|
|
|
|
|
| All | Paper |
|
|
±¹³» ¾ÐÃà À¯Æ¿¸®Æ¼ ZIP ÆÄÀÏ Æ÷¸ä Çڵ鸵 Ãë¾à¼º
- 2010. 6. 24
¾ÐÃà À¯Æ¿¸®Æ¼°¡ ZIP ÆÄÀÏ Æ÷¸äÀÇ File name Çʵ带 ÆÄ½Ì ¹× Çڵ鸵ÇÏ´Â °úÁ¤¿¡¼ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾à¼ºÀÌ Á¸ÀçÇÕ´Ï´Ù.
ÀÌ·¯ÇÑ ¹®Á¦Á¡Àº, ÇØ´ç ÇÁ·Î±×·¥ÀÇ Crash ¶Ç´Â ¾ÇÀÇÀûÀÎ ÄÚµåÀÇ ½ÇÇà°ú °°Àº °á°ú·Î À̾îÁú ¼ö ÀÖ½À´Ï´Ù.
º» ±Ç°í¹® ¹ßÇ¥ ½Ã È®ÀεǾîÁø Ãë¾àÇÑ À¯Æ¿¸®Æ¼´Â »§Áý, V3ZIP, ¹ãÅçÀÌ µîÀÔ´Ï´Ù.
Various Hacking - ISEC 2009
- 2009. 8. 7
ISEC 2009ÀÇ ¹ßÇ¥ÀÚ·áÀÔ´Ï´Ù. Various HackingÀ̶ó´Â ÁÖÁ¦·Î ÁøÇàÇß¾ú°í, ½ÇÁ¦ ³»¿ëÀº Å©°Ô µÎ °¡Áö·Î ±¸ºÐµÇ¾î ÀÖ½À´Ï´Ù.
Çϳª´Â Mysql InjectionÀ» ÅëÇÏ¿© ½©À» ȹµæÇϴ°Ϳ¡ ´ëÇÑ ³»¿ëÀ̰í, ³ª¸ÓÁö Çϳª´Â ¸®´ª½º Ä¿³Î Ãë¾à¼º¿¡ °üÇÑ °ÍÀ¸·Î,
´ç½Ã Ä¿³Î±â¹Ý ÀͽºÇ÷ÎÀÕ¿¡ ºó¹øÇÏ°Ô Àû¿ëµÇ¾ú´ø Null Dereference Ãë¾à¼ºÀÇ ¼³¸íÀ» Áß½ÉÀ¸·Î Çϰí ÀÖ½À´Ï´Ù.
DEFCON 2009 Capture The Flag º»¼± ¹®Á¦ Ç®ÀÌ - tucod
- 2009. 8. 7
¿ÃÇØ ºÎÅÍ´Â ±âÁ¸ CTFÀÇ ¿î¿µÀ» ´ã´çÇØ¿À´ø kenshoto°¡ ¹°·¯³ª°í ddtekÀÌ »õ·Î¿î ¿î¿µÁøÀ¸·Î ¼±Á¤µÇ¾ú½À´Ï´Ù. ´öºÐ¿¡ ÀüüÀûÀÎ
¿î¿µ¿¡ ´ëÇÑ ¹æ½ÄÀ̳ª °¢ ¹®Á¦ °³º°ÀÇ ½ºÅ¸ÀÏ È¤Àº ¼öÁØ µî¿¡ ¾î´ÀÁ¤µµ º¯È°¡ ÀÖ¾ú½À´Ï´Ù. º» ¹®¼¿¡¼´Â tucod ¹ÙÀ̳ʸ®¿¡
´ëÇÑ Ç®À̸¦ ±â¼ú ÇÒ °ÍÀ̸ç, IDAÀÇ disassemble °á°ú¸¦ ÅëÇÏ¿© ÁøÇàÇϰíÀÚ ÇÕ´Ï´Ù. ƯÁ¤ °ø°Ý ±â¼ú¿¡ ´ëÇÑ »ó¼¼ ¼³¸íÀ̳ª
ÀϹÝÀûÀÎ ·çƾÀÇ ºÐ¼® ȤÀº ÀͽºÇ÷ÎÀÕ ´ç½ÃÀÇ ½ÃÇàÂø¿À µî°ú °°Àº ºÎ°¡ÀûÀÎ ¼³¸íÀº µÇµµ·Ï Á¦¿ÜÇϰí ÇÙ½ÉÀûÀÎ ³»¿ëÀ» À§ÁÖ·Î
±â¼úÇÏ¿© ³ª°¥ °ÍÀÔ´Ï´Ù.
