Exploit

Exploit pwntool์˜ checksec ๋ช…๋ น์–ด๋กœ ์–ด๋–ค ๋ณด์•ˆ์ด ์ ์šฉ๋˜์—ˆ๋Š”์ง€ ํ™•์ธ ๊ฐ€๋Šฅํ•˜๋‹ค. Shell Code exploit์€ ํŒŒ์ผ ์ฝ๊ณ  ์“ฐ๊ธฐ(open-read-write, orw), ์…ธ ๋ช…๋ น ์‹คํ–‰(execve) ๊ถŒํ•œ์„ ์ทจ๋“ํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•œ๋‹ค. Shell ๊ถŒํ•œ์„ ํš๋“ํ•˜๊ธฐ ์œ„ํ•œ ์–ด์…ˆ๋ธ”๋ฆฌ ์ฝ”๋“œ๋“ค์˜ ๋ชจ์Œ์„ โ€˜Shell Codeโ€™ ๋ผ ์นญํ•œ๋‹ค. ํ™˜๊ฒฝ์„ธํŒ… pwntools checksec shellcraft ROPgadget one_gadget patchelf ์ทจ์•ฝ์  ๊ณต๊ฒฉ ์ˆœ์„œ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•˜์—ฌ ๋ณดํ˜ธ๊ธฐ๋ฒ•์„ ํ™•์ธํ•œ๋‹ค. checksec ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐ”์ด๋„ˆ๋ฆฌ์— ์ ์šฉ๋œ ๋ณดํ˜ธ๊ธฐ๋ฒ•์„ ํ™•์ธํ•˜๊ณ , ์ ์šฉ ๋ถˆ๊ฐ€๋Šฅํ•œ exploit ๊ธฐ๋ฒ•์„ ์ถ”๋ ค๋‚ธ๋‹ค. checksec ์ฐธ์กฐ ldd ๋ช…๋ น์„ ํ™œ์šฉํ•˜์—ฌ ์˜์กด์„ฑ ๊ด€๊ณ„๋ฅผ ํ™•์ธํ•œ๋‹ค. ldd ๋ช…๋ น ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•˜์—ฌ ์ทจ์•ฝ์  ๋ฐ ๊ตฌ์กฐ(stack ํ˜•ํƒœ)์„ ํŒŒ์•…ํ•œ๋‹ค stack์€ ํ•จ์ˆ˜์—์„œ ์„ ์–ธ๋œ ์ˆœ์„œ๋Œ€๋กœ ํ• ๋‹น๋˜์ง€ ์•Š์Œ์— ์ฃผ์˜ํ•˜๋ฉฐ, ๋ฌด์กฐ๊ฑด assembly์–ด๋ฅผ ํ†ตํ•ด stack ์ฃผ์†Œ์—์„œ ํŠน์ • ๋ณ€์ˆ˜์˜ ์œ„์น˜๋ฅผ ํ™•์ธํ•˜๋„๋ก ํ•œ๋‹ค. ...

<span title='2024-03-11 20:46:33 +0900 KST'>March 11, 2024</span>&nbsp;ยท&nbsp;67 min&nbsp;ยท&nbsp;AswinBlue