๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Reverse Engineering/CodeEngn

[Reverse Engineering] CodeEngn Basic RCE L14 WriteUp

by A Lim Han 2023. 11. 10.

โ›ฑ๏ธ CodeEngn Basic RCE L14 WriteUp

1.  ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

2.  7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ  -->  14 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ

3.  14.exe ํŒŒ์ผ์„ ์‹คํ–‰ํ•˜์—ฌ ์ž„์˜์˜ ๊ฐ’์„ ์ž…๋ ฅํ•œ ํ›„ "Check" ํด๋ฆญ  -->  Serial ์ด ํ‹€๋ ธ๋‹ค๋Š” ์•ˆ๋‚ด๋ฌธ์ด ์ถœ๋ ฅ

4.  ๊ด€๋ จ ์ •๋ณด ์ˆ˜์ง‘์„ ์œ„ํ•ด Detect It Easy ๋ฅผ ํ†ตํ•ด ํŒŒ์ผ ์˜คํ”ˆ  -->  ํŒŒ์ผ์ด UPX ํ˜•์‹์œผ๋กœ ํŒจํ‚น๋˜์–ด์žˆ์Œ์„ ํ™•์ธ

 

++  ์•„์ง Detect It Easy ๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด?

-->  https://www.majorgeeks.com/

 

MajorGeeks.Com - MajorGeeks

 

www.majorgeeks.com

5.  ํŒจํ‚น๋œ ์ƒํƒœ์ธ 14 ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ์–ธํŒจํ‚น ์ง„ํ–‰

 

++  UPX ํŒจํ‚น๋œ ํŒŒ์ผ ์–ธํŒจํ‚นํ•˜๊ธฐ

-->  https://alim11.tistory.com/456

 

[UPX Un/Packer] UPX ํŒจํ‚น๋œ ํŒŒ์ผ ์–ธํŒจํ‚นํ•˜๊ธฐ

๐Ÿงฎ UPX ํŒจํ‚น๋œ ์ƒํƒœ์˜ ํŒŒ์ผ์„ ์–ธํŒจํ‚นํ•˜๋Š” ๋ฐฉ๋ฒ• 1. ํ•˜๋‹จ์˜ ๋งํฌ๋กœ ์ ‘์†ํ•˜์—ฌ UPX Packer ๋‹ค์šด๋กœ๋“œ --> https://github.com/upx/upx/releases Releases · upx/upx UPX - the Ultimate Packer for eXecutables. Contribute to upx/upx developme

alim11.tistory.com

6.  Immunity Debugger ์„ ํ†ตํ•ด 14_unpacked.exe ํŒŒ์ผ ์˜คํ”ˆ

7.  ์„ฑ๊ณต ๋ฉ”์‹œ์ง€์™€ ์‹คํŒจ ๋ฉ”์‹œ์ง€๋กœ ๋ถ„๊ธฐํ•˜๋Š” ๋ถ€๋ถ„ ๋ฐœ๊ฒฌ  -->  ๋ถ„๊ธฐ์ ๊ณผ ๊ทธ ๋ฐ”๋กœ ์•„๋ž˜ BreakPoint ์„ค์ •

 

8.  ๋””๋ฒ„๊น… ์‹œ์ž‘ ํ›„ ๋ฌธ์ž์—ด CodeEngn๊ณผ 10์ง„์ˆ˜ "1234" ์ž…๋ ฅ  -->  ๊ฐ ๋ ˆ์ง€์Šคํ„ฐ์˜ ๊ฐ’์ด ์•„๋ž˜์™€ ๊ฐ™์ด ๋ณ€ํ•จ์„ ํ™•์ธ

# EAX ๋ ˆ์ง€์Šคํ„ฐ
: 000004D2

# ESI ๋ ˆ์ง€์Šคํ„ฐ
: 000129A1

 

++ ์•Œ ์ˆ˜ ์žˆ๋Š” ์‚ฌ์‹ค

: "CodeEngn" ์— ๋Œ€ํ•œ Serial ๊ฐ’  ==  000129A1 ์˜ 10์ง„์ˆ˜ ํ‘œ๊ธฐ

9.  8๋ฒˆ ๊ณผ์ •์„ ํ†ตํ•ด ์–ป์€ ์‚ฌ์‹ค๋“ค์„ ํ† ๋Œ€๋กœ CodeEngn ์— ๋Œ€ํ•œ Serial ๊ฐ’ ์œ ์ถ”

16์ง„์ˆ˜ 10์ง„์ˆ˜
000004D2 1234
000129A1 76193

10.  ๋‹ค์‹œ exe ์‹คํ–‰ ํ›„ ์œ ์ถ”ํ•œ ๊ฐ’ ์ž…๋ ฅ  -->  ๋ฌธ์ œ๊ฐ€ ์„ฑ๊ณต์ ์œผ๋กœ ํ•ด๊ฒฐ๋˜์—ˆ์Œ์„ ํ™•์ธ