777 DDoS ¾Ç¼ºÄÚµå ºÐ¼®
- 2009. 7. 9
2009³â 7¿ù, Çѱ¹°ú ¹Ì±¹ÀÇ ÁÖ¿ä »çÀÌÆ®µéÀÌ ¼ºñ½º °ÅºÎ °ø°Ý(Distributed Denial-of-Service)ÀÇ À§ÇùÀ» ¹Þ°Ô µË´Ï´Ù.
º» ¹®¼´Â ±×·¯ÇÑ °ø°ÝÀÇ ¿øÀÎÀÌ µÇ´Â ¾Ç¼º ÇÁ·Î±×·¥À» Áö±ØÈ÷ °³ÀÎÀûÀÎ °üÁ¡¿¡¼ ÇÊ¿äÇÑ ÀϺθ¸À» Á¤Àû ºÐ¼®ÇÏ¿´°í,
ºÎÁ·ÇÏÁö¸¸ ÇØ´ç ºÎºÐ°ú °ü·ÃÇÏ¿© Á¶±ÝÀÇ Âü°í¶óµµ µÇ°íÀÚ ÇÏ´Â ¸¶À½¿¡ °ø°³ÇÕ´Ï´Ù. ¾Ç¼º Äڵ忡 ´ëÇÑ »ùÇÃ(Sample)À»
¸ðµÎ ±¸ÇÏÁö ¸øÇÏ¿´±â ¶§¹®¿¡ ºÐ¼®¿¡ ¾î´À Á¤µµ Á¦ÇÑÀÌ ÀÖÀ» °ÍÀÓÀ» ¹Ì¸® ¹àÇôµÓ´Ï´Ù.
Defcon CTF 2009 Binary Leetness 100-500 Solutions
- 2009. 7. 4
Äڵ忣Áø(CodeEngn) ¼¼¹Ì³ªÀÇ ¹ßÇ¥ÀÚ·áÀÔ´Ï´Ù. Defcon CTF 2009 Binary Leetness ºÐ¾ßÀÇ ¸ðµç ¹®Á¦ Ç®À̸¦
´ã°í ÀÖÀ¸¸ç, Defcon CTF¿Í °¢ ¹®Á¦ À¯Çü¿¡ ´ëÇÑ °£·«ÇÑ ¼Ò°³¿Í ÇÔ²² ´ëȸ ±â°£µ¿¾È Á¶±Ý ÀλóÀûÀ̾ú´ø PwnableÀÇ
ù ¹øÂ° ¹®Á¦¿¡ ´ëÇÑ ¼Ò°³¸¦ Æ÷ÇÔÇϰí ÀÖ½À´Ï´Ù.
Mem Jacking
- 2009. 1. 24
º» ¹®¼¿¡¼´Â Mem-Jacking¿¡ ´ëÇÑ °£·«ÇÑ ¼³¸í, ¹æ¾îÃ¥°ú ÇÔ²² ±×¿¡ ´ëÇÑ ±â¼ú Áõ¸í Äڵ带 Æ÷ÇÔÇϰí ÀÖ½À´Ï´Ù.
ÇØ´ç ±â¼úÀº milw0rm¿¡¼ °ø°³µÈ Mem Jacking ¹®¼¸¦ ±â¹ÝÀ¸·Î Çϰí ÀÖÀ¸¸ç ÀÌ·¯ÇÑ ±â¼ú¸íÀº ±âÁ¸¿¡ ºÒ¸®¿öÁö´Â
Session-Hijacking, Click-Jacking¿Í °°Àº ±â¼úµé ó·³ ¾ÇÀÇÀûÀÎ Àǵµ·Î ¸Þ¸ð¸®¸¦ °¡·Îæ´Ù´Â Àǹ̷ΠMem-Jacking
À̶ó´Â ¸íĪÀÌ ¸¸µé¾îÁ³½À´Ï´Ù.
