804854c
0x080484bf <main+79>:        call   0x804834c <printf>
0x080484c4 <main+84>:        add    $0x10,%esp
0x080484c7 <main+87>:        leave  
0x080484c8 <main+88>:        ret    
0x080484c9 <main+89>:        lea    0x0(%esi),%esi
0x080484cc <main+92>:        nop    
0x080484cd <main+93>:        nop    
0x080484ce <main+94>:        nop    
0x080484cf <main+95>:        nop    
End of assembler dump.
(gdb) b *0x080484bf    <--ºê·¹ÀÌÅ© °ÉÀ½
(gdb) r   <--- ½ÇÇà
Starting program: /home/level12/tmp/attackme
¹®ÀåÀ» ÀÔ·ÂÇϼ¼¿ä.
AAAA    <--- °ª ÀÔ·Â
Breakpoint 1, 0x080484bf in main ()
(gdb) x/12x $esp   <---esp °ª È®ÀÎ
0xbfffdfb0:        0x0804854c        0xbfffdfc0        0xbfffdfe0        0x00000001
0xbfffdfc0:        0x41414141       0x00000000        0x00000000  0x078e530f
0xbfffdfd0:        0xbfffe070          0x40015a38        0x0029656e  0x00000000
(gdb) r         <--- ´Ù½Ã ½ÇÇà
The program being debugged has been started already.
Start it from the beginning? (y or n) y
Starting program: /home/level12/tmp/attackme
¹®ÀåÀ» ÀÔ·ÂÇϼ¼¿ä.
AAAA

Breakpoint 1, 0x080484bf in main ()
(gdb) x/12x $esp  (°ª ´Þ¶óÁü)
0xbfffe6b0:        0x0804854c       0xbfffe6c0          0xbfffe6e0        0x00000001
0xbfffe6c0:        0x41414141       0x00000000       0x00000000        0x078e530f
0xbfffe6d0:        0xbfffe770        0x40015a38        0x0029656e        0x00000000
(gdb)

  Hit : 3820     Date : 2014/01/17 06:36



    
Deferto FTZ ±¸ÃàÀ» ³ôÀº Ä¿³Î ¹öÁ¯¿¡¼­ ÇϽŠ¸ð¾çÀÔ´Ï´Ù. ´ë·« 2.6ÀÌ»óÀÇ Ä¿³Î ¹öÁ¯¿¡¼­ºÎÅÍ ASLRÀÌ °É¸®¹Ç·Î ±× ÀÌÇÏ¿¡ Ä¿³Î¹öÀüÀ» °¡Áö°í ÀÖ´Â ¸®´ª½º·Î ±¸ÃàÇØÁÖ¼¼¿ä. ·¹µåÇÞ 6.2¸¦ ±¸ÇÏ½Ã¸é µÉ°Å °°½À´Ï´Ù. 2014/01/17  
cd80 /proc/sys/kernel/randomize_va_space ÆÄÀÏÀÌ ÀÖÀ¸¸é
echo 0 > /proc/sys/kernel/randomize_va_space¸¦ ÇÏ°í Çغ¸¼¼¿ä
2014/01/17  
ygw0225 ¿©±âȨÆäÀÌÁö¿¡ÀÖ´ø À̹ÌÁö¸¦ ¹Þ¾Æ¼­ ±¸ÃàÇß¾ú´Âµ¥ ¾Ë°íº¸´Ï ·¹µåÇÞ9.0ÀÌ´õ±º¿ä..
6.2·Î ´Ù½Ã ±¸ÃàÇß´õ´Ï Á¦´ë·Î µÇ³×¿ä^^ °¨»çÇÕ´Ï´Ù
2014/01/18  
1414   ½º¸¶Æ®ÆùÇØÅ·[3]     ykoy1577
06/16 3876
1413   ÇϾÆ.... µµÀúÈ÷ ¸ð¸£°Ú½À´Ï´Ù ¹ÌÃĹö¸±²¨°°³×¿ä Á¦¹ß µµ¿ÍÁÖ¼¼¿ä ¤Ð_¤Ð[13]     ykji1003
01/13 4167
1412   ÀüÈ­±â¿¡¼­ ±Ã±ÝÇÑ°Ô À־ ±×·¯´Âµ¥..[4]     YJG
09/19 3813
1411   ÀÌ°Å ¾îµð´Ù ½á¾ß ÇÒÁö ¸ô¶ó¼­ ½Ã½ºÅÛ ÇØÅ·¿¡¼­ ¹°¾îº¾´Ï´Ù.[2]     yj6393
07/31 3618
1410   À©Çí½º°¡ ¹¹¿¡¿ä?[1]     yj6393
07/29 3576
1409   v3´Â ÇÁ·Î±×·¥ÀÇ ¼Ò½ºÄڵ带 º¸°í Ä¡·áÇÏ´Â ÇÁ·Î±×·¥Àΰ¡¿ä?     yj6393
07/08 2939
1408   ¹ÙÀÌ·¯½ºµµ ÇÁ·Î±×·¥Àΰ¡¿ä?[3]     yj6393
07/06 3281
1407   [bof] ¹öÆÛ¿À¹öÇ÷οì Áú¹®ÀÌ¿ä ½ºÆ÷ÁÖÀ§[2]     yj6393
11/05 2928
1406   drive by download °ü·ÃÀÚ·á ã½À´Ï´Ù..[1]     yine01
11/04 3225
1405   µÇµµ¾Ê´Â Å©·¡Å· ¸»°í... ÇØÅ·¸»ÀÔ´Ï´Ù...[6]     yhs4489
08/28 3783
1404   Á¤º¸º¸¾ÈÀü¹®°¡ °¡ µÇ°í ½Í½À¤¤µð¤¿[4]     yh0473
05/30 3482
  ½ºÅÿ¡ ASLRÀÌ °É·ÁÀÖÀ¸¸é...???[3]     ygw0225
01/17 3819
1402   BOFÇÚµåºÏ ¸¶Áö¸·½Ç½À¹®Á¦ Áú¹®..[4]     ygw0225
01/08 3343
1401   Àú±â¿ä ±ÞÇÕ´Ï´Ù ¤Ì[2]     yenaghhi5
03/13 3800
1400   ½Ã½ºÅÛ ÇØÅ· Linux Ãʺ¸¿¡¼­ dumpÄڵ忡¼­ ¸·Çô¼­ Áú¹®µå¸³´Ï´Ù ¤Ð[1]     yelohair354
03/31 3863
1399   µµ¿ÍÁÖ¼¼¿ä ¤Ð¤Ð ¹öÆÛ ¿À¹öÇ÷οì...[2]     ydh1220
08/11 3303
1398   ¹öÆÛ¿À¹öÇ÷ο쿡 ´ëÇØ Áú¹®ÀÌ ÀÖ½À´Ï´Ù..     yangil06
05/14 3344
1397   ÈÞ´ëÆù ÇØÅ·[1]     ya2ho
08/17 4842
1396   ¾ÆÁ÷¹æÇâÀ» ¸øÀâ°Ù½À´Ï´Ù µµ¿òÁ» ºÎŹµå·Á¿ä ^^[5]     ya2ho
07/08 3517
1395   SQL ÀÎÁ§¼Ç ÁÁÀº °­ÀÇÁ»...[3]     xodnr631
08/25 3274
[1][2][3][4][5][6][7][8] 9 [10]..[79]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org