Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Attack N Defence
Search
Buzzvil
January 23, 2019
230
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Attack N Defence
Buzzvil
January 23, 2019
More Decks by Buzzvil
See All by Buzzvil
220903_GFS
buzzvil
0
660
Git 해부하기 2 + 3
buzzvil
0
74
Metastable Failure
buzzvil
0
380
Git 해부하기
buzzvil
0
92
Introduction to Plate Solving
buzzvil
0
83
Airbnb Minerva
buzzvil
0
540
Shape up 방법론
buzzvil
0
1.1k
Buzzvil Billing Data Pipeline
buzzvil
0
740
Journey of Dash's release-cycle
buzzvil
0
290
Featured
See All Featured
State of Search Keynote: SEO is Dead Long Live SEO
ryanjones
0
240
コードの90%をAIが書く世界で何が待っているのか / What awaits us in a world where 90% of the code is written by AI
rkaga
62
45k
The Limits of Empathy - UXLibs8
cassininazir
1
560
How to Talk to Developers About Accessibility
jct
2
450
Pawsitive SEO: Lessons from My Dog (and Many Mistakes) on Thriving as a Consultant in the Age of AI
davidcarrasco
0
200
GitHub's CSS Performance
jonrohan
1033
470k
Navigating the Design Leadership Dip - Product Design Week Design Leaders+ Conference 2024
apolaine
1
380
New Earth Scene 8
popppiees
3
2.4k
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
28
3.6k
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
2
430
The Illustrated Guide to Node.js - THAT Conference 2024
reverentgeek
1
420
How To Stay Up To Date on Web Technology
chriscoyier
790
250k
Transcript
Attack N Defence - 0101 - JD
Notice • Solution is not perfect. • Also, sample is
not perfect. • So, we should have imagine.
Process Product Attack Defence
Setup • docker pull jongsu253/dev-seminar:0.1 • docker run --privileged --cap-add=SYS_PTRACE
--security-opt seccomp=unconfined -it ed79ba87900b /bin/bash
Let’s do it now!
Section I - Hooking Dynamic Linking libc.so program call printf@PLT
PLT[0]: call resolver PLT[X]: jmp *GOT[X] push XX jmp PLT[0] GOT[X]: &printf printf: … ld.so resolver: … program call printf@PLT PLT[0]: call resolver PLT[X]: jmp *GOT[X] push XX jmp PLT[0] GOT[X]: &hooker libc.so printf: … ld.so resolver: … hook.so hooker: …
Section I - Hooking Dynamic Loading ld.so libc.so libm.so libhook.so
printf read write pow sqrt ceil printf read write libraries: libc.so libm.so libhook.so ld.so libraries: libhook.so libc.so libm.so libc.so libm.so libhook.so printf read write printf read write pow sqrt ceil
Section II - Debugger Process A Process B name phone
address … Process A Process B name phone address … access / control kernel access / control
Section II - Debugger Process A Process B name phone
address … kernel access / control Process C 1 2
Section II - Debugger Process A Process B name phone
address … kernel Process B` fork Attached Not Attached
Section II - Debugger Process A Process B kernel Attached
Thread 1 Thread 2 Thread 3 Thread N
Section II - Debugger Process A Process B kernel Thread
1 Thread 2 Thread 3 Thread N Attached Process C
What do you think …?
Q & A
Thank you!