Linux Kernel Memory Disclosure Ãë¾à¼ºÀÇ ±âÃÊ
- 2009. 1. 5
º» ¹®¼¿¡¼´Â Linux Kernel Memory Disclosure Ãë¾à¼ºÀÇ ±âÃÊ¿¡ ´ëÇÏ¿© ¼³¸íÇϰíÀÚ ÇÕ´Ï´Ù. ÀÌ´Â ºñ·Ï Ä¿³Î ·¹º§¿¡¼ÀÇ
Ãë¾à¼ºÀÌÁö¸¸ Àü¹ÝÀûÀ¸·Î »ó´çÈ÷ ½¬¿î °³³ä¿¡ ¼ÓÇϸç Ä¿³ÎÀ̶ó´Â »ý¼ÒÇÔ ¶ÇÇÑ Å©°Ô ´À³¥ ¼ö ¾øÀ» °ÍÀÔ´Ï´Ù. ÇØ´ç Ãë¾à¼ºÀº
·çÆ® ±ÇÇÑÀ» ȹµæÇÒ ¸¸ÅÀÇ Á÷Á¢ÀûÀÎ À§Ç輺Àº Áö´Ï°í ÀÖÁö ¾ÊÁö¸¸ ¸Þ¸ð¸® »ó¿¡ Á¸ÀçÇÏ´Â ÆÐ½º¿öµå¿Í °°Àº Áß¿äÇÑ µ¥ÀÌÅ͸¦
ȹµæÇÒ ¼ö ÀÖ´Â °£Á¢ÀûÀÎ À§Ç輺Àº ÃæºÐÇÕ´Ï´Ù. ±â¹ý¿¡ ´ëÇÑ ¼³¸íÀº ½ÇÁ¦ ¹ßÇ¥µÈ Ãë¾à¼ºÀ» ÅëÇØ ÁøÇàÇÒ °ÍÀÔ´Ï´Ù.
ActiveX Ãë¾à¼º °ø°Ý½ÃÀÇ Unicode Shellcode
- 2008. 8. 27
¸¹Àº »ç¶÷µéÀÌ ActiveX Ãë¾à¼º °ø°Ý ½Ã À¯´ÏÄÚµå»óÀÇ ¹®Á¦Á¡À¸·Î ÀÎÇÏ¿© ¾î·Á¿òÀ» °Þ°í ÀÖ½À´Ï´Ù. ÀÌ´Â ¿µ¹®ÆÇ À©µµ¿ì¸¦ Á¦¿ÜÇÑ
¸ðµç »ç¿ëÀڵ鿡°Ô ÇØ´çµÇ´Â °ÍÀε¥, À©µµ¿ì´Â ´Ù¾çÇÑ ¾ð¾îÀÇ Áö¿øÀ» À§ÇÏ¿© ³»ºÎÀûÀ¸·Î MBCS(Multi Byte Character Set)¸¦
Àû¿ëÇϰí ÀÖ½À´Ï´Ù. ¶§¹®¿¡ ¿ì¸®°¡ »ðÀÔÇÑ µ¥ÀÌÅͰ¡ ±×¿¡ ¸Â°Ô º¯°æµÇ¹Ç·Î ½© ÄÚµå Á¦ÀÛÀÌ Èûµé´Ù´Â °ÍÀÌ ÀϹÝÀûÀÎ »ç½ÇÀÔ´Ï´Ù.
º» ¹®¼´Â Áö±Ý±îÁö °ü·Ã ¹®Á¦·Î °í»ýÇß´ø ±×¸®°í ¾ÕÀ¸·Î °øºÎÇϰíÀÚ ÇÏ´Â ¸ðµç ºÐµéÀ» À§ÇÏ¿© ÀÛ¼ºÇÏ¿´½À´Ï´Ù.
