25, 1/1 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   ¸Û¸Û
   http://hackerschool.org
   mremap_bug.c (4.7 KB), Download : 231     [¿À¸¥ÂÊ ¹öÆ° ´­·¯ ´Ù¿î ¹Þ±â]
   do_mremap() Ãë¾àÁ¡ : Ãë¾àÁ¡ È®ÀÎ

http://www.hackerschool.org/HS_Boards/zboard.php?id=advisory&no=10 [º¹»ç]


Çö °Ô½Ã¹°¿¡ ÷ºÎµÈ À¯Æ¿¸®Æ¼¸¦ ÀÌ¿ëÇÏ¿© ¿î¿µÇÏ°í °è½Å
¼­¹öÀÇ do_mremap() Ãë¾àÁ¡ Á¸Àç ¿©ºÎ¸¦ ÆÇ´ÜÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
Ãë¾àÁ¡ÀÌ Á¸ÀçÇÒ °æ¿ì Ä¿³Î ¾÷±×·¹ÀÌµå °úÁ¤À» °ÅÃÄ ÆÐÄ¡¸¦
ÁøÇàÇϽðí, ÆÐÄ¡ ÈÄ¿¡µµ ÀÌ À¯Æ¿¸®Æ¼¸¦ ÀÌ¿ëÇÏ¿© ÆÐÄ¡ ¼º°ø ¿©ºÎ¸¦
È®ÀÎÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.

[Ãë¾àÁ¡ È®ÀÎ ÀýÂ÷]

1. ÷ºÎµÈ ¼Ò½º¸¦ º¹»çÇϽðųª FTP µîÀ¸·Î ÇØ´ç ¼­¹ö¿¡ ¾÷·Îµå
   ÇϽŠÈÄ ÄÄÆÄÀÏÀ» ÇÕ´Ï´Ù.

[root@work root]# cat > mremap_check.c
... ºÙ¿©³Ö±â ...
[Ctrl+D]
[root@work root]# gcc -o mremap_check mremap_check.c
[root@work root]#

2. ÇÁ·Î±×·¥ ½ÇÇà

[root@work root]# ./mremap_check

Base address : 0x60000000

08048000-08049000 r-xp 00000000 03:02 294572     /root/mremap_check
08049000-0804a000 rw-p 00000000 03:02 294572     /root/mremap_check
40000000-40015000 r-xp 00000000 03:02 3482984    /lib/ld-2.3.2.so
40015000-40016000 rw-p 00014000 03:02 3482984    /lib/ld-2.3.2.so
40016000-40018000 rw-p 00000000 00:00 0
40022000-40155000 r-xp 00000000 03:02 3482991    /lib/libc-2.3.2.so
40155000-40159000 rw-p 00132000 03:02 3482991    /lib/libc-2.3.2.so
40159000-4015b000 rw-p 00000000 00:00 0
60000000-60002000 rw-p 00000000 00:00 0
bfffd000-c0000000 rwxp ffffe000 00:00 0

Remapping at 0x70000000...

08048000-08049000 r-xp 00000000 03:02 294572     /root/mremap_check
08049000-0804a000 rw-p 00000000 03:02 294572     /root/mremap_check
40000000-40015000 r-xp 00000000 03:02 3482984    /lib/ld-2.3.2.so
40015000-40016000 rw-p 00014000 03:02 3482984    /lib/ld-2.3.2.so
40016000-40018000 rw-p 00000000 00:00 0
40022000-40155000 r-xp 00000000 03:02 3482991    /lib/libc-2.3.2.so
40155000-40159000 rw-p 00132000 03:02 3482991    /lib/libc-2.3.2.so
40159000-4015b000 rw-p 00000000 00:00 0
60000000-60002000 rw-p 00000000 00:00 0
bfffd000-c0000000 rwxp ffffe000 00:00 0

Report :
This kernel appears to be NOT VULNERABLE

[root@work root]#

À§Ã³·³ NOT VULNRABLE À̶ó°í Ãâ·ÂµÉ °æ¿ì Ãë¾àÇÏÁö ¾ÊÀº Ä¿³ÎÀ»
»ç¿ëÇÏ°í °è½ÉÀ¸·Î ÆÐÄ¡¸¦ ÇÏ½Ç ÇÊ¿ä°¡ ¾ø½À´Ï´Ù.
¹Ý¸é¿¡, Ãë¾àÁ¡ÀÌ Á¸ÀçÇÒ °æ¿ì¿£ ´ÙÀ½°ú °°Àº ¸Þ½ÃÁö°¡ Ãâ·ÂµË´Ï´Ù.

Report :
This kernel appears to be VULNERABLE

ÀÌ °æ¿ì¿£ ÆÐÄ¡¸¦ ÁøÇàÇϽʽÿä.

Âü°í·Î ÷ºÎµÈ üũ ÇÁ·Î±×·¥Àº ¼­¹ö¿¡ ¾î¶°ÇÑ ¾Ç¿µÇâµµ ¹ÌÄ¡Áö ¾ÊÀ½À¸·Î
¾È½ÉÇÏ°í »ç¿ëÇϼŵµ µË´Ï´Ù.


