Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Attack N Defence
Search
Buzzvil
January 23, 2019
230
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Attack N Defence
Buzzvil
January 23, 2019
More Decks by Buzzvil
See All by Buzzvil
220903_GFS
buzzvil
0
670
Git 해부하기 2 + 3
buzzvil
0
76
Metastable Failure
buzzvil
0
390
Git 해부하기
buzzvil
0
96
Introduction to Plate Solving
buzzvil
0
87
Airbnb Minerva
buzzvil
0
560
Shape up 방법론
buzzvil
0
1.1k
Buzzvil Billing Data Pipeline
buzzvil
0
740
Journey of Dash's release-cycle
buzzvil
0
300
Featured
See All Featured
ラッコキーワード サービス紹介資料
rakko
1
4.4M
The Anti-SEO Checklist Checklist. Pubcon Cyber Week
ryanjones
0
210
Helping Users Find Their Own Way: Creating Modern Search Experiences
danielanewman
31
3.3k
Future Trends and Review - Lecture 12 - Web Technologies (1019888BNR)
signer
PRO
0
3.7k
The Invisible Side of Design
smashingmag
301
52k
Bridging the Design Gap: How Collaborative Modelling removes blockers to flow between stakeholders and teams @FastFlow conf
baasie
0
660
No one is an island. Learnings from fostering a developers community.
thoeni
21
3.8k
Mind Mapping
helmedeiros
PRO
1
320
Public Speaking Without Barfing On Your Shoes - THAT 2023
reverentgeek
1
540
Fantastic passwords and where to find them - at NoRuKo
philnash
52
3.8k
A Tale of Four Properties
chriscoyier
163
24k
Producing Creativity
orderedlist
PRO
348
40k
Transcript
Attack N Defence - 0101 - JD
Notice • Solution is not perfect. • Also, sample is
not perfect. • So, we should have imagine.
Process Product Attack Defence
Setup • docker pull jongsu253/dev-seminar:0.1 • docker run --privileged --cap-add=SYS_PTRACE
--security-opt seccomp=unconfined -it ed79ba87900b /bin/bash
Let’s do it now!
Section I - Hooking Dynamic Linking libc.so program call printf@PLT
PLT[0]: call resolver PLT[X]: jmp *GOT[X] push XX jmp PLT[0] GOT[X]: &printf printf: … ld.so resolver: … program call printf@PLT PLT[0]: call resolver PLT[X]: jmp *GOT[X] push XX jmp PLT[0] GOT[X]: &hooker libc.so printf: … ld.so resolver: … hook.so hooker: …
Section I - Hooking Dynamic Loading ld.so libc.so libm.so libhook.so
printf read write pow sqrt ceil printf read write libraries: libc.so libm.so libhook.so ld.so libraries: libhook.so libc.so libm.so libc.so libm.so libhook.so printf read write printf read write pow sqrt ceil
Section II - Debugger Process A Process B name phone
address … Process A Process B name phone address … access / control kernel access / control
Section II - Debugger Process A Process B name phone
address … kernel access / control Process C 1 2
Section II - Debugger Process A Process B name phone
address … kernel Process B` fork Attached Not Attached
Section II - Debugger Process A Process B kernel Attached
Thread 1 Thread 2 Thread 3 Thread N
Section II - Debugger Process A Process B kernel Thread
1 Thread 2 Thread 3 Thread N Attached Process C
What do you think …?
Q & A
Thank you!