์ „์ฒด ๊ธ€

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚HackerSchool_FTZ

HackerSchool_level3

Level3 ๋ฌธ์ œํ’€์ด Keyword : System() func weakness ๋ฌธ์ œ ํŒŒ์•… ์ด์ „์ด๋ž‘ ๋น„๊ตํ•˜๋ฉด ํž˜๋“ค์–ด๋ณด์ด๋„ค์š” ใ…  ์ € ์ฝ”๋“œ๋ฅผ ๋œฏ์–ด๋ด…์‹œ๋‹น~ ์ด์   ์ € ์œ„ C์–ธ์–ด์˜ ์†Œ์Šค์ฝ”๋“œ์˜ ์ž‘๋™ ์ˆœ์„œ๋ฅผ ์•„์‹œ๊ณ  autodig ํŒŒ์ผ ์ฐพ์„๊นŒ์š”? autodig ํŒŒ์ผ ํƒ์ƒ‰ ๐Ÿ’กfind / -perm +4000 -user level4 2>/dev/null ๊ถŒํ•œ ํ™•์ธ๊นŒ์ง€ ๋๋‚ฌ์ฃ (๊ตณ์ด ์•ˆํ•ด๋„ ๋˜๋Š”๋ฐ ํ˜น์‹œ ๋ชจ๋ฅด๋‹ˆ๊นŒ..) ๊ทผ๋ฐ ์•„๊นŒ ํžŒํŠธ์—์„œ ๋ญ๋ผ๊ณ  ํ–ˆ์„๊นŒ์š”? more hints - ๋™์‹œ์— ์—ฌ๋Ÿฌ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉ - ๋ฌธ์ž์—ด ํ˜•ํƒœ๋กœ ๋ช…๋ น์–ด ์ „๋‹ฌ ํ•ด์„ํ•˜๋ฉด ๋™์‹œ ๋ช…๋ น์–ด๋Š” linux์—์„  ;(์„ธ๋ฏธ์ฝœ๋ก )/ |(ํŒŒ์ดํ”„๋ผ์ธ) / &(์—”ํผ์„ผํŠธ)๊ฐ€ ์žˆ๊ณ  ; / ์ „์ž ํ›„์ž ๋‘˜๋‹ค ์‹คํ–‰ ์„ฑ๊ณต์—ฌ๋ถ€ ์ƒ๊ด€์—†์ด ์‹คํ–‰ || / ์ „์ž๊ฐ€ ์„ฑ๊ณต๋˜๋ฉด ํ›„์ž๋Š” ์‹คํ–‰ X && /..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚HackerSchool_FTZ

HackerSchool_level2

level2 ๋ฌธ์ œ ํ’€์ด Keyword : Editor Shell Command Exploit ๋ฌธ์ œ ํŒŒ์•… ์œ„์™€ ๊ฐ™์ด ํžŒํŠธ ํ™•์ธ ์‹œ ํ…์ŠคํŠธ ํŒŒ์ผ ์ค‘ ์‰˜ ๋ช…๋ น์–ด ๋œ๋‹ค๋Š”๋ฐ.. ์—ญ์‹œ๋‚˜ ์ทจ์•ฝํ•œ ํŒŒ์ผ์˜ SetUID๋ฅผ ์ฐพ๋Š” ๋ถ€๋ถ„์œผ๋กœ find ๋ช…๋ น์–ด๋ฅผ ํ™œ์šฉํ•ฉ์‹œ๋‹ค find ๋ช…๋ น์–ด ํ™œ์šฉ ๐Ÿ’กfind / -perm +4000 -user level3 2>/dev/null ๊ทธ๋ฆฌ๊ณ  ์œ„ ๊ฒฝ๋กœ๊ฐ€ ๋‚˜์™”๊ธฐ์— ์ด๋™ํ•ฉ์‹œ๋‹ค editor๋Š” ์ตœ์ข…์ด๋‹ˆ๊นŒ ๊ทธ ์ „๊นŒ์ง€๋งŒ! editor๋ฅผ ๊ทธ๋Ÿผ ์‹คํ–‰์„ ํ•ด๋ณด๋ฉด(์ฐธ๊ณ ๋กœ ์‹คํ–‰ํ•  ๋• ./ ์‚ฌ์šฉ) ์‹คํ–‰ํ•ด๋ณด๋ฉด vi๊ฐ€ ๋‚˜์˜ค๋„ค์š” ํŽธ์ง‘๊ธฐ๋กœ์จ ๋‚˜์˜ค๋‚˜๋ด์š”(vi๋Š” ๊ตณ์ด ์„ค๋ช…์„.. ๋งํฌ ์˜ฌ๋ ค๋“œ๋ฆด๊ป˜์š” ใ…Ž) [๋ฆฌ๋ˆ…์Šค, ์œ ๋‹‰์Šค]vi (vim) ํŽธ์ง‘๊ธฐ ๊ธฐ๋ณธ ์‚ฌ์šฉ๋ฒ•, ๋ช…๋ น์–ด, ๋‹จ์ถ•ํ‚ค, ๋™์ž‘๋ฒ• & ๋ฌธ์ œ [๋ฆฌ๋ˆ…์Šค / ์œ ๋‹‰์Šค / ์…ธ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚HackerSchool_FTZ

