ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level14: Bugbear >> Giant

Level 14. Bugbear >> Giant Theme: RTL ๋กœ๊ทธ์ธ id : bugbear pw : new divide bash2 & ์ฝ”๋“œํ™•์ธ 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - giant 4 - RTL2 5 */ 6 #include 7 #include 8 #include 9 main(int argc, char *argv[]) 10 { 11 char buffer[40]; 12 FILE *fp; 13 char *lib_addr, *execve_offset, *execve_addr; 14 char *ret; 15 if(argc < 2){ 16 printf("argv error\n"); 17 exit(0); 18 } 19 // gai..

2020.08.02 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level13: Darkknight >> Bugbear

Level 13. Darkknight >> Bugbear Theme: RTL ๋กœ๊ทธ์ธ id : darkknight pw : new attacker bash2&์ฝ”๋“œํ™•์ธ [darkknight@localhost darkknight]$ bash2 [darkknight@localhost darkknight]$ nl bugbear.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - bugbear 4 - RTL1 5 */ 6 #include 7 #include 8 main(int argc, char *argv[]) 9 { 10 char buffer[40]; 11 int i; 12 if(argc < 2){ 13 printf("argv error\n"); 14 ex..

2020.07.31 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level12: Golem >> Darkknight

Level 12. Golem >> Darkknight Theme: FPO ๋กœ๊ทธ์ธ id : golem pw : cup of coffee bash2 & ์ฝ”๋“œํ™•์ธ [golem@localhost golem]$ bash2 [golem@localhost golem]$ nl darkknight.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - darkknight 4 - FPO 5 */ 6 #include 7 #include 8 void problem_child(char *src) 9 { 10 char buffer[40]; 11 strncpy(buffer, src, 41); 12 printf("%s\n", buffer); 13 } 14 main(int argc..

2020.07.31 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level11: Skeleton >> Golem

Level 11. Skeleton >> Golem Theme: Stack Destroyer ๋กœ๊ทธ์ธ id : skeleton pw : shellcoder bash2 & ์ฝ”๋“œ ํ™•์ธ [skeleton@localhost skeleton]$ ls golem golem.c [skeleton@localhost skeleton]$ bash2 [skeleton@localhost skeleton]$ nl golem.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - golem 4 - stack destroyer 5 */ 6 #include 7 #include 8 extern char **environ; 9 main(int argc, char *argv[]) 10 {..

2020.07.26 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level10: Vampire >> Skeleton

Level 10. Vampire >> Skeleton Theme: argv hunter ๋กœ๊ทธ์ธ id : vampire pw : music world bash2 & ์ฝ”๋“œํ™•์ธ [vampire@localhost vampire]$ bash2 [vampire@localhost vampire]$ nl skeleton.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - skeleton 4 - argv hunter 5 */ 6 #include 7 #include 8 extern char **environ; 9 main(int argc, char *argv[]) 10 { 11 char buffer[40]; 12 int i, saved_argc; 13 if(argc..

2020.07.26 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level8: Orge >> Troll

Level 8. Orge >> Troll Theme: Check argc + argv hunter ๋กœ๊ทธ์ธ id : orge pw : timewalker bash2 ์ž…๋ ฅํ•ด์ฃผ์‹œ๊ณ , ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ด…์‹œ๋‹ค. [orge@localhost orge]$ bash2 [orge@localhost orge]$ nl troll.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - troll 4 - check argc + argv hunter 5 */ 6 #include 7 #include 8 extern char **environ; 9 main(int argc, char *argv[]) 10 { 11 char buffer[40]; 12 int i; 13 // here i..

2020.07.25 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level7: Darkelf >> Orge

Level 7. Darkelf >> Orge Theme: Check argv[0] (Symbolic Link) ๋กœ๊ทธ์ธ id: darkelf pw: kernel crashed bash2 ํ•„์ˆ˜ํ•„์ˆ˜~ [darkelf@localhost darkelf]$ bash2 [darkelf@localhost darkelf]$ nl orge.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - orge 4 - check argv[0] 5 */ 6 #include 7 #include 8 extern char **environ; 9 main(int argc, char *argv[]) 10 { 11 char buffer[40]; 12 int i; 13 if(argc < 2)..

2020.07.19 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

๋‚˜์˜ ๊ณ ํ˜ˆ์••๊ฑธ๋ฆฌ๋Š” ์—๋Ÿฌ์ผ๊ธฐ

[PuTTY/LOB] "Stack is still your friend"; ๋ถ„๋ช… ๋งž๋Š” ํŽ˜์ด๋กœ๋“œ๋ฅผ ์งฐ๋Š”๋ฐ ํ‹€๋ ธ์„ ๋•Œ

LOB๋ฅผ ํ’€๋‹ค๋ณด๋ฉด Segmentation Fault๋„ ์•„๋‹ˆ๊ณ  "stack is still your friend"๊ฐ€ ๋œฐ ๋•Œ๊ฐ€ ์žˆ๋‹ค. ๊ฒฐ๋ก ๋ถ€ํ„ฐ ์–˜๊ธฐํ•˜๋ฉด bash2์ž…๋ ฅํ•˜์„ธ์š”. ์ž ๊ฐˆ๊ธธ๊ฐˆ์‚ฌ๋žŒ๋“ค์€ ๊ฐ€์‹œ๊ณ  "์™œ?"๊ฐ€ ๊ถ๊ธˆํ•˜์‹  ๋ถ„๋“ค์€ ๋‚˜๋จธ์ง€ ๊ธ€์„ ์ฝ์์‹œ๋‹ค. ์•„๋‹ˆ ๋‚œ ์Šคํƒ ์ž˜ ๋งž์ถฐ์คฌ๋Š”๋ฐ ๋„๋Œ€์ฒด ๋ญ๊ฐ€ ๋ฌธ์ œ์ง€? gdb๋กœ ํ•œ๋ฒˆ ๋ถ„์„์„ ํ•ด๋ด…์‹œ๋‹ค. ๋ฌธ์ œ๋Š” lob wolfman ์ผ๋ถ€๋ฅผ ๊ฐ€์ ธ์™”์Šต๋‹ˆ๋‹ค. [orc@localhost orc]$ gdb -q lolfman (gdb) disas main Dump of assembler code for function main: 0x8048500 : push %ebp 0x8048501 : mov %esp,%ebp 0x8048503 : sub $0x2c,%esp 0x8048506 : cmpl ..

