[Info] Using Docker in PWNABLE (dreamhack)
ยท
INFO
Dreamhack์—์„œ pwnable๋ฌธ์ œ๋ฅผ ํ’€ ๋•Œ ์„œ๋ฒ„์˜ ํ™˜๊ฒฝ๊ณผ ๋™์ผํ•˜๊ฒŒ ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก, Dockerfile์„ ์ œ๊ณตํ•ด์ฃผ๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค ์ด Docker๋ฅผ ๊ตฌ์ถ•ํ•˜๋ฉด, ๋ฌธ์ œ ์„œ๋ฒ„์™€ ๋™์ผํ•œ ํ™˜๊ฒฝ์„ ๋งž์ถœ ์ˆ˜ ์žˆ์–ด, offset์ด๋‚˜ libc ๋ฒ„์ „์„ ๊ตณ์ด ๋กœ์ปฌ์—์„œ ์„ค์ •ํ•ด์ค„ ํ•„์š”๊ฐ€ ์—†๋‹ค ๊ทธ๋Ÿฌ๋ฉด Dreamhack๋ฟ๋งŒ ์•„๋‹ˆ๋ผ Dockerfile์„ ์ œ๊ณตํ•ด์ฃผ๋Š” pwnable ๋ฌธ์ œ์—์„œ ๋„์ปค๋ฅผ ๊ตฌ์ถ•ํ•˜๊ณ , exploit์„ ์งค ์ˆ˜ ์žˆ๋Š” ํ™˜๊ฒฝ์„ ์„ค์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•˜๊ฒ ๋‹ค 0x00. Download prob file(Dreamhack ๊ธฐ์ค€)์ด๊ฑด ์ทจํ–ฅ ์ฐจ์ด์ด๊ธด ํ•œ๋ฐ, "1. ๋ฌธ์ œ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ํ›„ ํƒ์ƒ‰๊ธฐ๋กœ wsl ํด๋”์— ๋ณต๋ถ™" or "2. wget์œผ๋กœ wsl์—์„œ ๋ฐ”๋กœ ๋ถ™์—ฌ๋†“๊ธฐ" 1๋ฒˆ ๋ฐฉ๋ฒ•์€ ๋ˆ„๊ตฌ๋‚˜ ํ•  ์ˆ˜ ์žˆ์„๊ฑฐ๋‹ˆ๊น, ๋„˜์–ด๊ฐ€๊ณ  2๋ฒˆ ๋ฐฉ..
[Info] Ubuntu 22.04 Docker for PWN
ยท
INFO
0x00. Intropwnable์„ ํ•˜๋ฉฐ Docker๋กœ ๋กœ๋˜๋ฆฌ์•ˆ ๋ฐ ๋กœ์•ˆ๋ฆฌ๋˜๋ฅผ ๊ฒฝํ—˜ํ•˜๋ฉฐ ๋„์ปค์˜ ํ•„์š”์„ฑ์„ ๋А๊ผˆ๊ณ , Docker ์„ค์น˜ ๋ฐ ์‹คํ–‰์„ ์˜ค๋ฅ˜ ์—†์ด, ํŽธ๋ฆฌํ•˜๊ฒŒ ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๊ณต๋ถ€ํ•˜๋ฉฐ ์•Œ๊ฒŒ๋œ ๋‚ด์šฉ๊ณผ ๋‚ด๊ฐ€ ์‚ฌ์šฉํ•  ๋ฐฉ๋ฒ•์„ ๊ธฐ๋กํ•˜๊ธฐ ์œ„ํ•ด์„œ ์ ๋Š” ๊ธ€ 0x01. Build and RunBuild :docker build -t [IMAGE_NAME] .Run :docker run -u root -v /mnt/c/Kim_Jun_Won/03_Programming/6_HACKING/Wargame\\(Dreamhack\\):/shared_dir -it [IMAGE_NAME] /bin/bash> ์ด๋Ÿฌ๋ฉด /mnt/c/....(local)๊ณผ Docker๋‚ด์˜ shared_dir์ด๋ผ๋Š” ํด๋”๊ฐ€ ๊ณต์œ ๋จ 0x02. Dreamhack์—..
[Dreamhack] stack aligne test(pwn)
ยท
Dreamhack
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[Dreamhack] Rock Paper Scissors(pwn)
ยท
Dreamhack
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
[Dreamhack] Repeat Service(pwn)
ยท
Dreamhack
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
์•ˆ๋…•ํ•˜์„ธ์š” pandas์ž…๋‹ˆ๋‹ค. ์ €์˜ 1๋…„์€์š”..
ยท
๋””๋ฏธ๊ณ 
๊ทธ๋™์•ˆ ํ‹ฐ์Šคํ† ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  velog๋ฅผ ์‚ฌ์šฉํ•˜๋‹ค๊ฐ€ velog๊ฐ€ ์ข€ ์•ˆ ์ด์œ๊ฒƒ ๊ฐ™์•„์„œ tistory๋กœ ์ปค์Šคํ…€์„ ํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์‹œ ๊ธ€์„ ์ ์–ด๋ณด๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. 2024๋…„ ์ง€๋‚œ ํ•œ๊ตญ๋””์ง€ํ„ธ๋ฏธ๋””์–ด๊ณ ๋“ฑํ•™๊ต 1ํ•™๋…„ ์ƒํ™œ์„ ํ•˜๋ฉฐ ํ•™๊ธฐ ์ดˆ ํ•ดํ‚น์— ๋Œ€ํ•ด์„œ ๊ด€์‹ฌ์ด ์—†๋˜ ์ €์—๊ฒŒ "์‹ ์ž…์ƒ ๋Œ€์ƒ DIMI CTF"๋ผ๋Š” ์ข‹์€ ๋Œ€ํšŒ๋ฅผ ์ ‘ํ•˜๊ฒŒ ๋˜์—ˆ๊ณ , ํ•ดํ‚น์— ์žฌ๋ฏธ์— ๋น ์ง€๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ดํ›„ ์ด ์ข‹์€ ๊ธฐ์–ต์ด ๋™์•„๋ฆฌ ์ง€์›์—๋„ ์˜ํ–ฅ์„ ๋ฏธ์ณ ํ•ดํ‚น ๋™์•„๋ฆฌ "STEALTH"์— ์ง€์›ํ•˜๊ฒŒ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.  ์ดํ›„ ์™œ ๋ถ™์—ˆ๋Š”์ง€๋Š” ์•„์ง๋„ ์˜๋ฌธ์ด์ง€๋งŒ, ํ•ฉ๊ฒฉ์„ ํ•˜๊ณ , ํ•ดํ‚น์„ ์ทจ๋ฏธ๋กœ ๊ณต๋ถ€ํ•˜๊ธฐ ์‹œ์ž‘ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ๋ถ„์•ผ๋ฅผ ์„ ํƒํ•  ๋•Œ ์ €๋Š” ๋ถ„์•ผ์— ๋Œ€ํ•œ ์ง€์‹์ด ๊ฑฐ์˜ ์ „๋ฌดํ•˜์˜€๊ณ , ์ œ๊ฐ€ CTF๋‹น์‹œ ์†๋„ ๋ชป๋Œ€๋ณด๊ณ  ๋๋‚œ "์‹œ์Šคํ…œ ํ•ดํ‚น; PWNABLE"์„ ์ฃผ ๋ถ„์•ผ๋กœ ๋‘๊ณ  ๊ณต๋ถ€๋ฅผ ํ•˜..