์ „์ฒด ๊ธ€

๐Ÿ“šโ”‚War_Game/๐Ÿ˜˜โ”‚CTF

CCE 2022

๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.

๐ŸŒ‡โ”‚System_Study/๐Ÿ”’โ”‚H4C_5๊ธฐ

๋นก๊ณตํŒŸ 5๊ธฐ OT

๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚HackerSchool_FTZ

HackerSchool_level12

keyworld : gets buffer Overflow level12 - WriteUp ์œ„ ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด์‹œ๋ฉด gets()๋ผ๋Š” ์ž…๋ ฅ๋ฐ›๋Š” ๋ถ€๋ถ„์ด ์–ด๋””๊นŒ์ง€ ์ž…๋ ฅ๋ฐ›๋Š”์ง€ ์„œ์ˆ ๋˜์ง€ ์•Š์•˜๊ธฐ์— ์ทจ์•ฝํ•จ! ์ฐธ๊ณ ๋กœ ์•ˆ์ „ํ•œ ๋ฐฉ์‹์€ gets_s๊ฐ€ ์žˆ๊ฒ ์ฃ . ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ณ  ๋ถ„์„ํ•  ์ˆ˜ ์žˆ๊ฒŒ tmp๋กœ ์˜ฎ๊ฒจ์„œ ์‹คํ–‰ํ•˜์ง€์š” ์œ„ ๋ฐฉ์‹์œผ๋กœ ํ•˜์‹œ๋ฉด ๋ณดํ†ต ์ €๋Š” intel ๋ฐฉ์‹์œผ๋กœ ์‚ฌ์šฉํ•˜๊ธฐ์— ๋ณด๊ธฐ ๋ถˆํŽธํ•  ์ˆ˜ ์žˆ๊ธฐ์— ๋ณ€๊ฒฝํ•˜๋Š” ๋ฐฉ์‹๋„ ์žˆ๋Š”๊ฑฐ ๊ฐ™์€๋ฐ ๊ทธ๋ƒฅ ์ „๋ถ€ํ„ฐ ์ด๋ ‡๊ฒŒ ํ–ˆ์œผ๋‹ˆ๊นŒ ๊ทธ๋ƒฅ ํ• ๊ป˜์š” ์ฒซ๋ฒˆ์งธ ๋ฐฉ์‹์œผ๋กœ๋Š” ๋ฉ”๋ชจ๋ฆฌ์— ํ• ๋‹น๋œ stack์˜ ํฌ๊ธฐ๋ฅผ ์•Œ ์ˆ˜ ์žˆ์œผ๋ฉฐ, 0x108(264)๋กœ ํ™•์ธ ๋˜๋ฉฐ, ๋‘๋ฒˆ์งธ๋Š” gets์˜ ํ˜•์‹์ด ์žˆ๊ธฐ ์ „์— str๋กœ ์ž…๋ ฅ๋ฐ›์€ ํ˜•์‹์ด ์ธ์ž๋กœ ๋„ฃ์–ด์ง€๋Š”๋ฐ gets์˜ ํ˜•์‹์˜ ์ธ์ž์— ๋งž๊ฒŒ ๋„ฃ๊ธฐ์— ํ™•์ธํ•ด๋ณด๋ฉด, 0xff.. ์‹ค์ œ๊ฐ’์ด๋ผ๊ธฐ์—” ..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚HackerSchool_FTZ

HackerSchool_level11

keyword : strcpy bof keyword : printf Format String keyword : NOP level11 - Write Up(NOP) ํžŒํŠธ๊ฐ€ ์ฝ”๋“œ๋„ค์š”... ์œ„ ์ฝ”๋“œ๋ฅผ ๋ณด๋ฉด argv๋ผ๋Š” main์ธ์ž์˜ ๊ฐ’์„ ๋ฐ›์•„์„œ ์ถœ๋ ฅํ•˜๋„ค์š” setreuid๊ฐ€ ์žˆ๊ธฐ์— level12๋กœ ํ–ฅํ•˜๋Š” ๋น„๋ฒˆ์˜ ๊ถŒํ•œ์„ ์ทจ๋“ํ•  ์ˆ˜ ์žˆ๋‹ต๋‹ˆ๋‹ค. BOF์— ์ทจ์•ฝํ•œ ๋Œ€ํ‘œ์ ์ธ ํ•จ์ˆ˜๊ฐ€ strcpy์ด๋‹ˆ๊นŒ bof๋กœ main์˜ ret๋ฅผ ์กฐ์ž‘ํ•˜๋ฉด ๋˜๊ฒ ๋„ค์š” ์ฐธ๊ณ ๋กœ ์ € ํ•จ์ˆ˜์—์„œ bof ์ทจ์•ฝ์ ์„ ๋ง‰์„๋ ค๋ฉด strncpy๋กœ ํ•˜๋ฉด ๋˜์š” ใ…Ž ๊ทธ๋Ÿผ ๋ฆฌ๋ฒ„์‹ฑ์œผ๋กœ ํ™•์ธํ•ด๋ณผ๊นŒ์š”? ์Œ.. ๋ณด์‹œ๋ฉด ํ”„๋กค๋กœ๊ทธ๊ฐ€ ์œ„์™€ ๊ฐ™์ด ๋‚˜์™€์žˆ์œผ๋ฉฐ, ์˜ ์–ด์…ˆ ์ฝ”๋“œ๊ฐ€ $0x108, %esp๋กœ์จ ์•„๊นŒ ์ฝ”๋“œ์—์„œ ๋ณธ char str[256]์˜ ํฌ๊ธฐ๋ฅผ ์ €๋ ‡๊ฒŒ esp๋กœ์จ ๊ณต๊ฐ„ ํ• ๋‹นํ•œ๊ฑฐ๋„ค์š”..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚HackerSchool_FTZ

