[CTF] 2024 ELECCON ์ผ๋ ‰์ฝ˜ ์˜ˆ์„ 

2025. 2. 27. 02:10ยทCTF

sudo rm -rf /bin์ด๋ผ๋Š” ํŒ€๋ช…์œผ๋กœ ์ฐธ๊ฐ€ํ–ˆ๋‹ค

์Šค์ฝ”์–ด๋ณด๋“œ๊ฐ€ ๋น„๊ณต๊ฐœ๋กœ ์ „ํ™˜๋˜์–ด ์ตœ์ข… ์ ์ˆ˜๋Š” ๋ชจ๋ฅด์ง€๋งŒ ์•„๋งˆ 40~50๋“ฑ ์ •๋„ ํ•  ๊ฒƒ ๊ฐ™๋‹ค

์ตœ์ข… ์Šค์ฝ”์–ด

๊ฐ๊ฐ ํ•œ ๋ฌธ์ œ์”ฉ ํ’€์—ˆ๋‹ค
๋‚ด๊ฐ€ CAN-DI-PING์„ ํ’€์—ˆ๋‹ค

Write Up (?)

CAN-DI-PING

ํŒจํ‚ท ํŒŒ์ผ ํ•˜๋‚˜ ๋˜์ €์ฃผ๊ณ  ๊ณต๊ฒฉํ•œ ์ทจ์•ฝ์  ๋ถ„์„ํ•œ CVE๋ฅผ ์ฐพ์œผ๋ผ๊ณ  ํ–ˆ๋‹ค

wireshark์—์„œ ์—ด์–ด์ค€๋‹ค

์ œ๊ฐ€ ๋ฐœ์ƒ๋˜๊ณ  ์žˆ๋Š” HOST์˜ IP๋Š” 192.168.11.57๋กœ ํ™•์ธ๋˜๊ณ  HTTP ํ”„๋กœํ† ์ฝœ ํŒจํ‚ท์ด ํ•ด๋‹น IP๋กœ ๋“ค์–ด์˜ค๋Š” ๊ฒƒ์ด ํ™•์ธ๋ฉ๋‹ˆ๋‹ค. ์ถ”๊ฐ€์ ์œผ๋กœ HTTPํ—ค๋”์˜ Accept-Encoding ๊ฐ’์ด ์กฐ์ž‘๋˜์–ด ๋“ค์–ด์˜ค๋Š” ํŒจํ‚ท์ด ์žˆ๋‹ค๊ณ  ๊ด€์ œํŒ€์œผ๋กœ ์—ฐ๋ฝ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค.

๋ญ” ๋ง์ธ์ง€๋Š” ๋ชจ๋ฅด๊ฒ ๋Š”๋ฐ ๋Œ€์ถฉ Accept-Encoding์ด๋ผ๋Š” ์ •๋ณด๋ฅผ ์†ก์ˆ˜์‹ ํ•˜๋Š” ํŒจํ‚ท์„ ์ฐพ์œผ๋ฉด ๋œ๋‹ค

๊ทธ๋ฆฌ๊ณ  ๊ทธ ๊ทผ์ฒ˜์— ์žˆ๋Š” ํŒจํ‚ท ๋ชจ์กฐ๋ฆฌ ๋ณต-๋ถ™ ํ•ด์„œ GPT

๋งŽ์ด ์•Œ๋ ค์ฃผ์ง€๋งŒ ๋‹ค ํ‹€๋ ธ๋‹ค

๋ ๋•Œ๊นŒ์ง€ ๋ฌผ์–ด๋ณธ๋‹ค

์ด๊ฑฐ๋‹ค

ELECCON{CVE-2022-21907}

์ˆ˜๋™ ๋ธŒ๋ฃจํŠธํฌ์‹ฑ

Review

๋ฆฌ๋ฒ„์‹ฑ์€ ๋ฌธ์ œ๊ฐ€ ๋„ˆ๋ฌด ์–ด๋ ค์›Œ์„œ ๋ถ„์„์ด ์•ˆ๋˜๊ณ 
์‹œ์Šคํ…œ์€ ์›น๊ณผ ๋„์ปค๊ฐ€ ๊ฐ™์ด ๋‚˜์™€์„œ ์ „์ฒด 0์†”ํ•œ ๋งค์šฐ ์–ด๋ ค์šด ๋ฌธ์ œ๊ณ 
์›น์€ ์–ด์งœํ”ผ ํ’€ ์ƒ๊ฐ์„ ์•ˆํ–ˆ๋‹ค

