๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

๋ฆฌ๋ฒ„์‹ฑ5

Buffer Over Flow - Protostar ๋ฌธ์ œ ์ด๋ฒˆ์— Buffer Over Flow ๊ด€๋ จ ๋ฌธ์ œ๋ฅผ ํ•œ๋ฒˆ ํ’€์–ด๋ณด์•˜๋‹ค. ์šฐ์„  Buffer Over Flow์˜ ์˜๋ฏธ๋Š” ์•„๋ž˜์™€ ๊ฐ™๋‹ค. ํ”„๋กœ๊ทธ๋žจ์ด ์‹คํ–‰๋  ๋•Œ ์ž…๋ ฅ ๋ฐ›๋Š” ๊ฐ’์ด ๋ฒ„ํผ๋ฅผ ๊ฐ€๋“ ์ฑ„์šฐ๋‹ค ๋ชปํ•ด ๋„˜์ณํ˜๋Ÿฌ ๋ฒ„ํผ ์ดํ›„์˜ ๊ณต๊ฐ„์„ ์นจ๋ฒ”ํ•˜๋Š” ํ˜„์ƒ. ์ด๋ ‡๊ฒŒ ๊ธ€๋กœ๋งŒ ๋ด์„œ๋Š” ๋น„์ „๊ณต์ž์ธ ๋‚˜๋Š” ์ดํ•ด ํ•˜๊ธฐ๊ฐ€ ์ข€ ํž˜๋“ค์—ˆ๋‹ค... Youtube์—์„œ ์•„๋ž˜์™€ ๊ฐ™์ด ์‰ฝ๊ฒŒ ์„ค๋ช… ํ•ด์ฃผ๋Š” ์˜์ƒ์ด ์žˆ์–ด์„œ ์ฐธ๊ณ  ์šฐ์„  Protostar์— ์žˆ๋Š” Bufferoverflow ๋ฌธ์ œ๋ฅผ ํ’€์–ด ๋ณด์•˜๋‹ค ์ฒซ๋ฒˆ์งธ๋Š” Stack0 ์ด๋‹ค ์•„๋ž˜์™€ ๊ฐ™์€ ์ฝ”๋“œ๋กœ ๋˜์–ด ์žˆ๋‹ค. 1. ๋จผ์ € ํ•ด๋‹น ์ฝ”๋“œ๋ฅผ kali ์—์„œ ์ปดํŒŒ์ผ ์ง„ํ–‰ ํ–ˆ๋‹ค --> ํ•˜์ง€๋งŒ ์ผ๋ฐ˜์ ์ธ ๋ฐฉ๋ฒ•์œผ๋กœ ์ง„ํ–‰ํ•˜๋ฉด ์ทจ์•ฝ์ (Bufferoverflow)์ด ๋‚˜ํƒ€๋‚˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ์•„๋ž˜์˜ ๋ช…๋ น์–ด๋กœ ์ปดํŒŒ์ผ --> ์Šคํƒ ๊ณต๊ฒฉ์— ์ทจ์•ฝํ•œ .. 2020. 10. 18.
Process Monitor / ๋™์  ๋ถ„์„ ํˆด https://docs.microsoft.com/en-us/sysinternals/downloads/procmon Process Monitor - Windows Sysinternals Monitor file system, Registry, process, thread and DLL activity in real-time. docs.microsoft.com 2020. 8. 23.
Bin Text / ๋™์  ๋ถ„์„ ํˆด ํŒŒ์ผ์— ์žˆ๋Š” String ์ •๋ณด๋ฅผ ํ™•์ธ ๊ฐ€๋Šฅํ•˜๋‹ค. https://www.aldeid.com/wiki/BinText 2020. 8. 23.
PE View / ๋™์  ๋ถ„์„ ํˆด http://wjradburn.com/software/ WJR Software - PEview (PE/COFF file viewer),... Utilities (for use with Windowsยฎ XP operating system or later) PEview provides a quick and easy way to view the structure and content of 32-bit Portable Executable (PE) and Component Object File Format (COFF) files. This PE/COFF file viewer displays heade wjradburn.com ์‹คํ–‰ ํŒŒ์ผ์˜ ์†์„ฑ๊ณผ ๊ตฌ์กฐ๋ฅผ ํŒŒ์•… ํ•  ์ˆ˜ ์žˆ๋‹ค. 2020. 8. 23.
Process Hacker / ๋™์  ๋ถ„์„ ํˆด https://processhacker.sourceforge.io/ PC์˜ ํ˜„์žฌ ์ƒํƒœ์™€ ์–ด๋– ํ•œ ํ”„๋กœ์„ธ์Šค๋“ค์ด ๋™์ž‘ ๋˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธ ๊ฐ€๋Šฅํ•œ ํˆด. 2020. 8. 23.