๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

โœ’๏ธ Reverse Engineering24

[Reverse Engineering] CodeEngn Basic RCE L11 WriteUp ๐Ÿ…ฑ๏ธ CodeEngn Basic RCE L11 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 11 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. ๊ด€๋ จ ์ •๋ณด ์ˆ˜์ง‘์„ ์œ„ํ•ด Detect It Easy ๋ฅผ ํ†ตํ•ด ํŒŒ์ผ ์˜คํ”ˆ --> ํŒŒ์ผ์ด UPX ํ˜•์‹์œผ๋กœ ํŒจํ‚น๋˜์–ด์žˆ์Œ์„ ํ™•์ธ ++ ์•„์ง Detect It Easy ๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด? --> https://www.majorgeeks.com/ MajorGeeks.Com - MajorGeeks www.majorgeeks.com 4. ํŒจํ‚น๋œ ์ƒํƒœ์ธ 11 ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ์–ธํŒจํ‚น ์ง„ํ–‰ ++ UPX ํŒจํ‚น๋œ ํŒŒ์ผ ์–ธํŒจํ‚นํ•˜๊ธฐ --> https://alim11.tistory.com/456 [UPX Un/Packer] UPX.. 2023. 11. 7.
[Reverse Engineering] CodeEngn Basic RCE L10 WriteUp ๐Ÿ‘ข CodeEngn Basic RCE L10 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. ๋ฐ˜๋””์ง‘์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 10 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. ๊ด€๋ จ ์ •๋ณด ์ˆ˜์ง‘์„ ์œ„ํ•ด Detect It Easy ๋ฅผ ํ†ตํ•ด ํŒŒ์ผ ์˜คํ”ˆ --> ํŒŒ์ผ์ด ASPack ํ˜•์‹์œผ๋กœ ํŒจํ‚น๋˜์–ด์žˆ์Œ์„ ํ™•์ธ ++ ์•„์ง Detect It Easy ๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด? --> https://www.majorgeeks.com/ MajorGeeks.Com - MajorGeeks www.majorgeeks.com 4. ํŒจํ‚น๋œ ์ƒํƒœ์ธ 10 ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ์–ธํŒจํ‚น ์ง„ํ–‰ ++ VMUnpacker ์„ค์น˜ํ•˜๊ธฐ 5. ์–ธํŒจํ‚นํ•œ 10 ํŒŒ์ผ์„ Immunity Debugger ๋กœ ์˜คํ”ˆ --> OEP๊ฐ€ 00445834 ์ž„์„ ํ™•์ธ ++ OEP(.. 2023. 10. 3.
[Reverse Engineering] CodeEngn Basic RCE L09 WriteUp ๐Ÿง CodeEngn Basic RCE L09 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 09 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. ๊ด€๋ จ ์ •๋ณด ์ˆ˜์ง‘์„ ์œ„ํ•ด Detect It Easy ๋ฅผ ํ†ตํ•ด ํŒŒ์ผ ์˜คํ”ˆ --> ํŒŒ์ผ์ด UPX ํ˜•์‹์œผ๋กœ ํŒจํ‚น๋˜์–ด์žˆ์Œ์„ ํ™•์ธ ++ ์•„์ง Detect It Easy ๋ฅผ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜๋‹ค๋ฉด? --> https://www.majorgeeks.com/ MajorGeeks.Com - MajorGeeks www.majorgeeks.com 4. ํŒจํ‚น๋œ ์ƒํƒœ์ธ 09 ํŒŒ์ผ์— ๋Œ€ํ•˜์—ฌ ์–ธํŒจํ‚น ์ง„ํ–‰ ++ UPX ํŒจํ‚น๋œ ํŒŒ์ผ ์–ธํŒจํ‚นํ•˜๊ธฐ --> https://alim11.tistory.com/456 [UPX Un/Packer] UPX .. 2023. 10. 2.
[Reverse Engineering] CodeEngn Basic RCE L08 WriteUp ๐ŸŒธ CodeEngn Basic RCE L08 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ++ OEP(Original Entry Point) ๋ž€? OEP๋Š” "Original Entry Point"์˜ ์•ฝ์ž๋กœ, ์ฃผ๋กœ ํŒจํ‚น(packing)๋œ ์•…์„ฑ ์ฝ”๋“œ๋‚˜ ์••์ถ•๋œ ์ฝ”๋“œ์˜ ํŠน์ • ๋ถ€๋ถ„์—์„œ์˜ ์›๋ž˜ ์‹คํ–‰ ์ง€์ ์„ ์˜๋ฏธํ•œ๋‹ค. ํŒจํ‚น์€ ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ๊ฐ์ถ”๊ณ  ํƒ์ง€๋ฅผ ํ”ผํ•˜๊ธฐ ์œ„ํ•ด ์‹คํ–‰ ํŒŒ์ผ์„ ์••์ถ•ํ•˜๋Š” ๊ธฐ์ˆ ๋กœ, ์ด๋Ÿฌํ•œ ๊ฒฝ์šฐ ์‹คํ–‰ ํŒŒ์ผ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์ •์ƒ์ ์ธ ์‹คํ–‰ ํ๋ฆ„์„ ๋”ฐ๋ฅด์ง€ ์•Š์„ ์ˆ˜ ์žˆ๋‹ค. ์ด๋•Œ OEP๋Š” ๋ณด์•ˆ ๋ถ„์„๊ฐ€๋‚˜ ๋ฆฌ๋ฒ„์Šค ์—”์ง€๋‹ˆ์–ด๊ฐ€ ์•…์„ฑ ์ฝ”๋“œ์˜ ๋™์ž‘์„ ๋ถ„์„ํ•˜๊ณ  ์ดํ•ดํ•˜๋Š” ๋ฐ ๋„์›€์„ ์ฃผ๋ฉฐ, ์•…์„ฑ ์ฝ”๋“œ์˜ ์‹ค์ œ ๊ธฐ๋Šฅ์„ ๋ถ„์„ํ•˜๊ณ  ๋Œ€์‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๊ฐœ๋ฐœํ•˜๋Š” ๋ฐ ๋„์›€์„ ์ค„ ์ˆ˜ ์žˆ๋‹ค. 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ•.. 2023. 10. 1.
