๋“œ๋ฆผํ•ต 5

[CodeEngn] Malware L06

์ด๋ฒˆ ๋ฌธ์ œ๋Š” ๊ฐ„๋‹จํžˆ Flow graph ์ด๋ฏธ์ง€๋ฅผ ๋ณด๊ณ  Thread Mutex๋ฅผ ์ฐพ๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.   Flow์˜ ์‹œ์ž‘์ž…๋‹ˆ๋‹ค. ์‹œ์ž‘ ๋ถ€๋ถ„๋ถ€ํ„ฐ mutex๋ฅผ ์ƒ์„ฑํ•˜๋Š” CreateMutexA ํ•จ์ˆ˜๊ฐ€ ์žˆ์ง€๋งŒ, ์ด์–ด์„œ GetLastError๊ฐ€ ํ˜ธ์ถœ๋˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์•„ ๋ฎคํ…์Šค ์ƒ์„ฑ์ด ์‹คํŒจ๋˜์—ˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. GetLastError ํ•จ์ˆ˜๋Š” ์˜ค๋ฅ˜ ์ฝ”๋“œ๋ฅผ ๋ฐ˜ํ™˜ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์‹คํŒจํ•œ ์ด์œ ๋ฅผ ํŒŒ์•…ํ•˜๋ ค๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.   ๊ทธ ์•„๋ž˜๋ฅผ ์‚ดํŽด๋ณด๋‹ˆ ๋‹ค์‹œ ํ•œ ๋ฒˆ CreateMutexA ํ•จ์ˆ˜๊ฐ€ ํ˜ธ์ถœ๋ฉ๋‹ˆ๋‹ค. ์ด๋•Œ ์„ฑ๊ณต์ ์œผ๋กœ ํ˜ธ์ถœ๋˜์—ˆ๊ธฐ์— CreateMutexA ๋ฐ˜ํ™˜๊ฐ’์„ ํ†ตํ•ด ๋ฎคํ…์Šค ํ•ธ๋“ค hMutex์— ์ €์žฅํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.   ์ •๋‹ต์ธ Thread Mutex๋Š” ๋ฎคํ…์Šค ์ด๋ฆ„์„ ์ฐพ์œผ๋ผ๋Š” ๊ฒƒ ๊ฐ™์œผ๋‹ˆ CreateMutexA ํ•จ์ˆ˜์˜ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ๋“ค์—ฌ๋‹ค๋ณด๋ฉด..

Study/wargame 2024.12.31

[Dreamhack] Secure Mail

Secure Mail์€ ๋ณด์•ˆ ๋ฉ”์ผ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ฐพ๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.   ์ด๋ฒˆ ๋ฆฌ๋ฒ„์‹ฑ ๋ฌธ์ œ๋Š” html ํŒŒ์ผ์ž…๋‹ˆ๋‹ค. ์‹คํ–‰ํ•˜๋ฉด ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•  ์ˆ˜ ์žˆ๋Š” ํผ์ด ์žˆ์Šต๋‹ˆ๋‹ค.  html๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๊ณ  Confirm ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜๋ฉด, ์ž…๋ ฅํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ํŒŒ๋ผ๋ฏธํ„ฐ๋กœ ํ•˜๋Š” ๋‚ด๋ถ€ javascript ํ•จ์ˆ˜ _0x9a220๋ฅผ ํ˜ธ์ถœํ•ฉ๋‹ˆ๋‹ค.   JS: _0x9a220 ํ•จ์ˆ˜ ๋ถ„์„_0x9a220๊ฐ€ ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ์˜ ๋ฉ”์ธ ํ•จ์ˆ˜๋กœ, ์ž…๋ ฅ๋œ ์ƒ๋…„์›”์ผ์„ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.   _0x9a220๋Š” ๋ณ€์ˆ˜ file์— ์ €์žฅ๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณตํ˜ธํ™”(AES-128-CBC)ํ•˜์—ฌ ๋ณ€์ˆ˜ dfbora์— ์ €์žฅํ•˜๊ณ  ์ด๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๊ฒ€์ฆ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.   ์ž…๋ ฅ๋œ ์ƒ๋…„์›”์ผ์„ for๋ฌธ์„ ํ†ตํ•ด ์ž์ฒด์ ์ธ ์•Œ๊ณ ๋ฆฌ์ฆ˜์„ ๊ฑฐ์ณ ๋‚œ๋…ํ™”๋œ ๋ฐ์ดํ„ฐ๋กœ ๋ณ€์ˆ˜ odradurs1์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.   ์ž…๋ ฅ ๋ฐ›..

