waffle
์™€ํ”Œ๊ณต์žฅ
waffle
์ „์ฒด ๋ฐฉ๋ฌธ์ž
์˜ค๋Š˜
์–ด์ œ
  • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (72)
    • ๐Ÿ“’ Daily Log (2)
    • ๐Ÿ”จ Dev_BE (5)
      • ๊ฐœ๋…์ •๋ฆฌ (4)
      • ๊ธฐ๋ก (1)
    • ๐Ÿ”จ Dev_FE (4)
    • ๐Ÿ”จ Dev_DB (1)
    • โš™ Dev_Ops (0)
    • ๐Ÿ”ก Lang (2)
      • Python (2)
    • ๐Ÿ’ก ํ”„๋กœ์ ํŠธ (9)
      • Base (1)
      • ์•„๋Œ€๋ฐ€๋งต (8)
    • ๐Ÿƒ๐Ÿป ์™ธ๋ถ€ํ™œ๋™ (2)
      • [ํ”„๋ฆฌ์ฝ”์Šค] ์šฐ์•„ํ•œํ…Œํฌ์ฝ”์Šค 7๊ธฐ - BE (2)
    • ๐Ÿ“• [STUDY] ๊ฐœ๋ฐœ (13)
      • [STUDY] ์•Œ๊ณ ๋ฆฌ์ฆ˜ (9)
      • ๋™๊ณ„ ์Šคํ„ฐ๋”” [Do-iT: ์›นํŒฉ] (2021) (4)
    • ๐Ÿ“™ [STUDY] AI (2)
      • Tensorflow (2)
    • ๐Ÿ” ๋ณด์•ˆ,์ •๋ณด๋ณดํ˜ธ (32)
      • CTF (2)
      • ๐Ÿ“˜ [STUDY] ํฌ๋ Œ์‹ (15)
      • ๐Ÿ“˜ [STUDY] ์ทจ์•ฝ์  (4)
      • ๐Ÿ“˜ [STYDY] ๋ฆฌ๋ฒ„์‹ฑ (11)
    • ๐Ÿ“” IT ๋ฒ•๋ฅ  (0)

๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

  • ํ™ˆ
  • ํƒœ๊ทธ

๊ณต์ง€์‚ฌํ•ญ

์ธ๊ธฐ ๊ธ€

ํƒœ๊ทธ

  • reversing
  • ์ˆ˜ํ•™_1
  • ์—ฐ์Šต_์ž๋ฃŒ๊ตฌ์กฐ
  • write-up
  • til
  • ์•„์ฃผ๋Œ€_์•Œ๊ณ ๋ฆฌ์ฆ˜_๊ต์œก
  • javascript
  • ์ฝ”๋”ฉํ…Œ์ŠคํŠธ_๊ณ ๋“์ 
  • ์ž๋ฃŒ๊ตฌ์กฐ
  • Java
  • scrum
  • ์•Œ๊ณ ๋ฆฌ์ฆ˜
  • ์ˆ˜ํ•™_1(์—ฐ์Šต)
  • ๋ฐฑ์ค€
  • ๋ฌธ์ž์—ด
  • ์šฐํ…Œ์ฝ”
  • Weekly
  • dopwn
  • ๋ฐ์ผ๋ฆฌ์•Œ๊ณ 
  • ํ”„๋กœ๊ทธ๋ž˜๋จธ์Šค
  • ๊ฐœ๋ฐœ
  • ํ”„๋ฆฌ์ฝ”์Šค
  • JAVA_API
  • ์šฐ์•„ํ•œํ…Œํฌ์ฝ”์Šค
  • ๊ฐœ๋ฐœ๋ฐฑ์„œ
  • ์šฐํ…Œ์ฝ”_7๊ธฐ
  • js
  • gdb
  • API
  • sql