HackerSchool_level10

keyword : Shared Memory level10-WriteUp Shared Memory ๊ณต์œ  ๋ฉ”๋ชจ๋ฆฌ๋ž€ ์—ฌ๋Ÿฌ ์žฅ์น˜(์ฃผ๋กœ CPU)๋‚˜ ์—ฌ๋Ÿฌ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ณต๋™์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๋ฉ”๋ชจ๋ฆฌ Ex) ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋“ฑ.. [ CS / OS ] ๊ณต์œ  ๋ฉ”๋ชจ๋ฆฌ (Shared Memory) ๊ณต์œ  ๋ฉ”๋ชจ๋ฆฌ๋ž€ ์—ฌ๋Ÿฌ ์žฅ์น˜(์ฃผ๋กœ CPU)๋‚˜ ์—ฌ๋Ÿฌ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ณต๋™์œผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๋ฉ”๋ชจ๋ฆฌ๋ฅผ ์˜๋ฏธํ•œ๋‹ค.์œ„์˜ ๊ทธ๋ฆผ์ฒ˜๋Ÿผ ์ผ๋ฐ˜์ ์ธ ํ”„๋กœ์„ธ์Šค๋Š” ๊ฐ์ž์˜ ๋…๋ฆฝ๋œ ๋ฉ”๋ชจ๋ฆฌ๋ฅผ ๊ฐ€์ง€๊ณ  ์‚ฌ์šฉํ•˜๊ฒŒ ๋œ๋‹ค. ํ•˜์ง€๋งŒ ๊ณต์œ  velog.io ๊ณต์œ  ๋ฉ”๋ชจ๋ฆฌ์— ์ €์žฅํ•œ๋‹ค๋ผ.. ๊ทธ๋Ÿผ ๋จผ์ € ๊ณต์œ  ๋ฉ”๋ชจ๋ฆฌ ์„ค์ •๊ณผ ๊ธฐ๋Šฅ ๊ทธ๋ฆฌ๊ณ  ์ฝ”๋”ฉ์— ๋Œ€ํ•˜์—ฌ ์•Œ์•„๋ณด๊ธฐ ์ „์— ์ถ”๊ฐ€์ ์œผ๋กœ ์ •๋ณด๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•ด๋ด…์‹œ๋‹ค ์ผ๋‹จ ./program์ด๋ผ๋Š” ํŒŒ์ผ์ด ์กด์žฌํ•˜๊ธฐ์— ํ™•์ธ์„ ํ•ด๋ณด๋‹ˆ๊นŒ ๊ถŒํ•œ์ด ์—†๋‹ค.. ์ฆ‰, root ๊ถŒํ•œ์—์„œ ์‹คํ–‰..

๐Ÿ“šโ”‚War_Game/๐Ÿซโ”‚Genius_SW

MNU Junior CTF 2022

๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.

