½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ Ä¿ÇǴнº Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
 FAQFAQ   °Ë»ö°Ë»ö   ¸â¹ö¸®½ºÆ®¸â¹ö¸®½ºÆ®   »ç¿ëÀÚ ±×·ì»ç¿ëÀÚ ±×·ì   »ç¿ëÀÚ µî·ÏÇϱâ»ç¿ëÀÚ µî·ÏÇϱâ 
 °³ÀÎ Á¤º¸°³ÀÎ Á¤º¸   ºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀ   ·Î±×Àηα×ÀΠ

°¡ÀÔ¾øÀÌ ´©±¸³ª ±ÛÀ» ¾µ ¼ö ÀÖ½À´Ï´Ù. °øÁö»çÇ׿¡ ´ëÇÑ ´ñ±Û±îÁöµµ..




BBS >> ¼³Ä¡, ¿î¿µ Q&A | ³×Æ®¿÷, º¸¾È Q&A | ÀÏ¹Ý Q&A || Á¤º¸¸¶´ç | AWS || ÀÚÀ¯°Ô½ÃÆÇ | ±¸Àα¸Á÷ || °øÁö»çÇ× | ÀǰßÁ¦½Ã
¸ðµç ¸®´ª½º Ä¿³Î¿¡ ½É°¢ÇÑ º¸¾È °áÇÔ ¹ß°ß

 
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â  
±Û¾´ÀÌ ¸Þ½ÃÁö
pront40



°¡ÀÔ: 2004³â 8¿ù 18ÀÏ
¿Ã¸° ±Û: 2
À§Ä¡: VVT

¿Ã¸®±â¿Ã·ÁÁü: 2005.1.17 ¿ù, 9:47 am    ÁÖÁ¦: ¸ðµç ¸®´ª½º Ä¿³Î¿¡ ½É°¢ÇÑ º¸¾È °áÇÔ ¹ß°ß Àοë°ú ÇÔ²² ´äº¯

¾È³çÇϼ¼¿ä...

Ä¿³Î º¸¾È°áÇÔÀÔ´Ï´Ù. Âü°íµé ÇϽñ⠹ٶø´Ï´Ù.

¿ø¹®Ãâó : certcc-kr ¸ÞÀϸµ¸®½ºÅ© 2005. 01. 11.
-----------------------------------------------------------------------------
¾È³çÇϽʴϱî? ¿À´Ã°ú³»ÀÏÀÇ È«¼®¹üÀÔ´Ï´Ù.

ÃÖ±Ù µé¾î ¸®´ª½º Ä¿³Î¿¡ ¸î °¡Áö º¸¾È ¹ö±×°¡ ÀÖ¾úÁö¸¸
´ëºÎºÐ Ư¼öÇÑ È¯°æ¿¡¼­ÀÇ Ãë¾à¼ºÀ̾ú½À´Ï´Ù.

±×·¯³ª ÃÖ±Ù °ø°³µÈ uselib() ÇÔ¼ö¿¡¼­ÀÇ º¸¾È Ãë¾à¼ºÀ» ÅëÇØ¼­
³»ºÎÀÇ ÀÏ¹Ý À¯Àú°¡ root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Â Ãë¾à¼ºÀÌ È®ÀεǾú½À´Ï´Ù.
º» Ãë¾à¼º¿¡ ´ëÇÑ Á¤º¸´Â ¾Æ·¡¿Í °°½À´Ï´Ù.


* Ãë¾àÇÑ Ä¿³Î¹öÀü
2.2.x : ¸ðµç ¹öÀü
2.4.x : 2.4.28À» Æ÷ÇÔÇÑ 2.4.29-pre3 ±îÁö, 2.4.28 ÀÌÇÏ ¸ðµç ¹öÀü
2.6.x : 2.6.10À» Æ÷ÇÔÇÑ 2.6.10 ÀÌÇÏ ¸ðµç ¹öÀü

* Ãë¾àÇÏÁö ¾ÊÀº Ä¿³Î ¹öÀü
2.4.x : 2.4.29-rc1
--> 2.4.28 ¼³Ä¡ÈÄ 2.4.29-rc1 À¸·Î ÆÐÄ¡ÇÏ¿©¾ß ÇÔ
¶Ç´Â 2.4.28 ¼³Ä¡ÈÄ http://maphia.flowsecurity.org/patch/uselib-2.4.28.patch ÆÐÄ¡

2.6.x : 2.6.10-ac8
2.6.10 ¼³Ä¡ÈÄ 2.6.10-ac8 ·Î ÆÐÄ¡ÇÏ¿©¾ß ÇÔ

* °ø°Ý¹æ¹ý
Local exploitÀ̸ç remote¿¡¼­ÀÇ °ø°ÝÀº ºÒ°¡ÇÕ´Ï´Ù.
±×·¯³ª ÃÖ±Ù php injectionµîÀ» ÅëÇØ ÀÏ¹Ý ±ÇÇÑÀ» ½±°Ô ȹµæÇÒ ¼ö ÀÖÀ¸¹Ç·Î
Á¶Ã³¸¦ ÃëÇϽô °ÍÀÌ ÁÁ½À´Ï´Ù.


