๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Reverse Engineering/CodeEngn

[Reverse Engineering] CodeEngn Basic RCE L05 WriteUp

by A Lim Han 2023. 9. 24.

๐Ÿชท CodeEngn Basic RCE L05 WriteUp

1.  ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

2.  7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ  -->  05 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ

3.  05 ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋”๋ธ” ํด๋ฆญํ•˜์—ฌ ์‹คํ–‰  -->  ์•„๋ž˜์™€ ๊ฐ™์€ ํŒ์—…์ฐฝ์„ ํ™•์ธ

4.  ์ž…๋ ฅ๋ž€์— ์ž„์˜์˜ ๊ฐ’ ์ž…๋ ฅ ํ›„ "Register now!" ํด๋ฆญ  -->  ์•„๋ž˜์™€ ๊ฐ™์€ ์—๋Ÿฌ ํŒ์—…์ฐฝ์„ ํ™•์ธ

5.  ๊ด€๋ จ ์ •๋ณด ์ˆ˜์ง‘์„ ์œ„ํ•ด Detect It Easy ๋ฅผ ํ†ตํ•ด ํŒŒ์ผ ์˜คํ”ˆ  -->  ํŒŒ์ผ์ด UPX ํ˜•์‹์œผ๋กœ ํŒจํ‚น๋˜์–ด์žˆ์Œ์„ ํ™•์ธ

 

++  ์•„์ง Detect It Easy ๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด?

-->  https://www.majorgeeks.com/

 

MajorGeeks.Com - MajorGeeks

 

www.majorgeeks.com

6.  ํŒจํ‚น๋œ ์ƒํƒœ์ธ 05 ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ์–ธํŒจํ‚น ์ง„ํ–‰

 

++  UPX ํŒจํ‚น๋œ ํŒŒ์ผ ์–ธํŒจํ‚นํ•˜๊ธฐ

-->  https://alim11.tistory.com/456

 

[UPX Un/Packer] UPX ํŒจํ‚น๋œ ํŒŒ์ผ ์–ธํŒจํ‚นํ•˜๊ธฐ

๐Ÿงฎ UPX ํŒจํ‚น๋œ ์ƒํƒœ์˜ ํŒŒ์ผ์„ ์–ธํŒจํ‚นํ•˜๋Š” ๋ฐฉ๋ฒ• 1. ํ•˜๋‹จ์˜ ๋งํฌ๋กœ ์ ‘์†ํ•˜์—ฌ UPX Packer ๋‹ค์šด๋กœ๋“œ --> https://github.com/upx/upx/releases Releases · upx/upx UPX - the Ultimate Packer for eXecutables. Contribute to upx/upx developme

alim11.tistory.com

7.  05 ํŒŒ์ผ์„ Immunity Debugger ๋กœ ์˜คํ”ˆ

8.  ๋งˆ์šฐ์Šค ์šฐ์ธก ๋ฒ„ํŠผ ํด๋ฆญ ํ›„ 'Search for' ์„ ํƒ  -->  'All referenced text strings' ํด๋ฆญ

9.  ๋ฌธ์ž์—ด ์ค‘ ์ •๋‹ต์œผ๋กœ ๋ณด์ด๋Š” "Registered User"์™€ "GFX-754-IER-954" ์„ ๋ฐœ๊ฒฌ

10.  ๋‹ค์‹œ 05 ํŒŒ์ผ์„ ์‹คํ–‰์‹œํ‚จ ํ›„ ์œ„์—์„œ ๋ฐœ๊ฒฌํ•œ Serial๊ณผ ๋“ฑ๋กํ‚ค๋ฅผ ์ž…๋ ฅ  -->  ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์—ˆ์Œ์„ ํ™•์ธ