DEFCON 2008 Capture The Flag º»¼± ¹®Á¦ Ç®ÀÌ - bakalakadakaChat_d
- 2008. 8. 17
µ¥ÇÁÄÜ º»¼± ¹®Á¦ÀÇ Ç®À̸¦ ½á¼ °ø°³ÇÏ´Â ÀÌÀ¯´Â, ¿©·¯°¡Áö »çÁ¤ ¶§¹®¿¡ º»¼±¿¡ Á÷Á¢ Âü°¡ÇÏÁö ¸øÇÑ »ç¶÷µé¿¡°Ô °£Á¢ÀûÀ¸·Î³ª¸¶
°æÇèÀ» ÁÖ°í ½ÍÀº°Í°ú, ¼¼°èÀûÀÎ ´ëȸ¶ó°í ÇØ¼ °áÄÚ ¾î·ÆÁö¸¸Àº ¾Ê´Ù´Â °ÍÀ» º¸ÀÌ°í ½Í¾î¼ÀÔ´Ï´Ù. ¶§¹®¿¡ ¹®Á¦ ¼öÁØÀ» °í·ÁÇÏ¿©
Ç®ÀÌ ´ë»óÀ» ¼±ÅÃÇßÁö¸¸ ¾Æ¹«Æ°, ÈÄÀÚÀÇ °æ¿ì¸¦ ´Ù½Ã ¸»ÇÏÀÚ¸é ÀÏÁ¾ÀÇ Capture The Flag¿¡ ´ëÇÑ °íÁ¤°ü³äÀ» ¾ø¾Ö°í ÀڽۨÀ» ¾òÀ»
¼ö ÀÖµµ·Ï µµ¿ÍÁÖ°í ½ÍÀº ¸¶À½¿¡ ¹®¼¸¦ ÀÛ¼ºÇß½À´Ï´Ù.
FLACK ¿ö°ÔÀÓ Ç®ÀÌ
- 2008. 6. 30
FLACK ¿ö°ÔÀÓÀº SQL Injection°ú °ü·ÃµÈ ¹®Á¦µé·Î ÀÌ·ç¾îÁ® ÀÖÀ¸¸ç ¼¹ö´Â Linux, Mysql, Apache ±â¹ÝÀÔ´Ï´Ù.
¸ðµç ¹®Á¦ÀÇ ÃÖÁ¾ÀûÀÎ ¸ñÇ¥´Â ·Î±×ÀÎÀÇ ¼º°øÀ̰í, Àüü ¹®Á¦´Â °¢°¢ Level1~Level5, Other1, Other3À¸·Î ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.
¹®Á¦ À¯ÇüÀº ±âº»ÀûÀÎ ÀÎÁõ ¿ìȸºÎÅÍ LOAD_FILE, Blind SQL Injection µî ¾î´À Á¤µµ ´ëÇ¥ÀûÀÎ ±â¹ýµéÀ» Æ÷ÇÔÇϰí ÀÖÀ¸¸ç,
¿ö°ÔÀÓÀº http://zetorownage.xf.cz/ ¿¡¼ Ç® ¼ö ÀÖ½À´Ï´Ù.
Core Rootkit Technology for Linux Kernel 2.6
- 2008
¸®´ª½º Ä¿³Î 2.6ÀÇ ½Ã½ºÅÛ ÄÝ Á¦¾î¿¡ ´ëÇÑ ¹®¼ÀÔ´Ï´Ù. Ä¿³Î 2.4 ¿¡¼ÀÇ ±â¼úÀº ¸¹ÀÌ °ø°³µÇ¾î ÀÖÁö¸¸ 2.6 ºÎÅÍ´Â ¿©·¯°¡Áö
Á¦¾à »çÇ× ¶§¹®¿¡ Àû¿ëÀÌ ¾î·Á¿î °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖÀ¸¸ç Àü¹ÝÀûÀÎ ±â¹Ý ±â¼úÀ» Á¤¸®Çؼ ¹®¼È ÇÑ ÀÚ·áµµ ã±â Èûµì´Ï´Ù.
º» ¹®¼¿¡¼´Â Ä¿³Î 2.6 ¿¡¼ÀÇ ½Ã½ºÅÛ ÄÝ Á¦¾î¿Í °ü·ÃµÈ ÇÙ½É ±â¼ú¿¡ ´ëÇÏ¿© »ó¼¼È÷ ´Ù·ç°í ÀÖ½À´Ï´Ù.
