๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

์ „์ฒด ๊ธ€443

[Reverse Engineering] CodeEngn Basic RCE L17 WriteUp ๐ŸŽฏ CodeEngn Basic RCE L17 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 17 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. 17.exe ์„ ์‹คํ–‰ํ•˜์—ฌ ์ž„์˜์˜ ๊ฐ’ ์ž…๋ ฅ ํ›„ "Check it!" ํด๋ฆญ --> "Please Enter More Chars..." ์ด๋ผ๋Š” ๊ฒฝ๊ณ ๋ฌธ ํ™•์ธ 4. Immunity Debugger ์„ ํ†ตํ•ด 17.exe ํŒŒ์ผ ์˜คํ”ˆ --> ์„ฑ๊ณต & ์‹คํŒจ ๋ฉ”์‹œ์ง€์™€ ๋น„๊ต๋ฌธ ๋ฐœ๊ฒฌ 5. ๋ฐœ๊ฒฌํ•œ ๋น„๊ต๋ฌธ์„ 03 --> 01๋กœ ๋ณ€๊ฒฝ 6. ์‹คํŒจ๋ฌธ๊ณผ ๊ทธ ์•„๋ž˜ BreakPoint ์„ค์ • --> ํŒจ์น˜ ์‚ฌํ•ญ ์ €์žฅ 7. Debugging ์‹คํ–‰ ํ›„ ASCII ์‹œ๋ฆฌ์–ผ์ด ์ƒ์„ฑ๋œ ๊ฒƒ์„ ํ™•์ธ 8. 17.0045B850 ํ•จ์ˆ˜์— BreakPoint ์„ค์ •.. 2023. 11. 15.
[Reverse Engineering] CodeEngn Basic RCE L16 WriteUp ๐Ÿ‘บ CodeEngn Basic RCE L16 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 16 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. 16.exe ์„ ์‹คํ–‰ํ•˜์—ฌ ์ž„์˜์˜ ๊ฐ’ ์ž…๋ ฅ ํ›„ "Enter" ํด๋ฆญ --> "Wrong password!" ์ด๋ผ๋Š” ๊ฒฝ๊ณ ๋ฌธ ํ™•์ธ 4. Immunity Debugger ์„ ํ†ตํ•ด 16.exe ํŒŒ์ผ ์˜คํ”ˆ 5. ์„ฑ๊ณต ๋ฌธ์ž์—ด๊ณผ ์‹คํŒจ ๋ฌธ์ž์—ด๋กœ ๋ถ„๊ธฐํ•˜๋Š” ๋ถ€๋ถ„ ๋ฐœ๊ฒฌ --> ๋ถ„๊ธฐ ๋ถ€๋ถ„๊ณผ ๊ทธ ์•„๋ž˜ BreakPoint ์„ค์ • 6. Debugging ์‹คํ–‰ ํ›„ ๋ ˆ์ง€์Šคํ„ฐ ๊ฐ’ ํ™•์ธ # EAX ๋ ˆ์ง€์Šคํ„ฐ : 000004D2 # EBP ๋ ˆ์ง€์Šคํ„ฐ : 0070FF28 7. ๋ฐœ๊ฒฌํ•œ ์‚ฌ์‹ค๋“ค์„ ๊ธฐ๋ฐ˜์œผ๋กœ Password ํƒ์ƒ‰ --> ํŒจ์Šค์›Œ๋“œ๊ฐ€ E4C60.. 2023. 11. 14.
[Debugging & Assembly] DnSpy ํˆด ๋‹ค์šด๋กœ๋“œ ๋ฐ ์‚ฌ์šฉ ๋ฐฉ๋ฒ• ๐Ÿ‘พ DnSpy ๋ž€? DnSpy๋Š” .NET ์–ด์…ˆ๋ธ”๋ฆฌ ํŽธ์ง‘ ๋ฐ ๋””๋ฒ„๊น… ๋„๊ตฌ๋กœ, .NET ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์˜ ์–ด์…ˆ๋ธ”๋ฆฌ ์ฝ”๋“œ ํŽธ์ง‘ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•œ๋‹ค. DnSpy๋Š” ์˜คํ”ˆ ์†Œ์Šค ํ”„๋กœ์ ํŠธ๋กœ .NET ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋‚ด๋ถ€ ๋™์ž‘์„ ์ดํ•ด & ์ˆ˜์ •ํ•˜๋Š” ๋ฐ ์ฃผ๋กœ ์‚ฌ์šฉํ•˜๋ฉฐ, ๋””๋ฒ„๊น…๊ณผ ์—ญ์ปดํŒŒ์ผ๋ง์„ ์œ„ํ•œ ๋‹ค์–‘ํ•œ ๊ธฐ๋Šฅ๋„ ์ œ๊ณตํ•œ๋‹ค. ๐Ÿ‘พ DnSpy ํˆด ๋‹ค์šด๋กœ๋“œ ๋ฐ ์‚ฌ์šฉ ๋ฐฉ๋ฒ• 1. ์•„๋ž˜ ๋งํฌ๋กœ ์ ‘์†ํ•˜์—ฌ ๋ณธ์ธ์˜ ํ™˜๊ฒฝ์— ๋งž๋Š” ๋ฒ„์ „ ์„ค์น˜ --> https://github.com/dnSpy/dnSpy/releases Releases · dnSpy/dnSpy .NET debugger and assembly editor. Contribute to dnSpy/dnSpy development by creating an account on GitHub. git.. 2023. 11. 13.