๐Ÿ”ฌโ”‚Reversing & Cryptography/๐Ÿ“•โ”‚CodeEnge

Basic RCE L02

Basic RCE L02 - WriteUp ๋ง ๊ทธ๋Œ€๋กœ ํŒŒ์ผ์ด ํšŒ์†๋˜์–ด x32dbg๊ฐ€ ์‹คํ–‰์ด ์•ˆ๋˜๋„ค์š” IDA๋Š” ์‹คํ–‰์ด ๋˜๊ธด ํ•œ๋ฐ.. ํ•ด๋ณด๋‹ˆ๊นŒ ๊ทธ๋ ‡๊ฒŒ ์ •ํ™•ํ•˜๊ฒŒ๋Š” ์›ํ•˜๋Š” ๊ฐ’์€ ์•ˆ ๋‚˜์™€์„œ.. ์œˆ๋„์šฐ 11์—์„œ๋Š” ์ €๋ ‡๊ฒŒ ๋œจ๋„ค์š” ์ผ๋‹จ HxD(Hex Editor)๋กœ ํ™•์ธ ํ•ด๋ด…์‹œ๋‹ค ์• ์‹œ๋‹น์ดˆ ์ฝ๊ธฐ ์ „์šฉ์œผ๋กœ ๋งŒ๋“ค์—ˆ๋„ค์š”.. ํ•˜๊ธด ๊ทธ๋Ÿฌ๋‹ˆ๊นŒ ํšŒ์†ํ–ˆ๋‹ค๊ณ  ํ–ˆ๊ฒ ๋‹ค ๋ฐ‘์œผ๋กœ ๋” ๋‚ด๋ ค๊ฐ€๋ฉด์„œ ํ™•์ธํ•ด๋ณด๋ฉด... ๊ธ€๋กœ "Nope, try.." ์ฆ‰ ์‹คํŒจํ–ˆ์„ ๋•Œ ๋ฉ”์‹œ์ง€์™€ "Yeah you did it!"์ด๋ผ๋Š” ์„ฑ๊ณต ๋ฉ”์‹œ์ง€ ๊ทธ๋ฆฌ๊ณ  ๋ฐ‘์— Crackme#1์œผ๋กœ JK3FJZh๋กœ ๋ฌธ์ž์—ด์ด ์žˆ๋Š” ๊ฑธ ๋ณด์•„.. ๊ทธ๊ฒŒ ์ •๋‹ต์ผ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ๊ฒ ๋„ค์š” ํ™•์ธํ•ด๋ณด๋ฉด.. ์„ฑ๊ณต!! ์ฐธ๊ณ  ์ž๋ฃŒ CodeEngn.com [์ฝ”๋“œ์—”์ง„] ์ฝ”๋“œ์—”์ง„์€ ๊ตญ๋‚ด ๋ฆฌ๋ฒ„์Šค์—”์ง€๋‹ˆ์–ด๋ง ์ •๋ณด๊ณต์œ ๋ฅผ ์œ„ํ•ด 200..

๐Ÿ”ฌโ”‚Reversing & Cryptography/๐Ÿ“•โ”‚CodeEnge

Basic RCE L01 - Basic

Basic RCE L01 - Write Up ๋น„๋ฒˆ : codeengn ๋กœ์จ HD๊ฐ€ CD-Rom์— ์ ‘๊ทผ์ด ๋˜์–ด์•ผ๋งŒ ์‹คํ–‰์ด ๋œ๋‹ค๊ณ .... ์ฆ‰, ์ธ์ž๋กœ CD-Rom์œผ๋กœ ์ ‘๊ทผ๋œ ๊ฒƒ์„ ํ™•์ธํ•˜๊ณ  ๋ฐ˜ํ™˜ํ•ด์„œ ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์ด ๊ตฌ๋ถ„์ด ๋˜์–ด ์žˆ๋„ค์š” ๊ทธ๋Ÿผ ์ฝ”๋“œ๋ฅผ x32dbg๋กœ ํ•ด์„œ ํ•ด๋ณผ๊ป˜์š” ์‹คํ–‰์„ ์‹œ์ผœ์„œ ๋ถ„์„์„ ํ•ด๋ณด๋ฉด.. ์œ„์™€ ๊ฐ™์ด ๋œน๋‹ˆ๋‹ค ํ•˜๋‚˜์”ฉ ๋น„๊ต๋ฅผ ํ•ด๋ณผ๊นŒ์š”? ๋ณด์‹œ๋ฉด 0040100C๊นŒ์ง€๋Š” ํ”„๋กค๋กœ๊ทธ์ด๊ธฐ ๋•Œ๋ฌธ์— ๋ฌด์‹œํ•˜์…”๋„ ํฐ ์ƒ๊ด€์€ ์—†์„ ๋“ฏ ์‹ถ๋„ค์š” ๊ทธ๋ฆฌ๊ณ  push 01.402094๊นŒ์ง€์˜ ๋‚ด์šฉ๋„ ํฐ ๋ฌธ์ œ๋Š” ์—†์ง€๋งŒ ํŒ์„ ์ค€๋‹ค๋ฉด.. call : ์‹œ์Šคํ…œ ์•„์ด์ฝ˜, ์ผ๋ จ์˜ ๋‹จ์ถ”, ์ƒํƒœ ๋˜๋Š” ์˜ค๋ฅ˜ ์ •๋ณด์™€ ๊ฐ™์€ ๊ฐ„๋‹จํ•œ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ๋ณ„ ๋ฉ”์‹œ์ง€๊ฐ€ ํฌํ•จ๋œ ๋ชจ๋‹ฌ ๋Œ€ํ™” ์ƒ์ž๋ฅผ ํ‘œ์‹œ ํ•œ๋งˆ๋””๋กœ ๊ฒฐ๊ณผ๋ฅผ ๋ชจ๋‹ฌ์ฐฝ์œผ๋กœ ํ‘œ์‹œํ•ด์คŒ push 01.402094 : ..

Jastes
Jastes