[Ãë¾àÁ¡ ÇÇÇØ]
[Ãë¾àÁ¡ ºÐ¼®]
[Ãë¾àÁ¡ ÆÐÄ¡]

  Hit : 3474     Date : 2004/01/27 01:37



    
DarkSlayer ³­ ¾ø´Ù°í ³ª¿À³× -0- 2.4.22-12 Àε¥... ÀÌ°Å ÀÌÇϹöÀü¿¡¼­´Â ÀÖ´Ù°í ³ª¿Ã¶ó³ª;; 2004/01/29
25   setsockopt() Ãë¾àÁ¡ : ¹æ¾î ¸ðµâÀ» ÀÌ¿ëÇÑ ÆÐÄ¡[1]     ¸Û¸Û
05/20 3438
24   setsockopt() Ãë¾àÁ¡ : Ä¿³Î ¾÷±×·¹À̵带 ÅëÇÑ ÆÐÄ¡[5]     ¸Û¸Û
05/20 3186
23   setsockopt() Ãë¾àÁ¡ : Ãë¾àÁ¡ ÆÐÄ¡     ¸Û¸Û
05/20 3556
22   setsockopt() Ãë¾àÁ¡ : Ãë¾àÁ¡ ºÐ¼®     ¸Û¸Û
05/20 5123
21   setsockopt() Ãë¾àÁ¡ : °ø°ÝÀÇ ÇÇÇØ     ¸Û¸Û
05/20 3765
20   setsockopt() Ãë¾àÁ¡ : °ø°ÝÀÇ ´ë»ó[4]     ¸Û¸Û
05/20 4453
19   [5¿ù 20ÀÏ] 2.6.3°ú 2.4.25 ÀÌÇÏ ¸®´ª½º Ä¿³ÎÀÇ setsockopt ½Ã½ºÅÛ ÄÝ Ãë¾àÁ¡[5]     ¸Û¸Û
05/20 9255
18   do_mremap() Ãë¾àÁ¡ 2 : Ãë¾àÁ¡ ÆÐÄ¡[1]     ¸Û¸Û
03/16 3356
17   do_mremap() Ãë¾àÁ¡ 2 : Ãë¾àÁ¡ ºÐ¼®[4]     ¸Û¸Û
03/16 3580
16   do_mremap() Ãë¾àÁ¡ 2 : Ãë¾àÁ¡ ÇÇÇØ     ¸Û¸Û
03/16 3387
15   do_mremap() Ãë¾àÁ¡ 2 : °ø°ÝÀÇ ´ë»ó[2]     ¸Û¸Û
03/16 3365
14   [3¿ù 1ÀÏ] ¸®´ª½º Ä¿³Î do_mremap ³»ºÎ ÇÔ¼öÀÇ ¶Ç ´Ù¸¥ Ãë¾àÁ¡.     ¸Û¸Û
03/15 5057
13   do_mremap() Ãë¾àÁ¡ : Ãë¾àÁ¡ ÆÐÄ¡[8]     ¸Û¸Û
01/27 3646
12   do_mremap() Ãë¾àÁ¡ : Ãë¾àÁ¡ ºÐ¼®     ¸Û¸Û
01/27 4072
11   do_mremap() Ãë¾àÁ¡ : °ø°ÝÀÇ ÇÇÇØ     ¸Û¸Û
01/27 3434
  do_mremap() Ãë¾àÁ¡ : Ãë¾àÁ¡ È®ÀÎ[1]     ¸Û¸Û
01/27 3473
9   do_mremap() Ãë¾àÁ¡ : °ø°ÝÀÇ ´ë»ó     ¸Û¸Û
01/27 4018
8   [1¿ù 15ÀÏ] ¹öÀü 2.4.23 & 2.6.0 ÀÌÇÏ ¸®´ª½º Ä¿³ÎÀÇ do_mremap() Ãë¾àÁ¡[1]     ¸Û¸Û
01/27 7394
7   do_brk() Ãë¾àÁ¡ : ¹æ¾î ¸ðµâÀ» ÀÌ¿ëÇÑ ÆÐÄ¡[3]     ¸Û¸Û
12/17 4019
6   do_brk() Ãë¾àÁ¡ : Ä¿³Î ¾÷±×·¹À̵带 ÅëÇÑ ÆÐÄ¡     ¸Û¸Û
12/17 3809
5   do_brk() Ãë¾àÁ¡ : Ãë¾àÁ¡ ÆÐÄ¡[3]     ¸Û¸Û
12/17 4411
4   do_brk() Ãë¾àÁ¡ : Ãë¾àÁ¡ ºÐ¼®[1]     ¸Û¸Û
12/17 6332
3   do_brk() Ãë¾àÁ¡ : °ø°ÝÀÇ ÇÇÇØ     ¸Û¸Û
12/17 4602
2   do_brk() Ãë¾àÁ¡ : °ø°ÝÀÇ ´ë»ó     ¸Û¸Û
12/17 4992
1   [12¿ù 17ÀÏ] ¹öÀü 2.4.22 ÀÌÇÏ ¸®´ª½º Ä¿³ÎÀÇ do_brk() Ãë¾àÁ¡[2]     ¸Û¸Û
12/17 7537
1

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org