๐Ÿ‘ฉ๐Ÿป‍๐Ÿ’ป ๊ฐ“์ƒ ์ง์žฅ์ธ ๋‚จ๋ฐ”์˜ค
article thumbnail
[ ๋ณด์•ˆ ์šฉ์–ด ์ •๋ฆฌ ]
Security 2023. 7. 9. 16:11

CVSS (Common Vulnerability Scoring System) ์†Œํ”„ํŠธ์›จ์–ด ์ทจ์•ฝ์ ์˜ ํŠน์„ฑ๊ณผ ์‹ฌ๊ฐ๋„๋ฅผ ํŒŒ์•…ํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋˜๋Š” ๊ฐœ๋ฐฉํ˜• ํ”„๋ ˆ์ž„์›Œํฌ์ด๋‹ค. CVSS๋ฅผ ์ด์šฉํ•˜๋ฉด ์กฐ์ง์€ ํ†ต์ผ๋œ ๋“ฑ๊ธ‰ ๋ฐฉ์‹์œผ๋กœ ์—ฌ๋Ÿฌ ์†Œํ”„ํŠธ์›จ์–ด์— ๊ฑธ์นœ IT ์ทจ์•ฝ์ ์˜ ์‹ฌ๊ฐ๋„๋ฅผ ํ‰๊ฐ€ํ•  ์ˆ˜ ์žˆ๊ณ , CVSS ์ ์ˆ˜๋ฅผ ํ†ตํ•ด ์ฆ‰์‹œ ๊ฐœ์„ ์ด ํ•„์š”ํ•œ ์ทจ์•ฝ์ ์˜ ์šฐ์„ ์ˆœ์œ„๋ฅผ ๊ฒฐ์ •ํ•  ์ˆ˜ ์žˆ๋‹ค. Log4j JNDI์™€ LDAP๋ฅผ ์ด์šฉํ•œ ์ทจ์•ฝ์ ์ด๋‹ค. JNDI๋Š” Java ํ”„๋กœ๊ทธ๋žจ์ด ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ํ†ตํ•ด ๋ฐ์ดํ„ฐ(Java ๊ฐ์ฒด ํ˜•ํƒœ)๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” ๋””๋ ‰ํ† ๋ฆฌ ์„œ๋น„์Šค์ด๋‹ค. JNDI๋Š” ์ด๋Ÿฌํ•œ ๋””๋ ‰ํ† ๋ฆฌ ์„œ๋น„์Šค๋ฅผ ์œ„ํ•ด ๋‹ค์–‘ํ•œ ์ธํ„ฐํŽ˜์ด์Šค๊ฐ€ ์กด์žฌํ•˜๋Š”๋ฐ ๊ทธ ์ค‘ ํ•˜๋‚˜๊ฐ€ LDAP์ด๋‹ค. Java ํ”„๋กœ๊ทธ๋žจ๋“ค์€ ์•ž์„œ ๋งํ•œ JNDI์™€ LDAP๋ฅผ ํ†ตํ•ด Java ๊ฐ์ฒด๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋‹ค..

[๊ณผ์ œ ์ •๋ฆฌ] Windows Driver ์ทจ์•ฝ์ 
Security 2023. 3. 17. 23:11

https://s3.us-west-2.amazonaws.com/secure.notion-static.com/41f43383-5b84-458d-b1a1-1c9a6728ec44/Windows_Driver_%EC%B7%A8%EC%95%BD%EC%A0%90.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Content-Sha256=UNSIGNED-PAYLOAD&X-Amz-Credential=AKIAT73L2G45EIPT3X45%2F20230317%2Fus-west-2%2Fs3%2Faws4_request&X-Amz-Date=20230317T140756Z&X-Amz-Expires=86400&X-Amz-Signature=e016480d7fe689f47f51771e83aaf00c261d83..

[๊ณผ์ œ ์ •๋ฆฌ] SSL library hooking
Security 2023. 3. 17. 23:06

FILE HOOK์„ ์ˆ˜์ •ํ•ด์„œ SSL ํ†ต์‹ ๊ณผ์ •์„ ๋กœ๊ทธ๋กœ ๋‚จ๊ธฐ๋Š” ์ฝ”๋“œ๋ฅผ ๊ฐœ๋ฐœํ•˜๋Š” ๊ฒƒ์ด ๊ณผ์ œ์˜€๋‹ค. ์šฐ์„  ์•„๋ž˜๋Š” SSL์ฝ”๋“œ๋ฅผ ์ถ”๊ฐ€ํ•œ hook.c ์ฝ”๋“œ์ด๋‹ค. #hook.c #define _GNU_SOURCE #include #include #include #include #include extern char * __progname; static int (*hook_SSL_read)(SSL *ssl, char *buf, int num) = NULL; //SSL_read hooking int SSL_read(SSL *ssl, void *buf, int num){ //SSL_read ์ •์ƒ์ ์œผ๋กœ ๋™์ž‘ํ•˜๊ฒŒ๋” if (hook_SSL_read == NULL) hook_SSL_read = dlsym(RTLD_NEXT, "SSL..