์ตœ๊ทผ ๋Œ“๊ธ€

์ตœ๊ทผ ๊ธ€

ํ‹ฐ์Šคํ† ๋ฆฌ

hELLO ยท Designed By ์ •์ƒ์šฐ.
waffle

์™€ํ”Œ๊ณต์žฅ

[ DoPwn ] Week1 - "Student ID" Write Up
๐Ÿ” ๋ณด์•ˆ,์ •๋ณด๋ณดํ˜ธ/๐Ÿ“˜ [STYDY] ๋ฆฌ๋ฒ„์‹ฑ

[ DoPwn ] Week1 - "Student ID" Write Up

2021. 11. 20. 22:40
728x90

student ์‹คํ–‰๊ฒฐ๊ณผ

 

student ํ”„๋กœ๊ทธ๋žจ์€ ์ด๋ฆ„์„ ์ž…๋ ฅ๋ฐ›์€ ๋’ค ์ธ์‚ฌํ•˜๊ณ  ํ•™๋ฒˆ์„ ์ถœ๋ ฅํ•˜๋Š” ํ”„๋กœ๊ทธ๋žจ์ž„์„ ์‹คํ–‰๊ณผ์ •์„ ํ†ตํ•ด ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ์—ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์ž…๋ ฅ๋œ ์ด๋ฆ„์„ ๋ถ„์„ํ•˜๋Š” ์ฝ”๋“œ๊ฐ€ ์กด์žฌํ•  ๊ฒƒ์ž„์„ ์˜ˆ์ธกํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

 

์šฐ์„  ํ”„๋กœ๊ทธ๋žจ์˜ ์ •ํ™•ํ•œ ๊ตฌ์กฐ๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด gdb๋กœ ๋ถ„์„์„ ์‹œ๋„ํ–ˆ๋‹ค.

 

gdb - pd main ๊ฒฐ๊ณผ

pd main์„ ์‹คํ–‰ํ•œ ๊ฒฐ๊ณผ์ด๋‹ค. mainํ•จ์ˆ˜๋Š” ์œ„์™€ ๊ฐ™์ด ๊ตฌ์„ฑ๋˜์–ด์žˆ์œผ๋ฉฐ, ์•ž์„œ ์˜ˆ์ธกํ•œ ๋ฐ”์™€ ๊ฐ™์ด 0x401205 ์—์„œ ์ž…๋ ฅ๋ฐ›์€ ๊ฐ’์„ ๋น„๊ตํ•˜๋Š” ์ฝ”๋“œ๊ฐ€ ์กด์žฌํ•จ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

 

์šฐ์„  ๋น„๊ต๋Œ€์ƒ์˜ ๊ฐ’์„ ์•Œ์•„๋‚ด๋ฉด ์‰ฝ๊ฒŒ ํ’€ ์ˆ˜ ์žˆ์„ ๊ฒƒ ๊ฐ™์•„, ๋น„๊ตํ•˜๋Š” ๋Œ€์ƒ์˜ ์ฃผ์†Œ๊ฐ’์— ์žˆ๋Š” ๋ฌธ์ž์—ด์„ ํ™•์ธํ•˜๋Š” ์‹œ๋„๋ฅผ ํ–ˆ๋‹ค.

 

gdb - x/s 0x499602d2

 

gdb๊ฐ€ ๋ฉ”๋ชจ๋ฆฌ์— ์ ‘๊ทผํ•˜์ง€ ๋ชปํ•œ๋‹ค๋Š” ๋ฉ”์„ธ์ง€์™€ ํ•จ๊ป˜ ๋ฐ์ดํ„ฐ ์กฐํšŒ์— ์‹คํŒจํ–ˆ๋‹ค.

์กฐ๊ธˆ ๊ณ ๋ฏผํ•œ ๋’ค, ์ง์ ‘ ๊ฐ’์„ ํ™•์ธํ•˜๋Š” ๋Œ€์‹  return ๋˜๋Š” ์œ„์น˜๋ฅผ ๋ณ€๊ฒฝํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด๋ณด๊ธฐ๋กœ ํ–ˆ๋‹ค.