HackerSchool_level1

Level 1 ๋ฌธ์ œ ํ’€์ด Keyword : find Backdoor Exploit ๋ฌธ์ œ ํŒŒ์•… ์œ„์™€ ๊ฐ™์ด hint๋ฅผ ํ™•์ธํ•˜๋ฉด setuid๊ฐ€ ์žˆ๋Š” backboor๋ฅผ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์ฃ  setuid๋Š” ์ผ์‹œ์ ์œผ๋กœ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ์—ญํ• ์œผ๋กœ์จ, ์ด ๊ฒƒ์„ ํ™œ์šฉํ•ด ์ต์Šคํ”Œ๋กœ์ž‡์„ ํ•  ์ˆ˜ ์žˆ์–ด์š” find ๋ช…๋ น์–ด๋ฅผ ํ™œ์šฉํ•ด ํŒŒ์ผ์„ ์ฐพ์•„์•ผํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. find๋ช…๋ น์–ด ํ™œ์šฉ ๐Ÿ’กfind / -perm -4000 -user level2 ์—ฌ๊ธฐ์„œ Tip ๐Ÿ’ก๋‚˜์ค‘์— ๋ฐฐ์šฐ๊ฒ ์ง€๋งŒ Permission denied๋ผ๋Š” ์—๋Ÿฌ๋ฅผ ์—†์ด ์ถœ๋ ฅํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด๋ฉด $ find / -perm -4000 -user level2 ์œ„์™€ ๊ฐ™์€ ๋ฐฉ๋ฒ•์œผ๋กœ ํ•˜๋ฉด ์—๋Ÿฌ๊ฐ€ ๋งŽ์ด ๋ฐœ์ƒํ•˜๋ฏ€๋กœ ์ด ์—๋Ÿฌ๋ฅผ ์ƒ๋žตํ•˜๋ ค๋ฉด ๋ช…๋ น์–ด ๋งจ ๋’ค์— 2>/dev/null ์ด๋ผ๋Š” ๋ช…๋ น์–ด๋ฅผ ๋„ฃ์–ด์ฃผ๋ฉด ๋œ..

๐Ÿ’ปโ”‚IT_Study/๐Ÿ“ฐโ”‚DB_Study

2. DBS

๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์‹œ์Šคํ…œ์˜ ์ •์˜ DB์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ณ , ์ด๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ์กฐ์ง๊ณผ ์ •๋ณด๋“ฑ์„ ํ†ตํ‹€์–ด ๋งํ•จ -Keyword- - ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์‹œ์Šคํ…œ์˜ ๊ตฌ์„ฑ์š”์†Œ - - ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค 3๋‹จ๊ณ„ ๊ตฌ์กฐ - - DBMS ์‹œ์Šคํ…œ ๊ตฌ์„ฑ - DBS, DataBase System DB, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค : ์ €์žฅ๋œ ๋ฐ์ดํ„ฐ์˜ ์ง‘ํ•ฉ DBMS, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ด€๋ฆฌ ์‹œ์Šคํ…œ : DB์— ์ €์žฅ๋œ ๋ฐ์ดํ„ฐ๊ฐ€ ์ผ๊ด€๋˜๊ณ  ๋ฌด๊ฒฐํ•œ ์ƒํƒœ๋กœ ์œ ์ง€๋˜๋„๋ก ๊ด€๋ฆฌ DBS, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์‹œ์Šคํ…œ : DB์™€ DBMS๋ฅผ ํ†ตํ•ด ์กฐ์ง์— ํ•„์š” ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜๋Š” ์ „์ฒด ์‹œ์Šคํ…œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ๊ตฌ์กฐ DB์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ณ , ์ด๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ์กฐ์ง๊ณผ ์ •๋ณด๋“ฑ์„ ํ†ตํ‹€์–ด ๋งํ•จ ์Šคํ‚ค๋งˆ์™€ ์ธ์Šคํ„ด์Šค ์Šคํ‚ค๋งˆ : DB์— ์ €์žฅ๋œ ๋ฐ์ดํ„ฐ์˜ ๊ตฌ์กฐ์™€ ์ œ์•ฝ์กฐ๊ฑด - ํ•œ๋ฒˆ ์ •์˜๋˜๋ฉด ์ž์ฃผ ๋ณ€๊ฒฝ X ์ธ์Šคํ„ด์Šค : ์Šคํ‚ค๋งˆ์— ๋”ฐ๋ผ DB..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚Dreamhack_Hacking