2020.07.16 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level3: cobolt >> goblin

Level 3. Cobolt >> Goblin Theme: Basic BufferOverFlow (w/ stdin) ๋กœ๊ทธ์ธํ•ฉ์‹œ๋‹ค id: cobolt pw: hacking exposed ls -l๋กœ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ํ™•์ธํ•˜๋ฉด ์—ญ์‹œ๋‚˜ [cobolt@localhost cobolt]$ ls -l total 16 -rwsr-sr-x 1 goblin goblin 11824 Feb 26 2010 goblin -rw-r--r-- 1 root root 193 Mar 29 2010 goblin.c [cobolt@localhost cobolt]$ nl goblin.c 1 /* 2 The Lord of the BOF : The Fellowship of the BOF 3 - goblin 4 - small buffer + stdin 5..

2019.09.24 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level2: gremlin >> cobolt

Level 2. Gremlin >> Cobolt Theme: Basic BufferOverFlow (smaller buffer) ๋“ค์–ด๊ฐ‘์‹œ๋‹ค. id: gremlin pw: hello bof world ๊ธฐ๋ณธ bash2์ž…๋ ฅ ํ›„, ls -l๋กœ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ํ™•์ธํ•ด์ฃผ๋ฉด [gremlin@localhost gremlin]$ bash2 [gremlin@localhost gremlin]$ ls -l total 20 -rwsr-sr-x 1 cobolt cobolt 11970 Feb 26 2010 cobolt -rw-r--r-- 1 gremlin gremlin 291 Mar 29 2010 cobolt.c cobolt.cํŒŒ์ผ์„ ์—ด์–ด๋ณด๋ฉด [gremlin@localhost gremlin]$ nl cobolt.c 1 /* 2 The ..

2019.09.24 ๊ฒŒ์‹œ๋จ

 ํฌ์ŠคํŒ… ์ธ๋„ค์ผ ์ด๋ฏธ์ง€

War Games/ํ•ด์ปค์Šค์ฟจ LOB

[ํ•ด์ปค์Šค์ฟจ LOB] Level1: gate >> gremlin

Level 1. Gate >> Gremlin Theme: Basic BufferOverFlow LOB์— ์˜ค์‹  ์—ฌ๋Ÿฌ๋ถ„๋“ค ํ™˜์˜ํ•ฉ๋‹ˆ๋‹ค! ์šฐ์„  ๋“ค์–ด๊ฐ€์ค์‹œ๋‹ค. id: gate pw: gate ์•„ ์ผ๋‹จ ์ฒซ ๋ฌธ์ œ์ธ ๋งŒํผ, ์šฐ๋ฆฌ๊ฐ€ ์ด ๋ฌธ์ œ๋ฅผ ์™œ ํ’€๊ณ ์žˆ์œผ๋ฉฐ, ์–ด๋–ป๊ฒŒ ํ•˜๋ฉด ์ด ๋ฌธ์ œ๋ฅผ ํ’€ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ธ์ง€ ํƒ๊ตฌํ•ด๋ด…์‹œ๋‹ค. ์ผ๋‹จ ํฌ๋„ˆ๋ธ” ๋ฌธ์ œ๋“ค์˜ ๊ธฐ๋ณธ์€ ๊ด€๋ฆฌ์ž์˜ ๊ถŒํ•œ์„ ํƒˆ์ทจํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋’ค ์ •์ƒ์ ์œผ๋กœ๋Š” ์ ‘๊ทผํ•  ์ˆ˜ ์—†๋Š” ๊ณณ๋“ค์„ ์ ‘๊ทผํ•œ๋‹ค๋Š” ๊ฒƒ์ด ๊ธฐ๋ณธ์ ์ธ ์‹œ์Šคํ…œ ํ•ดํ‚น์˜ ๊ฐœ๋…์ด๊ณ ์š”. ๊ทธ๋ž˜์„œ ๋˜‘๊ฐ™์ด LOB์˜ ๋ชจ๋“  ๋ฌธ์ œ๋“ค๋„ ์ƒ์œ„ ๊ถŒํ•œ์„ ํš๋“ํ•˜์—ฌ ๋‹ค์Œ ๋‹จ๊ณ„์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์•Œ์•„๋‚ด๋Š” ๊ฒƒ์ด ๋ชฉ์ ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฉด LOB ๋ฌธ์ œ์˜ ํ๋ฆ„์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค. 1. ํ”„๋กœ๊ทธ๋žจ์ƒ์˜ ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ•ฉ๋‹ˆ๋‹ค. 2. ์ทจ์•ฝ์ ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ๊ณต๊ฒฉ ์‹œ๋‚˜๋ฆฌ์˜ค๋ฅผ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค. 3...

2019.09.18 ๊ฒŒ์‹œ๋จ