[UWSP Pointer Overflow CTF 2023] Unquestioned and Unrestrained Write Up ๐Ÿ‘จ‍๐Ÿ’ผ Unquestioned and Unrestrained Write Up 1. ๋ฌธ์ œ ์ˆ™์ง€ ํ›„ ์•”ํ˜ธ๋ฌธ ํ™•์ธ + ์•”ํ˜ธํ™” ๋ฐฉ์‹๊ณผ ํ‰๋ฌธ์„ ์•Œ๋ ค์ฃผ์ง€ ์•Š์€ ์ƒํƒœ์—์„œ ์•”ํ˜ธ๋ฌธ๋งŒ์„ ๋ณด๊ณ  ํ‰๋ฌธ์„ ์œ ์ถ”ํ•˜๋Š” ๋ฌธ์ œ ++ ์œ ์ผํ•œ ํžŒํŠธ๋Š” ๋ณดํŽธ์ ์ธ ์•”ํ˜ธํ™” ๋ฐฉ์‹์ด๋ผ๋Š” ๊ฒƒ! 2. ๊ฐ ์•”ํ˜ธํ™” ๋ฐฉ์‹์— ๋”ฐ๋ผ ๋ณตํ˜ธํ™”ํ•˜๊ธฐ ์œ„ํ•œ Python ์Šคํฌ๋ฆฝํŠธ ์ž‘์„ฑ # Base64 import base64 def base64_decode(encoded_text): ใ…คใ…คdecoded_bytes = base64.b64decode(encoded_text) ใ…คใ…คdecoded_text = decoded_bytes.decode('utf-8') ใ…คใ…คreturn decoded_text # ์ฃผ์–ด์ง„ ์•”ํ˜ธ๋ฌธ์— ๋Œ€ํ•ด Base64 ๋””์ฝ”๋”ฉ ์‹œ๋„ ciphertext = "cG9j.. 2023. 11. 12.
[Cake CTF 2023] Country DB - 92 Write Up ๐Ÿ›น Country DB - 92 Write Up 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ์ฝ”๋“œ ๊ฒ€์ƒ‰ ๋งํฌ๋กœ ์ ‘์† ++ 'CA' ์™€ 'KE' ์— ํ•ด๋‹นํ•˜๋Š” ๋‚˜๋ผ ์ด๋ฆ„์„ ์ฐพ์œผ๋ผ๋Š” ๋“ฏ 2. ์ฝ”๋“œ ๊ฒ€์ƒ‰ ๋งํฌ์—์„œ ๊ฐ ์ฝ”๋“œ์— ๋Œ€ํ•œ ๊ตญ๊ฐ€ ํ™•์ธ 3. FLAG ์–‘์‹์— ๋งž๊ฒŒ ์ž‘์„ฑ ํ›„ ์ œ์ถœ --> ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์ง€ ์•Š์Œ 4. ํ˜น์‹œ ์ฒจ๋ถ€ ํŒŒ์ผ์— ํžŒํŠธ๊ฐ€ ์žˆ์„๊นŒ ์‹ถ์–ด ์ฒจ๋ถ€ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 5. ํŒŒ์ผ ํƒ์ƒ‰ --> ์ฝ”๋“œ ๊ฒ€์ƒ‰ ์‚ฌ์ดํŠธ ์ƒ์„ฑ์„ ์œ„ํ•œ ํŒŒ์ผ๋กœ ์ถ”์ • 6. ํŒŒ์ผ์„ ๋ชจ๋‘ ์‚ดํŽด๋ณด์•˜์œผ๋‚˜ ์ถ”๊ฐ€์ ์ธ ํžŒํŠธ๋ฅผ ์–ป์ง€ ๋ชปํ•จ --> ๋ฌธ์ œ ํ•ด๊ฒฐ ์‹คํŒจ 2023. 11. 11.
[Reverse Engineering] CodeEngn Basic RCE L15 WriteUp ๐Ÿ“Œ CodeEngn Basic RCE L15 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 15 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. 15.exe ์„ ์‹คํ–‰ํ•˜์—ฌ ์ž„์˜์˜ ๊ฐ’ ์ž…๋ ฅ ํ›„ "Check it!" ๋ฒ„ํŠผ ํด๋ฆญ --> "Try Again!" ์ด๋ผ๋Š” ํŒ์—…์ฐฝ ํ™•์ธ 4. Immunity Debugger ์„ ํ†ตํ•ด 15 ํŒŒ์ผ ์˜คํ”ˆ 5. ์„ฑ๊ณต ๋ฌธ์ž์—ด๊ณผ ์‹คํŒจ ๋ฌธ์ž์—ด๋กœ ๋ถ„๊ธฐํ•˜๋Š” ๋ถ€๋ถ„ ๋ฐœ๊ฒฌ --> ๋ถ„๊ธฐ ๋ถ€๋ถ„๊ณผ ๊ทธ ์•„๋ž˜ BreakPoint ์„ค์ • 6. Debugging ์‹คํ–‰ ํ›„ ๋ ˆ์ง€์Šคํ„ฐ ๊ฐ’ ํ™•์ธ # EAX ๋ ˆ์ง€์Šคํ„ฐ : 00000457 # 45B844 Address : 0x6160 ++ ์•Œ ์ˆ˜ ์žˆ๋Š” ์‚ฌ์‹ค : "CodeEngn" ์— ๋Œ€ํ•œ Serial ๊ฐ’ ==.. 2023. 11. 10.