The Way of Binary Copy without Permission
- 2007. 7
Àб⠱ÇÇÑÀÌ Á¸ÀçÇÏÁö ¾Ê´Â ¹ÙÀ̳ʸ®¿¡ ´ëÇÑ º¹»ç¸¦ ¼öÇàÇÏ´Â ¹æ¹ý·Ð ¹× ½ÇÁ¦ ÄÚµåÀÇ Àû¿ë µîÀ» ±â¼úÇÑ ¹®¼ÀÔ´Ï´Ù.
32bit x86 Linux¿Í FreeBSD ȯ°æ¿¡¼ Å×½ºÆ® µÇ¾úÀ¸¸ç ÀϹÝÀûÀ¸·Î Àб⠱ÇÇÑÀÌ ¾ø´Â »óÅÂÀÇ ¹ÙÀ̳ʸ®¿¡ ´ëÇÑ º¹»ç°¡
ºÒ°¡´ÉÇÏ´Ù´Â Æí°ßÀ» Çϳª¾¿ Ç®¾î ³ª°¥ °Í ÀÔ´Ï´Ù. ¹®¼¿Í °ü·ÃµÈ Àüü ÄÚµå´Â Code ¸Þ´º¿¡¼ º¼ ¼ö ÀÖ½À´Ï´Ù.
vmsplice() system call »ç¿ë ¼³¸í°ú ¿¹Á¦
- 2008. 2. 14
´Ù¼Ò »ý¼ÒÇÑ vmsplice() ½Ã½ºÅÛ ÄÝ¿¡ ´ëÇÏ¿© °£·«È÷ ±â¼úÇÏ¿´½À´Ï´Ù.
°ü·Ã Ãë¾à¼º, ÀͽºÇ÷ÎÀÕÀ» ºÐ¼®ÇϽðųª vmsplice() ½Ã½ºÅÛ ÄÝ¿¡ ´ëÇÏ¿© ±Ã±ÝÇϽŠºÐµéÀÌ Àо½Ã¸é ÁÁÀ» °Í °°½À´Ï´Ù.
Ä¿³Î ¹æ¾î ¸ðµâÀ» ÅëÇÑ vmsplice() local root exploit Ãë¾àÁ¡ ÆÐÄ¡
- 2008. 2. 11
Ãë¾àÁ¡ ÀͽºÇ÷ÎÀÕÀ» »ìÆìº» µÚ¿¡ Àá±ñ ¸¸µé¾îº» Ä¿³Î ¹æ¾î¸ðµâ¿¡ ´ëÇØ ±â¼úÇÑ ÆäÀÌÆÛÀÔ´Ï´Ù.
KAIST & POSTECH Science War 7¹ø ¹®Á¦ Ç®ÀÌ
- 2007. 9
´ëȸ ´ç½Ã ¹®Á¦¸¦ ÇØ°áÇÑ Çб³°¡ ¾ø¾î¼ ³¡³ª°í ¹®Á¦Ç®À̸¦ ÀÛ¼ºÇØ º¸¾Ò½À´Ï´Ù.
6th HUST hacking festival race condition report
- 2007. 5
¿äû¿¡ ÀÇÇØ ÀÛ¼ºÇß´ø Race Condition ¹®Á¦ Ç®ÀÌÀÔ´Ï´Ù.
Race ConditionÀ» °øºÎÇϽô ºÐµéÀÌ Âü°íÇϸé ÁÁÀ» °Í °°½À´Ï´Ù.
Shared Library Hijacking For Playing Wargames
- 2005
°£´ÜÇÑ ÆÁ¿¡ ´ëÇØ ±â¼úÇÑ °ÍÀ¸·Î ¹®¼È´Â Á¦°¡ ÇÏÁö ¾Ê¾Ò½À´Ï´Ù.
Universal setreuid() Shellcode
- 2004
°£´ÜÇÑ ³»¿ëÀÇ ÆäÀÌÆÛÀÔ´Ï´Ù.
¿À·¡Àü¿¡ ÀÛ¼ºµÈ ÀÚ·áÀÔ´Ï´Ù.
About Buffering
- 2003
¾ÆÁÖ ¿À·¡Àü¿¡ ¹®ÀÚ¿ Ãâ·Â½Ã ¹öÆÛ¸µ¿¡ ´ëÇØ °£·«È÷ Àû¾î³õÀº ³¯¸²±ÛÀÔ´Ï´Ù.