Study/wargame 2024.12.31

[Dreamhack] rev-basic-2

correct๋ฅผ ์ถœ๋ ฅํ•˜๋„๋ก ํ•˜๋Š” ๋ฌธ์ž์—ด์„ ์ฐพ๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.   ๋ฌธ์ œ ํŒŒ์ผ chall2.exe๋ฅผ ์‹คํ–‰ํ•ด๋ณด๋‹ˆ Input ๋ฌธ์ž์—ด์„ ํ†ตํ•ด ์ž…๋ ฅ๊ฐ’์„ ๋ฐ›์Šต๋‹ˆ๋‹ค.x64dbg๋ฅผ ํ†ตํ•ด Input ๋ฌธ์ž์—ด์„ ์ฐธ์กฐํ•˜๋Š” ๊ณณ์— BP๋ฅผ ๊ฑธ๊ณ  ์‹คํ–‰ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.   Input ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅํ•˜๋Š” ์ฃผ์†Œ์— break๊ฐ€ ๊ฑธ๋ ค ๋ฉˆ์ท„์Šต๋‹ˆ๋‹ค.๊ทธ ์•„๋ž˜๋ถ€ํ„ฐ ์ž…๋ ฅ๊ฐ’์„ ๋ฐ›๊ณ (0x7FF72C421164), ์ž…๋ ฅ๊ฐ’์„ ๋น„๊ตํ•˜์—ฌ(0x7FF72C42116E),Correct ํ˜น์€ wrong ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅ(0x7FF72C42118D)ํ•ฉ๋‹ˆ๋‹ค.   0x7FF72C42116E์—์„œ ํ˜ธ์ถœํ•˜๋Š” 0x7FF72C421000 ์ฃผ์†Œ์—์„œ ์ž…๋ ฅ๊ฐ’์„ ๋น„๊ตํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ •๋‹ต์ด ์žˆ์„ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์ž…๋ ฅ๋ฐ›์€ ๊ฐ’๊ณผ ์ •๋‹ต์„ ๋น„๊ตํ•˜๋Š” ๋ถ€๋ถ„์„ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค.     ๋จผ์ € ์ฒซ ๋ฒˆ์งธ ๋ฌธ์ž๊ฐ€ 0x7FF72C42..