[Reverse Engineering] CodeEngn Basic RCE L07 WriteUp ๐Ÿ”• CodeEngn Basic RCE L07 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ 2. 7-Zip File Manager ์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 07 ํŒŒ์ผ ์† ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋ฐœ๊ฒฌ 3. 07 ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ๋”๋ธ” ํด๋ฆญํ•˜์—ฌ ์‹คํ–‰ํ•œ ํ›„ Check ๋ฒ„ํŠผ ํด๋ฆญ --> ์•„๋ž˜์™€ ๊ฐ™์€ ํŒ์—…์ฐฝ์„ ํ™•์ธ 4. 07 ์‹คํ–‰ ํŒŒ์ผ์„ Immunity Debugger ๋กœ ์˜คํ”ˆ 5. ๋งˆ์šฐ์Šค ์šฐ์ธก ๋ฒ„ํŠผ ํด๋ฆญ ํ›„ 'Search for' ์„ ํƒ --> 'All referenced text strings' ํด๋ฆญ 6. ๋ฌธ์ž์—ด ์ค‘ Serial ๋กœ ๋ณด์ด๋Š” "4562-ABEX" ์™€ "L2C-5781" ๋ฐœ๊ฒฌ 7. ๋กœ์ปฌ ๋””์Šคํฌ ํŒŒ์ผ๋ช…์„ CodeEngn์œผ๋กœ ๋ฐ”๊พผ ๋’ค, 07 ํŒŒ์ผ์„ Immunity Debugger ๋กœ ์‹คํ–‰ 8. ๋งˆ์šฐ์Šค ์šฐ์ธก.. 2023. 9. 30.
[Reverse Engineering] CodeEngn Basic RCE L06 WriteUp ๐Ÿ“ž CodeEngn Basic RCE L06 WriteUp 1. ๋ฌธ์ œ ํ™•์ธ ํ›„ ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ ++ OEP(Original Entry Point) ๋ž€? OEP๋Š” "Original Entry Point"์˜ ์•ฝ์ž๋กœ, ์ฃผ๋กœ ํŒจํ‚น(packing)๋œ ์•…์„ฑ ์ฝ”๋“œ๋‚˜ ์••์ถ•๋œ ์ฝ”๋“œ์˜ ํŠน์ • ๋ถ€๋ถ„์—์„œ์˜ ์›๋ž˜ ์‹คํ–‰ ์ง€์ ์„ ์˜๋ฏธํ•œ๋‹ค. ํŒจํ‚น์€ ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ๊ฐ์ถ”๊ณ  ํƒ์ง€๋ฅผ ํ”ผํ•˜๊ธฐ ์œ„ํ•ด ์‹คํ–‰ ํŒŒ์ผ์„ ์••์ถ•ํ•˜๋Š” ๊ธฐ์ˆ ๋กœ, ์ด๋Ÿฌํ•œ ๊ฒฝ์šฐ ์‹คํ–‰ ํŒŒ์ผ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์ •์ƒ์ ์ธ ์‹คํ–‰ ํ๋ฆ„์„ ๋”ฐ๋ฅด์ง€ ์•Š์„ ์ˆ˜ ์žˆ๋‹ค. ์ด๋•Œ OEP๋Š” ๋ณด์•ˆ ๋ถ„์„๊ฐ€๋‚˜ ๋ฆฌ๋ฒ„์Šค ์—”์ง€๋‹ˆ์–ด๊ฐ€ ์•…์„ฑ ์ฝ”๋“œ์˜ ๋™์ž‘์„ ๋ถ„์„ํ•˜๊ณ  ์ดํ•ดํ•˜๋Š” ๋ฐ ๋„์›€์„ ์ฃผ๋ฉฐ, ์•…์„ฑ ์ฝ”๋“œ์˜ ์‹ค์ œ ๊ธฐ๋Šฅ์„ ๋ถ„์„ํ•˜๊ณ  ๋Œ€์‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๊ฐœ๋ฐœํ•˜๋Š” ๋ฐ ๋„์›€์„ ์ค„ ์ˆ˜ ์žˆ๋‹ค. 2. ๋ฐ˜๋””์ง‘์„ ํ†ตํ•ด ํŒŒ์ผ ์••์ถ• ํ•ด์ œ --> 06 ํŒŒ์ผ ์† .. 2023. 9. 29.