Stack Pivoting
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Heap ๊ธฐ์ดˆ
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Tcache Double Free Bypass
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Tcache & Tcache dup Attack
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Heap ๊ธฐ์ดˆ 2
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Library : Static, Dynamic Link
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
Protection & Exploit Technique
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
RTL (Return to Library)
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๋ณดํ˜ธ๋˜์–ด ์žˆ๋Š” ๊ธ€์ž…๋‹ˆ๋‹ค.
_IO_FILE
ยท
๐Ÿ–Œ๏ธ Theory/PWN
๊ฐœ๋… "_IO_FILE"์€ ๋ฆฌ๋ˆ…์Šค ์‹œ์Šคํ…œ์˜ ํ‘œ์ค€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์—์„œ ํŒŒ์ผ ์ŠคํŠธ๋ฆผ์„ ๋‚˜ํƒ€๋‚ด๋Š” ๊ตฌ์กฐ์ฒด์ด๋‹ค. "fopen"๊ณผ ๊ฐ™์€ ํŒŒ์ผ๊ณผ ๊ด€๋ จ์žˆ๋Š” ํ•จ์ˆ˜๋ฉด ํŒŒ์ผ ์ŠคํŠธ๋ฆผ์„ ์—ด ๋•Œ ํž™์— ํ• ๋‹น๋œ๋‹ค. "_IO_FILE" ๊ตฌ์กฐ์ฒด์˜ ์ •์˜๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. struct _IO_FILE { int _flags;/* High-order word is _IO_MAGIC; rest is flags. */ /* The following pointers correspond to the C++ streambuf protocol. */ char *_IO_read_ptr;/* Current read pointer */ char *_IO_read_end;/* End of get area. */ char *_IO_read_base;/* Start o..