¾Æ·¡´Â exploit ¸¦ ½ÇÇàÇÏ¿© ¼º°øÇßÀ»¶§ÀÇ °á°úÀÔ´Ï´Ù.

$./exploit

[+] SLAB cleanup
child 1 VMAs 65527
child 2 VMAs 65527
child 3 VMAs 65527
...
child 18 VMAs 63322
[+] moved stack bfffb000, task_size=0xc0000000, map_base=0xbf800000
[+] vmalloc area 0xdf800000 - 0xfedbb000
Wait... \
[+] race won maps=49205
expanded VMA (0xbfffc000-0xffffe000)
[!] try to exploit 0xe2d25000
[+] gate modified ( 0xffec903c 0x0804ec00 )
[+] exploited, uid=0

sh-2.05b# id
uid=0(root) gid=0(root)

¾Æ·¡´Â 2.4.29-rc1À¸·Î ÆÐÄ¡ÇÑ ÈÄÀÇ ½ÇÇà °á°úÀÔ´Ï´Ù.

$./exploit
[-] FAILED: open lib (/dev/shm/_elf_lib not writable?) (Permission denied)
$

ÀϺο¡¼­´Â /dev/shmÀ» Ä¿³Î¿¡¼­ »èÁ¦Çϰųª umount¸¦ ÇÏ¸é µÈ´Ù°í ÇÏÁö¸¸
¿É¼Ç¿¡¼­ /tmp µîÀ¸·Î º¯°æÇÒ ¼ö Àֱ⠶§¹®¿¡ Àǹ̰¡ ¾ø½À´Ï´Ù.

¸¸¾à ÆÐÄ¡°¡ ¾î·Á¿î °æ¿ì¿¡´Â Àӽ÷Π´ÙÀ½°ú °°ÀÌ ÇØµµ µÇ´Â °Í °°½À´Ï´Ù.
(°ø½ÄÀûÀ¸·Î È®ÀÎµÈ ³»¿ëÀº ¾Æ´Ï¸ç ´ÜÁö ÀúÀÇ Å×½ºÆ® °á°úÀÏ »ÓÀÔ´Ï´Ù.)

# chmod 700 /proc/

Áï, /proc µð·ºÅ丮¸¦ 700 À¸·Î ¼³Á¤Çϵµ·Ï ÇÏ´Â °ÍÀ¸·Î ÀÌ ¼³Á¤À» ÅëÇØ¼­
ÀÏ¹Ý À¯Àú°¡ ps³ª w ¸¦ ½ÇÇàÇÒ ¼ö ¾ø´Â °Í ¿Ü¿¡ Ưº°È÷ ¹®Á¦°¡ µÇ´Â °ÍÀº ¾ø½À´Ï´Ù.
ÀÌ´Â °ø°ÝÄڵ峻¿¡¼­ /proc/slabinfo Á¤º¸¸¦ Àоî¾ß Çϱ⠶§¹®ÀÔ´Ï´Ù.

$ ./exploit

[+] SLAB cleanup
child 1 VMAs 65527
child 2 VMAs 65527
child 3 VMAs 65527
child 4 VMAs 65043
[+] moved stack bfffe000, task_size=0xc0000000, map_base=0xbf800000
[+] vmalloc area 0xe0000000 - 0xfffc1000
Wait... \
[-] FAILED: uselib (Cannot allocate memory)
Killed
$

$ ./exploit

[+] SLAB cleanup
[-] FAILED: get_slab_objs: /proc/slabinfo not readable? (Permission denied)
Killed
$

´Ù¸¥ Á¤º¸/ÀÇ°ß ÀÖÀ¸½Ã¸é °øÀ¯ ºÎʵ右´Ï´Ù.



°¨»çÇÕ´Ï´Ù.
À§·Î
»ç¿ëÀÚ Á¤º¸ º¸±â ºñ¹Ð ¸Þ½ÃÁö º¸³»±â MSN ¸Þ½ÅÀú
ÀÌÀü ±Û Ç¥½Ã:   
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸ ½Ã°£´ë: GMT + 9 ½Ã°£(Çѱ¹)
ÆäÀÌÁö 1 Áß 1

 
°Ç³Ê¶Ù±â:  
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù
¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù
ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù


Powered by phpBB © 2001, 2005 phpBB Group