Tool: pwntools

pwntools์˜ ๊ฐ„๋‹จ ์„ค๋ช… ํƒ„์ƒ ๋ฐฐ๊ฒฝ๊ณผ ์„ค์น˜ ๋ฐฉ๋ฒ• ์ง€๋‚œ ์‹œ๊ฐ„์— ํŒŒ์ด์ฌ๊ณผ ํŒŒ์ดํ”„(|)๋ฅผ ํ†ตํ•ด ๊ฐ„๋‹จํ•œ ์Šคํƒ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ ์ต์Šคํ”Œ๋กœ์ž‡์„ ํ–ˆ์ฃ  ํŒŒ์ด์ฌ์œผ๋กœ ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ƒ์„ฑํ•˜๊ณ , ํŒŒ์ดํ”„๋ฅผ ํ†ตํ•ด ์ด๋ฅผ ํ”„๋กœ๊ทธ๋žจ์— ์ „๋‹ฌํ–ˆ์ฃ  ๊ทธ๋Ÿฌ๋‚˜ ์ต์Šคํ”Œ๋กœ์ž‡์ด ์ข€๋งŒ ๋ณต์žกํ•ด๋„ ์œ„ ๋ฐฉ๋ฒ•์€ ์ด์šฉ์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ƒ์„ฑํ•˜๊ธฐ ์œ„ํ•ด ๋ณต์žกํ•œ ์—ฐ์‚ฐ๊ณผ ํ”„๋กœ์„ธ์Šค์™€ ๋ฐ˜๋ณต์  ๋ฐ์ดํ„ฐ ์†ก์ˆ˜์‹ ์ด ๊ฐ€๋Šฅํ•ด์•ผ์ฃ  ๊ทธ๋ž˜์„œ ํ•ด์ปค๋“ค์€ perl, python c์–ธ์–ด ๋“ฑ์œผ๋กœ ์ต์Šคํ”Œ๋กœ์ž‡ ์Šคํฌ๋ฆฝํŠธ, ๋˜๋Š” ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ์ œ์ž‘ํ•ด ์‚ฌ์šฉํ–ˆ์ฃ  ๋” ์ž์„ธํžˆ ์•Œ๊ณ  ์‹ถ๋‹ค๋ฉด ์†Œ์ผ“ ํ”„๋กœ๊ทธ๋ž˜๋ฐ์„ ๋ฐฐ์šฐ์‹œ๋ฉด ๋ผ์š” ํŒŒ์ด์ฌ์œผ๋กœ ์—ฌ๋Ÿฌ ๊ฐœ์˜ ์ต์Šคํ”Œ๋กœ์ž‡ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•˜๋‹ค ๋ณด๋ฉด, ์ž์ฃผ ์‚ฌ์šฉํ•˜๊ฒŒ ๋  ํ•จ์ˆ˜๊ฐ€ ์žˆ์ฃ  ์˜ˆ๋กœ ๋ฆฌํ‹€ ์—”๋””์•ˆ์˜ ๋ฐ”์ดํŠธ ๋ฐฐ์—ด๋กœ ๋ฐ”๊พธ๋Š” ํŒจํ‚น ํ•จ์ˆ˜, ๋˜๋Š” ๊ทธ ์—ญ์„ ์ˆ˜ํ–‰ํ•˜๋Š” ์–ธํŒจํ‚น ํ•จ์ˆ˜ ๋“ฑ์ด์ฃ  ์ต์Šคํ”Œ๋กœ..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚Dreamhack_Hacking

Tool: gdb

โ€‹๐Ÿ›Debug(ger)๋ž€? CS(Computer Science)์—์„  ์‹ค์ˆ˜๋กœ ํƒ„์ƒํ•œ ํ”„๋กœ๊ทธ๋žจ์˜ ๊ฒฐํ•จ์„ bug๋ผ๊ณ  ์นญํ•จ ์„ค์น˜ sudo apt-get install gdb git clone https://github.com/pwndbg/pwndbg cd pwndbg ./setup.sh GitHub - pwndbg/pwndbg: Exploit Development and Reverse Engineering with GDB Made Easy Exploit Development and Reverse Engineering with GDB Made Easy - GitHub - pwndbg/pwndbg: Exploit Development and Reverse Engineering with GDB Made Easy gi..

