2014-08-01ãã1ã¶æéã®è¨äºä¸è¦§
IPAã«å ±åãããWL-Enqãã®èå¼±æ§ã«ã¤ãã¦ãIPAã«æ å ±éé示ä¾é ¼ã®åãä¸ããç³è«ãã¦èªããããã®ã§ãèå¼±æ§é¢é£æ å ±ãå ¬éãã¾ããç§ã¯ãããã®æ å ±ã®å 容ãçå®ã§ããã¨ç¢ºä¿¡ãã¦ãã¾ãããéçºè ãªã©ã®åèªãæ¯æããæå³ã§ãããã®æ å ±ãå ¬éããããã§â¦
HITCON CTF 2014ã«ãã¼ã fuzzi3ã§åå ãããç·å¢24人ãçµæã¯1ä½ã以ä¸ãç§ã解ããåé¡ã mid (ACM) 250ç¹ ã¸ã£ã³ã«ãACMã§ãã¾ãã«ãããã競æããã°ã©ã³ã°ã®åé¡ãæ´æ°nã¨nåã®æ´æ°A0, A1, â¦, An-1ãä¸ããããAã®ä¸å¤®å¤ãçãããnã¯1iã¯ç¬¦å·ä»ã64bitâ¦
表ã¯ãããæå·åããã°ã©ã ã¨æå·åãããã¡ã¤ã«ãä¸ãããã¦ããã¡ã¤ã«ã復å·ããåé¡ãæå·åã®ã³ãã³ã㯠$ ./crypt 1 pub.txt flag.pdf flag.bincryptã«ã¯ãããã¡ã¼ãªã¼ãã¼ããã¼ã®èå¼±æ§ãåå¨ããã®ã§ãæ»æãã¦ã¿ãã [kusano@www10383uf Decrypt â¦
çµè« #include <stdlib.h> #include <unistd.h> int main() { execl("/bin/sh", "/bin/sh", "-p", NULL); } ããã㯠#include <stdlib.h> #include <unistd.h> int main() { setreuid(geteuid(), -1); system("/bin/sh"); } åè setuid - Wikipedia 7-3. setuid ã¯æ éã« Technical Memorandum: set</unistd.h></stdlib.h></unistd.h></stdlib.h>â¦
æ²è¶ã®åã®ãã¹ãçããã¬ã¤ãããé¢ç½ãã£ãã5æéãããã§çµãããå®ãããªã¹ã¹ã¡ã ã²ã¼ã ãã¤ã³ã¹ãã¼ã«ããã«ãããã使ç¨è¨±è«¾å¥ç´æ¸ãèªãã ããæ°ã«ãªãæ¡é ããã£ãã 第5æ¡ï¼å¥ç´ã®çµäºï¼ å¼ç¤¾ã¯ãã客æ§ãæ¬å¥ç´ã®ããããã®æ¡é ã«éåããã¨ãã¯â¦