< Competition Report >
HUST Hacking Festival Report
- 2008. 10. 13
¹®Á¦¸¦ ±¸°æÇÏ´Â µµÁß Áß°£¿¡ °©ÀÛ½º·´°Ô Âü¿©ÇÑ ´ëȸÀÔ´Ï´Ù.
º¸°í¼¸¦ ¸¶°¨ 2½Ã°£ Àü¿¡ ±ÞÈ÷ ½á¼ »ó´çÈ÷ ³¯¸²±ÛÀÔ´Ï´Ù.
°í±³»ý ÇØÅ·/º¸¾È èÇǾð½Ê º¸°í¼
- 2007. 12
remote attack, reversing, analysis, forensic, web hacking µî ´Ù¾çÇÑ ºÐ¾ßÀÇ ¹®Á¦°¡ ÃâÁ¦µÇ¾ú´ø ´ëȸÀÔ´Ï´Ù.
º¸°í¼¸¦ Ç×»ó ÅØ½ºÆ® Çü½ÄÀ¸·Î ½á¿À´Ù°¡ óÀ½À¸·Î Ms Word¸¦ ÀÌ¿ëÇÏ¿© ÀÛ¼ºÇØ º¸¾Ò½À´Ï´Ù.
PADOCON Live Hacking Festival Report
- 2006
PADOCON CTF ¿¹¼±Àü º¸°í¼ÀÔ´Ï´Ù.
PADOCON Live Hacking Festival Report
- 2005
PADOCON CTF ¿¹¼±Àü º¸°í¼ÀÔ´Ï´Ù.
¹®¼ÀÛ¼ºÀº °ÅÀÇ ´ëºÎºÐ wooyaggo´ÔÀÌ Çϼ̽À´Ï´Ù.
û¼Ò³â Á¤º¸º¸È£ Æä½ºÆ¼¹ú º¸°í¼
- 2007. 8
ARM Processor»ó¿¡¼ ÃâÁ¦µÈ ¸¶Áö¸· ¹®Á¦°¡ Àλó±í¾ú´ø ´ëȸÀÔ´Ï´Ù.
û¼Ò³â Á¤º¸º¸È£ Æä½ºÆ¼¹ú º¸°í¼
- 2006
3¹ø ¹®Á¦¿¡ °£´ÜÇÑ ¼öÇÐ °ø½ÄÀ» Àû¿ë½ÃÄÑ º¸¾Ò½À´Ï´Ù.
Argos Hacking Festival Report
- 2007. 3
À¥ »óÀÇ ¸ðÀÇÇØÅ· ȯ°æÀ» "Àǵµ"ÇÑ ¹®Á¦°¡ ¸¹ÀÌ ³ª¿Â ´ëȸ¿´½À´Ï´Ù.
Argos Hacking Festival Report
- 2005
¹®Á¦°¡ 11°³³ª ÃâÁ¦µÇ¾ú´ø ´ëȸÀÔ´Ï´Ù.
¼øÃµÇâ´ë ÃÑÀå¹è °í±³»ý Á¤º¸º¸È£ Æä½ºÆ¼¹ú º¸°í¼
- 2005
°íµîÇб³ 1Çг⠴ç½Ã óÀ½ ¿ì½ÂÇß´ø ´ëȸÀÔ´Ï´Ù.
UDCSC ÇØÅ·´ëȸ º¸°í¼
- 2006. 6
¸¶Áö¸· 2½Ã°£ µ¿¾È Âü°¡Çß´ø ´ëȸÀÔ´Ï´Ù.
Âü°í·Î UDCSC´Â 2006³âÀ» ¸¶Áö¸·À¸·Î »ç¶óÁø ´ëȸÀÔ´Ï´Ù.
±èõ°úÇдëÇÐ ÇØÅ·°æÁø´ëȸ º¸°í¼
- 2003
º¸°í¼´Â °¡Àå ¾û¼ºÇÏÁö¸¸ ÁßÇб³ 2Çг⠴ç½Ã óÀ½À¸·Î Âü°¡Çؼ ÀÔ»óÇß´ø Àú¿¡°Ô´Â Àǹ̰¡ Å« ´ëȸÀÔ´Ï´Ù.
|
|
|