๊ฒฐ๋ก ์ ์œผ๋กœ๋Š” ์นจํ•ด์‚ฌ๊ณ ๋ถ„์„(==misc)๋งŒ ์ž˜ ํ•˜๋ฉด ๋˜๋Š” ๋ฌธ์ œ์˜€๋‹ค

์‹œ๊ฐ„์ด ์—†์–ด์„œ ๋ฌธ์ œ๋ฅผ ๋งŽ์ด ๋ชป ํ‘ผ๊ฒŒ ์•„์‰ฝ๋‹ค

1์†”๋งŒ ๋”ํ–ˆ์œผ๋ฉด ๋ณธ์„ ? ๊ฐˆ ์ˆ˜ ์žˆ์—ˆ์„ ๊ฒƒ ๊ฐ™์€ใ„ท...

'CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[ 2025 COSS ์•„์ฃผ๋Œ€ CTF - ๋ณธ์„ ] - Write Up & ํ›„๊ธฐ  (5) 2025.07.25
[2025 COSS ์•„์ฃผ๋Œ€ CTF - ์˜ˆ์„  ] - Write Up & ํ›„๊ธฐ  (0) 2025.06.23
[2025 Codegate ์˜ˆ์„ ] - Write Up & ํ›„๊ธฐ  (0) 2025.05.26
[2025 DIMI CTF Write Up] - Prob by pandas. with ํ›„๊ธฐ  (3) 2025.03.25
[CTF] ์ œ 5ํšŒ ์ค‘๋ถ€๋Œ€ํ•™๊ต JBU CTF  (1) 2025.02.27
'CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • [2025 COSS ์•„์ฃผ๋Œ€ CTF - ์˜ˆ์„  ] - Write Up & ํ›„๊ธฐ
  • [2025 Codegate ์˜ˆ์„ ] - Write Up & ํ›„๊ธฐ
  • [2025 DIMI CTF Write Up] - Prob by pandas. with ํ›„๊ธฐ
  • [CTF] ์ œ 5ํšŒ ์ค‘๋ถ€๋Œ€ํ•™๊ต JBU CTF
Hello๐Ÿ–๏ธI'm pandas from KDMHS
Hello๐Ÿ–๏ธI'm pandas from KDMHS
ํ•œ๊ตญ๋””์ง€ํ„ธ๋ฏธ๋””์–ด๊ณ ๋“ฑํ•™๊ต 23๊ธฐ ์›น ํ”„๋กœ๊ทธ๋ž˜๋ฐ๊ณผ์—์„œ ํ•ดํ‚น์„ ๊ณต๋ถ€ํ•˜๊ณ  ์žˆ๋Š” pandas์ž…๋‹ˆ๋‹ค.
  • Hello๐Ÿ–๏ธI'm pandas from KDMHS
    pandasiuuuu
    Hello๐Ÿ–๏ธI'm pandas from KDMHS
  • ๊ณต์ง€์‚ฌํ•ญ

    • Hello I'm pandas ๐Ÿ–๏ธ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (40)
      • CTF (13)
      • ๋””๋ฏธ๊ณ  (17)
      • ๋ฐฑ์ค€ (1)
      • Dreamhack (5)
      • INFO (3)
      • 1 ไบบ 1 Project (1)
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ํƒœ๊ทธ
    • ๋ฐฉ๋ช…๋ก
  • ๋งํฌ

  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    info
    ctf
    Baekjoon
    ๋””๋ฏธ๊ณ 
    ํ•ดํ‚น
    DreamHack
    docker
    ํšŒ๊ณ ๋ก
    ๋ฐฑ์ค€
    reversing
    ์›นํ”„๋กœ๊ทธ๋ž˜๋ฐ๊ณผ
    ํŒฐ๋ฆฐ๋“œ๋กฌ
    Python
    1์ธ1ํ”„๋กœ์ ํŠธ
    pwnable
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • ์ตœ๊ทผ ๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.3
Hello๐Ÿ–๏ธI'm pandas from KDMHS
[CTF] 2024 ELECCON ์ผ๋ ‰์ฝ˜ ์˜ˆ์„ 
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”