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚Dreamhack_Hacking

Quiz: x86 Assembly

Quiz: x86 Assembly 1 ์œ„ ๋ฌธ์ œ๋ฅผ ํ•ด์„ํ•œ ๋ถ€๋ถ„์ด๋ฉฐ, Dreamhack์˜ ๋‚ด์šฉ์ž…๋‹ˆ๋‹น ์•ž์ฌ ๋‚ด์šฉ์—์„œ ๋Œ€์ถฉ ๋ช…๋ น์–ด์™€ ํ•ด๋‹น ๋ ˆ์ง€์Šคํ„ฐ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ํ–ˆ์œผ๋ฏ€๋กœ ๊ฐ„๋žตํ•˜๊ฒŒ ์„ค๋ช…ํ•˜๊ณ  ๋„˜์–ด๊ฐˆ๊ป˜์š” dl : RDX(64byte) → EDX(ํ•˜์œ„ 32byte) → DX(ํ•˜์œ„ 16byte) → DL(ํ•˜์œ„ 8byte) 1. mov dl, BYTE PTR[rsi+rcx] dl = rdx 8byte low_data > dl = 0x67 0x55 0x5c 0x53 0x5f 0x5d 0x55 0x10 0x57656c636f6d6520 0x400000 | 0x57656c636f6d6520 rcx = 0x1 result = -1 5 result is flase so.. code excute X

๐ŸŒ‡โ”‚System_Study/๐Ÿ“•โ”‚Dreamhack_Hacking

x86 Assembly: Essential Part

ํ•ด์ปค์˜ ์–ธ์–ด: ์–ด์…ˆ๋ธ”๋ฆฌ๐Ÿ’ฌ PC์—์„œ ๋ณต์žกํ•œ ๋…ผ๋ฆฌ์  ์ธ๊ณผ๊ด€๊ณ„, ์—ฌ๋Ÿฌ ๊ฐœ์ฒด๊ฐ€ ์ƒํ˜ธ์ž‘์šฉํ•˜๋ฉฐ ๊ทธ ์„ธ๊ณ„์—์„œ ํ†ต์šฉ๋˜๋Š” ๊ธฐ๊ณ„์–ด(Machine Code)์–ธ์–ด ํ•ต์‹ฌ! ์‹œ์Šคํ…œ ํ•ดํ‚น์„ ํ•  ๋•Œ๋Š” ์ปดํ“จํ„ฐ ์–ธ์–ด, ์šด์˜์ฒด์ œ, ๋„คํŠธ์›Œํฌ, ์•”ํ˜ธํ•™ ๋“ฑ ๋‹ค์–‘ํ•œ ๋ฐฐ์šธ ๊ฒƒ๋“ค์ด ์กด์žฌํ•˜์ง€๋งŒ, ๊ทธ์ค‘ ์‹œ์Šคํ…œ ํ•ด์ปค๊ฐ€ ๊ฐ€์žฅ ๊ธฐ๋ณธ์ ์œผ๋กœ ์Šต๋“ํ•ด์•ผ ํ•˜๋Š” ์ง€์‹์€ ์ปดํ“จํ„ฐ ์–ธ์–ด์— ๊ด€ํ•œ ๊ฒƒ์ž„! ์‹œ์Šคํ…œ ํ•ด์ปค๋Š” ์ปดํ“จํ„ฐ์˜ ์–ธ์–ด๋กœ ์ž‘์„ฑ๋œ ์†Œํ”„ํŠธ์›จ์–ด์—์„œ ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ•ด์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ ๊ทธ๋Ÿฐ๋ฐ ๋ฌธ์ œ๋Š” PC ์–ธ์–ด์ธ ๊ธฐ๊ณ„์–ด๊ฐ€ ๋„ˆ๋ฌด ์ดํ•ดํ•˜๊ณ  ์ž‘์„ฑํ•˜๊ธฐ ํž˜๋“ค๊ธฐ์— ๋‚œํ•ดํ•œ ๊ธฐ๊ณ„์–ด๋ฅผ ๋ฐ”๊พผ ์‚ฌ๋žŒ์ด ์žˆ์œผ๋‹ˆ, ์ปดํ“จํ„ฐ ๊ณผํ•™์ž ์ค‘ ํ•œ ๋ช…์ธ David Wheeler๋Š” EDSAC์„ ๊ฐœ๋ฐœํ•˜๋ฉด์„œ ์–ด์…ˆ๋ธ”๋ฆฌ ์–ธ์–ด(Assembly Language)์™€ ์–ด์…ˆ๋ธ”๋Ÿฌ(Assembler)๋ผ๋Š” ๊ฒƒ์„ ๊ณ ์•ˆ ์–ด์…ˆ๋ธ”๋Ÿฌ๋Š” ์ผ์ข…์— ํ†ต์—ญ..

Jastes
Jastes