[๊ณผ์ œ ์ •๋ฆฌ] Remote Code Execution
Security 2023. 3. 17. 23:05

๊ณผ์ œ2 64bit Remote Code Execution ๋ฉ˜ํ† ๋‹˜์ด ์ฃผ์‹  64bit exploit code์—์„œ ๊ฐ€์ ฏ์„ ๋ฐ”๊พธ์–ด ์‹œ๋„ํ•ด๋ณด์•˜๋‹ค. fts3_tokenizer ์ทจ์•ฝ์ ์„ ์ด์šฉํ•œ ๊ฒƒ์œผ๋กœ ์ƒˆ๋กœ์šด tokenizer๋ฅผ ๋“ฑ๋กํ•  ๋•Œ, ๋‘ ๊ฐ€์ง€ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์˜€๋‹ค. ์ฒซ ๋ฒˆ์งธ๋กœ ๋“ฑ๋ก๋œ tokenizer์˜ ์ฃผ์†Œ๋ฅผ ์ฟผ๋ฆฌํ•˜๋ฉด ์ฃผ์†Œ๊ฐ€ ์œ ์ถœ๋œ๋‹ค๋Š” ์ ๊ณผ

[๊ณผ์ œ ์ •๋ฆฌ] CARVING ํŽŒ์›จ์–ด ์ถ”์ถœ
Security 2023. 3. 17. 23:03

https://skaqnrudckfcjd.notion.site/BOB11-fd6908ab660a4957bf7d55d6da1f66cd [BOB11][๋‚จํ˜„๊ฒฝ]ํŽŒ์›จ์–ด์ถ”์ถœ์‹ค์Šต๊ณผ์ œ ์šฐ์„  ๊ฐ™์€ CRC๋ฅผ ๊ฐ€์ง€๋Š” ํ—ค๋”๋ฅผ ํ™•์ธํ•˜๋ฉด์„œ, ECํ—ค๋”์™€ VIDํ—ค๋”๋กœ ๊ฐ™์€ ํŒŒ์ผ๋ผ๋ฆฌ ๋ฌถ์–ด๋ณด์•˜๋‹ค. skaqnrudckfcjd.notion.site

[MC++๋ฆฌํฌํŠธ]
Security 2023. 3. 17. 23:00

https://skaqnrudckfcjd.notion.site/MC-86acb10429b14fe098b205c7a52784d3 [MC++๋ฆฌํฌํŠธ]๋‚จํ˜„๊ฒฝ c++์€ ์‚ฌ์šฉ์ž๊ฐ€ ์Šค์Šค๋กœ ๋ฉ”๋ชจ๋ฆฌ๋ฅผ ํ• ๋‹นํ•˜๊ณ  ํ•ด์ œํ•˜๋Š” ๊ณผ์ •์„ ๊ฑฐ์นœ๋‹ค. C++์—์„œ๋Š” new, delete๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค. ์ด ๋•Œ ํ• ๋‹น๋ฐ›์€ ๋ฉ”๋ชจ๋ฆฌ๋ฅผ ํ•ด์ œํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ์—” ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜(memory leak)์ด ๋ฐœ์ƒํ•œ๋‹ค. ์ด์™€ ๊ฐ™์€ skaqnrudckfcjd.notion.site

[RSA] code
Security 2023. 3. 17. 22:58

๋ฌธ์ œ HOMEWORK01 Bob์˜ RSA ๊ณต๊ฐœํ‚ค (e,n)์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์„ฑ๋ถ„์„ ๊ฐ€์ง„๋‹ค. e=65537 n=179769313486231590772930519078902473361797697894230657273430081157732675805500963132708477322407536021120113879871393357658789768814416622492847430652885096550381956977355009744407642308411545070379136134645709973060633048727107215362312651042098054062317216389604359801702614666769905641776363676873830995947 ์œ„ ์ •๋ณด๋งŒ์„ ์ด์šฉํ•˜์—ฌ Bob์˜ ๊ณต๊ฐœํ‚ค๋กœ ๊ฒ€์ฆ์— ์„ฑ๊ณต..

[IPC] heap-use-after-free crash
Security 2023. 3. 17. 22:57

https://www.notion.so/skaqnrudckfcjd/IPC-_-_HW-1-66f1a73a005d491eab3f34e04a942d17?pvs=4 [IPC]_{๋‚จํ˜„๊ฒฝ}_HW#1 Mojo Bindings for JavaScript ํ™œ์„ฑํ™” www.notion.so Mojo Bindings for JavaScript ํ™œ์„ฑํ™” ./chrome —enable-blink-features=MojoJS bob11.mojom → IBoB11 Mojo ์ธํ„ฐํŽ˜์ด์Šค IDL module blink.mojom; interface IBoB11 { hello() => (); iambinish() => (string whoami); //๊ฒฐ๊ณผ ์ถœ๋ ฅ๋˜๋Š” ๊ณณ init() => (); createInstance() => (pendi..