½© Ǫ¸£Áö

C ÇÁ·Î±×·¥À» Linux / x86 ½© ÄÚµå·Î º¯È¯ÇÏ´Â ÄÄÆÄÀÏ·¯
Áö±Ý ´Ù¿î·Îµå

½© Ǫ¸£Áö ¼øÀ§ ¹× ¿ä¾à

±¤°í

  • Rating:
  • ƯÇã:
  • GPL
  • °¡°Ý:
  • FREE
  • °Ô½ÃÀÚ À̸§:
  • Philippe Biondi
  • °Ô½ÃÀÚ À¥»çÀÌÆ®:
  • http://www.secdev.org/projects/etherpuppet

½© Ǫ¸£Áö ű×


½© Ǫ¸£Áö ¼³¸í

C ÇÁ·Î±×·¥À» Linux / x86 ½© ÄÚµå·Î º¯È¯ÇÏ´Â ÄÄÆÄÀÏ·¯ ShellForge´Â PythonÀ¸·Î ÀÛ¼ºµÈ ÇÁ·Î±×·¥ÀÔ´Ï´Ù. ½ºÅÚ½ºÀÇ hellkit¿¡¼­ ¿µ°¨À» ¾òÀº PythonÀÔ´Ï´Ù. Some System È£ÃâÀº Çì´õ ÆÄÀÏ¿¡ Á¤Àǵ˴ϴÙ. C ÇÁ·Î±×·¥Àº libc È£Ãâ ´ë½ÅÀ̸¦ »ç¿ëÇÕ´Ï´Ù. Shellforge´Â GCC¸¦ »ç¿ëÇÏ¿© ¾î¼Àºí·¯·Î º¯È¯ÇÕ´Ï´Ù. ±×·± ´ÙÀ½ ºñÆ®¸¦ ¼öÁ¤ÇÏ°í, °´Ã¼¿¡¼­ Äڵ带 ÃßÃâÇÏ°í, ÀÎÄÚµù ÇÒ ¼ö ÀÖ°í, ½ÃÀÛÇÒ ¼öÀÖ´Â ·Î´õ¸¦ Ãß°¡ ÇÒ ¼ö ÀÖ½À´Ï´Ù. * XOR : ½© Äڵ带 ÀÎÄÚµùÇÏ¿© ³Î ¹ÙÀÌÆ®¸¦ ÇÇÇÏ°í °£´ÜÇÏ°Ô Ãß°¡ÇϽʽÿÀ. XOR µðÄÚ´õ * ¾ËÆÄ : °ÅÀÇ ¿µ¼ýÀÚ ½© ÄÚµå (¿¹ ÂüÁ¶) ¹Ì·¡ÀÇ ÁøÈ­ : * ShellForge¸¦ ±âº»ÀûÀ¸·Î ¶Ç´Â Å©·Î½º ÄÄÆÄÀÏ·¯¸¦ »ç¿ëÇÏ¿© ½© ÄÚµùÀ» »ý¼º ÇÒ ¼ö Àְųª Ãß°¡ ·Î´õ (¹× ¾ËÆÄ ·Î´õ ¸¶Ä§)¸¦ Ãß°¡ÇϽʽÿÀ. ¿¹ : ¿©±â¿¡ Hello World Program (Hello.c). # Æ÷ÇÔ "Æ÷ÇÔ / sfsyscall.h"Int Main (Void) {char buf [] = "Hello World! N"; ¾²±â (1, buf, sizeof (buf)); exit (0);} ¿ì¸®´Â ¿ø½Ã ½© Äڵ带 °¡Áú ¼ö ÀÖ½À´Ï´Ù : $ ./shellforge.py hello.c ** ÄÄÆÄÀÏ Hello.c ** Æ©´× ¿ø·¡ ¾î¼Àºí·¯ ÄÚµå Á¶Á¤ ** ¼öÁ¤ µÈ ASM Á¶ÇÕ ** ±â°è ÄÚµå °Ë»ö ** ÄÄÇ»Æà XOR ¾Ïȣȭ Å° ! ** ½© ÄÚµå´Â x55x89xe5x83xecx24x53xe8x00x00x00x00x5bx83xc3xf4x8bx83x67x00x00x00x89x45xf0x8bx83x6bx00x00x00x89x45xf4x8bx83x6fx00x00x00x89x45xf8x0fxb7x83x73x00x00x00x66x89x45xfcx8dx4dxf0xbax0ex00x00x00xb8x04x00x00x00xc7x45xecx01x00x00x00x53x8bx59xfcxcdx80x5bxb8x01x00x00x00xc7x45xecx00x00x00x00x53x8bx59xfcxcdx80x5bx5bxc9xc3x48x65x6cx6cx6fx20x77x6fx72x6cx64x21x0ax00We ±×°ÍÀ» Å×½ºÆ® ÇÒ ¼ö ÀÖ½À´Ï´Ù À§Á¶ : $ ./shellforge.py -tt¿¡¼­´Â hello.c ** ÄÄÆÄÀÏ¿¡¼­´Â hello.c ** Æ©´× ¿ø·¡ ¾î¼Àºí·¯ ÄÚµå ** Á¶¸³ ¼öÁ¤ ASM ** °¡Á® ¿À´Â ±â°è ÄÚµå ** XOR ¾Ïȣȭ Å°¸¦ °è»ê * * ½© ÄÚµå À§Á¶! ** ÄÄÆÄÀÏ Å×½ºÆ® ÇÁ·Î±×·¥ ** Running Test ProgramHello World! ** Å×½ºÆ® ¿Ï·á! ¹Ýȯ »óÅ°¡ C = 0We °³Àç¹°À§ÇÑ Áغñ ½© Äڵ带 °¡Áú ¼öÀÖ´Ù : $ ./shellforge.py -V0 -C¿¡¼­´Â hello.c ¼­¸í ½¡ºÒ ½© ÄÚµå [] = "x55x89xe5x83xecx24x53xe8x00x00x00x00x5bx83xc3xf4x8bx83x67" "x00x00x00x89x45xf0x8bx83x6bx00x00x00x89x45xf4x8bx83x6fx00" "x00x00x89x45xf8x0fxb7x83x73x00x00x00x66x89x45xfcx8dx4dxf0" "xbax0ex00x00x00xb8x04x00x00x00xc7x45xecx01x00x00x00x53x8b" "x59xfcxcdx80x5bxb8x01x00x00x00xc7x45xecx00x00x00x00x53x8b" "x59xfcxcdx80x5bx5bxc9xc3x48x65x6cx6cx6fx20x77x6fx72x6cx64" "x21x0ax00"; int main (void) {(((void (*) () ½© ÄÚµå) (); } ¿ì¸®´Â (Á» ´õ ¸¹Àº ½Ã°£À»ÁÖ´Â µÎ °¡Áö¸¦ Á¦°ÅÇÏ´Â °ÅÀÇ ¿µ¼ýÀÚ ½© Äڵ带 °¡Áö°í ¾ËÆÄ ·Î´õ¸¦ »ç¿ëÇÒ ¼öÀÖ´Â ½© ÄÚµå $ ./shellforge.py -v0 -x hello.cxebx0dx5ex31xc9xb1x75x80x36x02x46xe2xfaxebx05xe8xeexffxffxffx57x8bxe7x81xeex26x51xeax02x02x02x02x59x81xc1xf6x89x81x65x02x02x02x8bx47xf2x89x81x69x02x02x02x8bx47xf6x89x81x6dx02x02x02x8bx47xfax0dxb5x81x71x02x02x02x64x8bx47xfex8fx4fxf2xb8x0cx02x02x02xbax06x02x02x02xc5x47xeex03x02x02x02x51x89x5bxfexcfx82x59xbax03x02x02x02xc5x47xeex02x02x02x02x51x89x5bxfexcfx82x59x59xcbxc1x4ax67x6ex6ex6dx22x75x6dx70x6ex66x23x08x02We ¹ÙÀÌÆ® ÇÇÇϱâ x00¿¡¼­¿¡ XOR ·Î´õ¸¦ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù ºñ ¿µ¼ýÀÚ ¹ÙÀÌÆ®) $ ./shellforge.py -v0 -R --loader = ¾ËÆÄ¿¡¼­´Â hello.c hAAAAX5AAAAHPPPPPPPPah0B20X5Tc80Ph0504X5GZBXPh445AX5XXZaPhAD00X5wxxUPTYII19hA000X5sOkkPTYII19h0000X5cDi3PTY19I19I19I19h0000X50000Ph0A0AX50yuRPTY19I19I19I19h0000X5w100PTYIII19h0A00X53sOkPTYI19h0000X50cDiPTYI19I19hA000X5R100PTYIII19h00A0X500yuPTYI19I19h0000X50w40PTYII19I19h0600X5u800PTYIII19h0046X53By9PTY19 ¸¶Áö¸· I19I19h0000X50VFuPTYI19I19h0000X5LC00PTYIII19h0060X5u79xPTY19I19I19I19h0000X5000FPTY19I19h2005X59DLZPTYI19h0000X500FuPTYI19I19h0010X5DLZ0PTYII19h0006X50Fu9PTY19I19I19I19h0000X5LW00PTYIII19h0D20X5Lx9DPTY19h0000X5000kPhA0A0X5ecV0PTYI19I19h0B0AX5FXLRPTY19h5550X5ZZZePTYI19 ?? °íÀü °£ºÎ / ºó / SH : #INCLUDE INT´Â º»Ã¼ (¹«È¿) {* CHAR = { "/ ºó / SH"0} "/ sfsyscall.h Æ÷ÇÔ"; ½ÇÇà (a , a, 0); ¸¶Áö¸· 1024INT ¸ÞÀÎ Á¤ÀÇ (void) {struc sockaddr_in sa; int s, i; char buf ; sa.sin_family = pf_inet; sa.sin_addr.s_addr = 0x0100007f; I = first-1; ¾²±â (1, "½ÃÀÛ ³¡", 4); ´Ý±â (1); Ãⱸ (0);}


½© Ǫ¸£Áö °ü·Ã ¼ÒÇÁÆ®¿þ¾î

ASFPGA.

ASFPGA´Â FPGA ¼³°è¿¡¼­ »ç¿ëÇϱâ À§ÇØ ÀÛ¼ºµÈ ¾î¼Àºí¸®ÀÔ´Ï´Ù. ...

194

´Ù¿î·Îµå

ÀûÁ¤

ÀûÁ¤Àº ´ÙÁß »ç¿ëÀÚ ÀÎ ´ÙÁß ÇÁ·ÎÁ§Æ® ÃßÀû ½Ã½ºÅÛÀÔ´Ï´Ù. ...

172

´Ù¿î·Îµå