์ฆ‰, jne์—์„œ ๊ทธ๋ƒฅ ์ ํ”„ ๋˜๋„๋ก ํ•˜๊ณ , return ์œ„์น˜๋ฅผ jne ๋‹ค์Œ์œผ๋กœ ์„ค์ •ํ•ด์„œ ๋‹ค์‹œ ํ•ด๋‹น ์œ„์น˜๋กœ ์ด๋™์‹œํ‚ค๋Š” ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ํ–ˆ๋‹ค.

 

์ฝ”๋“œ์ƒ์—์„œ ๋ฌธ์ž์—ด์„ ๋ฐ›๊ณ ์ž ํ–ˆ๋˜ ๊ธธ์ด๋Š” 16์ง„์ˆ˜๋กœ 0x20, ์ฆ‰ 32 ์ด๋ฏ€๋กœ, ์˜์–ด 32๊ธ€์ž ์ด์ƒ ์ž…๋ ฅํ•˜๋ฉด ์˜ˆ์ƒ ๋ฌธ์ž์—ด์˜ ๊ธธ์ด๋ณด๋‹ค ๋„˜์น  ๊ฒƒ์ด๋ฏ€๋กœ, ์ด๋ฅผ ์ด์šฉํ•ด ์ด๋™์ฃผ์†Œ๋ฅผ ๋ฎ์–ด์”Œ์šธ ๊ฒƒ์ด๋‹ค.

 

print "a"*32 + "b"*8 + "\x0e\x12\x40\x00\x00\x00\x00\x00"

 

์œ„ ์ฝ”๋“œ๋ฅผ ํŒŒ์ดํ”„๋ผ์ธ์œผ๋กœ ํ”„๋กœ๊ทธ๋žจ์— ์ธ์ž๋กœ์„œ ๋„˜๊ฒผ๋‹ค.

python์„ ํ™œ์šฉํ•˜์—ฌ student ํ”„๋กœ๊ทธ๋žจ์— ์ธ์ž๋ฅผ ๋„˜๊น€

student id๊ฐ€ ์˜ˆ์ƒํ•œ ๋ฐ”์™€ ๊ฐ™์ด ์ถœ๋ ฅ๋˜์—ˆ๋‹ค. ์ด์ œ ์„œ๋ฒ„์— ์˜ฌ๋ผ๊ฐ€์žˆ๋Š” ํ”„๋กœ๊ทธ๋žจ์— ํ•ด๋‹น ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ flag๋ฅผ ์–ป์–ด๋‚ธ๋‹ค.

 

flag ํš๋“

 

flag๋ฅผ ํš๋“ํ–ˆ๋‹ค.

์™„๋ฃŒ!

728x90
๋ฐ˜์‘ํ˜•

'๐Ÿ” ๋ณด์•ˆ,์ •๋ณด๋ณดํ˜ธ > ๐Ÿ“˜ [STYDY] ๋ฆฌ๋ฒ„์‹ฑ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[ DoPwn ] Week1 - "system" Write Up  (0) 2021.11.22
[ DoPwn ] Week1 - "Magic Spell" Write Up  (0) 2021.11.22
[Whois-Internal] "EasyReverseMe" Write-Up  (0) 2021.11.08
[root-me.org] "reversing - PE x86 -0 protection" Write Up  (0) 2021.11.08
[ Assembly ] ์–ด์…ˆ๋ธ”๋ฆฌ ํ•ธ๋“œ๋ ˆ์ด  (0) 2021.10.14
    '๐Ÿ” ๋ณด์•ˆ,์ •๋ณด๋ณดํ˜ธ/๐Ÿ“˜ [STYDY] ๋ฆฌ๋ฒ„์‹ฑ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
    • [ DoPwn ] Week1 - "system" Write Up
    • [ DoPwn ] Week1 - "Magic Spell" Write Up
    • [Whois-Internal] "EasyReverseMe" Write-Up
    • [root-me.org] "reversing - PE x86 -0 protection" Write Up
    waffle
    waffle
    ๊ฐœ๋ฐœ๊ธฐ์ˆ  ๊ด€๋ จ ๊ธ€๋“ค์€ velog์— ์žˆ์Šต๋‹ˆ๋‹ค :) (https://velog.io/@cm_waffle) Developer waffle = new Waffle();

    ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”