Study/wargame 2024.12.27

[Dreamhack] rev-basic-1

rev-basic-1๋„ rev-basic-0์™€ ๋˜‘๊ฐ™์ด correct๋ฅผ ์ถœ๋ ฅํ•˜๋Š” ์ž…๋ ฅ๊ฐ’์„ ์ฐพ๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.   ์‹คํ–‰ํ•˜๋ฉด ์ž…๋ ฅ๊ฐ’์„ ๋ฐ›๊ธฐ ์œ„ํ•ด input ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค.   input ๋ฌธ์ž์—ด์„ ์ฐพ์•„ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.   ํ”„๋กœ๊ทธ๋žจ์€ ๋ฐ›์€ ์ž…๋ ฅ๊ฐ’์„ cmp๋ฅผ ํ†ตํ•ด ๋น„๊ตํ•ฉ๋‹ˆ๋‹ค.๋จผ์ € ์ฒซ ๋ฒˆ์งธ ๋ฐ”์ดํŠธ๊ฐ€ 43h, ์ฆ‰ C์ธ์ง€ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.  ์ฒซ ๋ฒˆ์งธ ๋ฌธ์ž๊ฐ€ C๊ฐ€ ์•„๋‹ˆ๋ฉด 0x7FF6ACC9101E ์ฃผ์†Œ์—์„œ jmpํ•˜์—ฌ ๋น„๊ต๋ฅผ ์ข…๋ฃŒํ•ฉ๋‹ˆ๋‹ค.   ์ฒซ ๋ฒˆ์งธ ๋ฌธ์ž๊ฐ€ C๊ฐ€ ๋งž์œผ๋ฉด 0x7FF6ACC91023 ์ฃผ์†Œ๋กœ ์ ํ”„ํ•ฉ๋‹ˆ๋‹ค.๊ทธ๋ฆฌ๊ณ  ๋˜ ์—ฌ๋Ÿฌ ๋ฒˆ์˜ cmp ๋ช…๋ น์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์•„ ์ž…๋ ฅ๊ฐ’์˜ ํ•œ ๋ฐ”์ดํŠธ์”ฉ ๋น„๊ตํ•˜๋Š” ์ฝ”๋“œ์ธ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.  ๋น„๊ตํ•˜๋Š” ๋ฌธ์ž์—ด์„ ๋ชจ์•„๋ณด๋‹ˆ flag๊ฐ€ Compar3_the_ch4ract3r์ธ ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.์ž…๋ ฅ๊ฐ’..

Study/wargame 2024.12.19

[Dreamhack] rev-basic-0

correct๋ฅผ ์ถœ๋ ฅํ•˜๋„๋ก ํ•˜๋Š” flag๋ฅผ ์ฐพ๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.   ๋จผ์ € ์‹คํ–‰ํ•ด๋ณด๋‹ˆ ๋‹ต์„ ์ž…๋ ฅ ๋ฐ›๊ธฐ ์œ„ํ•ด input ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค.   ์ž…๋ ฅ๊ฐ’์„ ๋ฐ›์œผ๋ฉด ๋‹ต์„ ์ฒดํฌํ• ํ…Œ๋‹ˆ input ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅํ•˜๋Š” ์ฝ”๋“œ๋ฅผ ์ฐพ์•„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์ฐธ์กฐํ•˜๋Š” ๋ฌธ์ž์—ด์„ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค.    input ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅํ•˜๋Š” ์ฝ”๋“œ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.   vfscanf์„ ํ†ตํ•ด ์ž…๋ ฅ๊ฐ’์„ ๋ฐ›๊ณ   RCX์— ์ž…๋ ฅ๊ฐ’(ddddddddd)์ด ์ €์žฅ๋œ ์ฃผ์†Œ๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.   00007FF6C68F1000 ์ฃผ์†Œ๋กœ ์ง„์ž…ํ•˜๋ฉด   ๋ฌธ์ž์—ด์„ ๋น„๊ตํ•˜๋Š” strcmp๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.    ๋ฌธ์ž์—ด์„ ๋น„๊ต๋ฅผ ์œ„ํ•ด RDX์—๋Š” ์ •๋‹ต ๋ฌธ์ž์—ด, RCX์—๋Š” ์ž…๋ ฅ๋ฐ›์€ ๋ฌธ์ž์—ด ์ฃผ์†Œ๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.  ํ™•์ธ์„ ์œ„ํ•ด ๋น„๊ตํ•˜๋Š” ์ž…๋ ฅ๊ฐ’์„ ๋ฐ”๊ฟ”์คฌ์Šต๋‹ˆ๋‹ค.  Correct ๋ฌธ์ž์—ด์„ ์ถœ๋ ฅํ•ฉ๋‹ˆ๋‹ค

Study/wargame 2024.12.18