0CTF 2018 BabyHeap
0CTF 2018 Babyheap
前言
上周
0CTF临危受命,就做出一道题, 感觉思路很新颖, 分享一下.
题目分析
1. checksec
Arch: amd64-64-little RELRO: Full RELRO Stack: Canary found NX: NX enabled PIE: PIE enabled
结论: 保护全开, 必是堆溢出之类的.
2. 结构体
struct node{
int inUse;
int size;
char* ptr;
}
3. 菜单
===== Baby Heap in 2018 ===== 1. Allocate 2. Update 3. Delete 4. View 5. Exit Command:
4. Allocate(可以申请最大0x58字节的内存)
Command: 1 Size: 20 Chunk 0 Allocateed
5. Update(Off_By_One漏洞)
Command: 2 Index: 0 Size: 20 Content: AAAAAAAAAAAAAAAAAAAA Chunk 0 Updated
6. Delete
Command: 3 Index: 0 Chunk 0 Deleted
7. View
Command: 4 Index: 0 Chunk[0]: AAAAAAAAAAAAAAAAAAAA
8. Exit
Command: 5
3. 漏洞分析
Off_By_One:Off_By_One是指我们能够多写入一个字节, 这种漏洞往往和对边界的长度验证不严格和字符串操作有关.
小栗子:
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
int main(void){
char* buf1 = malloc(0x28);
char* buf2 = malloc(0x40);
read(0, buf1, 0x29); //0x29 - 0x28 = 1, 多写入一个字节
printf("buf1 is %s\n", buf1);
return 0;
}
编译gcc -g example.c -o example
运行
./off_by_one
(输入前)
0x602000: 0x0000000000000000 0x0000000000000031
0x602010: 0x0000000000000000 0x0000000000000000
0x602020: 0x0000000000000000 0x0000000000000000
0x602030: 0x0000000000000000 0x0000000000000051 -------
0x602040: 0x0000000000000000 0x0000000000000000 |
0x602050: 0x0000000000000000 0x0000000000000000 |
0x602060: 0x0000000000000000 0x0000000000000000 |
0x602070: 0x0000000000000000 0x0000000000000000 |
|
(输入后) |
0x602000: 0x0000000000000000 0x0000000000000031 |
0x602010: 0x4141414141414141 0x4141414141414141 |
0x602020: 0x4141414141414141 0x4141414141414141 |
0x602030: 0x4141414141414141 0x0000000000000041 <-------
0x602040: 0x0000000000000000 0x0000000000000000
0x602050: 0x0000000000000000 0x0000000000000000
0x602060: 0x0000000000000000 0x0000000000000000
0x602070: 0x0000000000000000 0x0000000000000000
结论: 可以修改chunk size大小.
4. 题目分析
漏洞点: Update功能可以允许我们多输入一个字节.
我们需要解决如下问题
- 如何
libc地址 ?- 如何获取
shell?
注意:上传附件及图片大小不得大于30M。
⚠️ 版权声明:
本博客所有内容(含教程、源码、工具)仅供个人技术学习与研究交流使用,严禁商用、倒卖、二次分发及非法用途。
未经作者书面授权,任何组织或个人不得转载、复制或用于其他平台,违者将追究相关责任。
复制成功
