HOME   ·Î±×ÀΠ  ȸ¿ø°¡ÀÔ
    
ȸ¿ø°¡ÀÔ
ºñ¹Ð¹øÈ£ ã±â ÀÚµ¿·Î±ä
ÀÌÀü°Ô½ÃÆÇ
   free_board
   °Ç°­°Ô½ÃÆÇ
   ¿À¶óŬDB
   Linux
   HTML/javascript
   Áú¹®°ú ´ä
È£¼­±â
   À̹ÌÁö°Ô½ÃÆÇ  
   °Ç°­°Ô½ÃÆÇ  
   À½¾ÇÀÚ·á  
   ¼ºÁØÀÌ °Ô½ÃÆÇ  
 Hit : 5504
 À̸§ : È£¼®  (220.¢½.198.142)
 ³¯Â¥ : 2007-06-18 21:28:53
 Á¦¸ñ : À¥¿¡¼­ ½Ã½ºÅÛÆÄÀÏ °ü¸®Çϱâ good
½© > ½ºÅ©¸³Æ® > suid > ¼ÂÀ¯¾ÆÀ̵ð

µµ¸ÞÀÎÀ» °ü¸®ÇÏ´Â FTP °èÁ¤ÀÌ myname À̶ó°í Çϰí,±× °èÁ¤ ±Ç
Submitted by woonuk on È­, 2006/01/03 - 10:28pm.
µµ¸ÞÀÎÀ» °ü¸®ÇÏ´Â FTP °èÁ¤ÀÌ myname À̶ó°í Çϰí,
±× °èÁ¤ ±ÇÇÑÀ¸·Î ¿øÇÏ´Â ÀÛ¾÷À» ÇÒ¼öÀÖ´Â ½©½ºÅ©¸³Æ®¸¦ mywork.sh ¶ó°í ¸¸µé°í,
À̰ÍÀ» °¨½Î´Â wrapper.c ¸¦ Çϳª ÀÛ¼ºÇÕ´Ï´Ù.

#define REAL_PATH "/home/user/bin/mywork.sh"
main(ac, av)
char **av;
{
execv(REAL_PATH, av);
}

gcc -o mywork wrapper.c
chown myname mywork.sh
chmod 4711 mywork

±×·±´ÙÀ½ php ¿¡¼­ exec(), system() µîÀ¸·Î È£ÃâÇÏ¸é µË´Ï´Ù.

½©½ºÅ©¸³Æ® ½ÇÇà½Ã¿¡ EUID°¡ »ç¶óÁö´Â ¹®Á¦ ¶§¹®¿¡ #!/bin/sh -p ÀÌ·¸°Ô -p ¿É¼ÇÀ» Ãß°¡ÇØ ÁÖ¾î¾ß ÇÏ´õ±º¿ä.

man bash ÇØº¸¸é ¾Æ·¡ ³»¿ëÀÌ ÀÖ½À´Ï´Ù.
Àοë:If the shell is started with the effective user (group) id not equal to the real user (group) id, and the -p option is not supplied, no startup files are read, shell functions are not inherited from the environment, the SHELLOPTS variable, if it appears in the environment, is ignored, and the effective user id is set to the real user id. If the -p option is supplied at invocation, the startup behavior is the same, but the effective user id is not reset.
È£¼® Áß¿ä ------------> #!/bin/sh -p ÀÌ·¸°Ô -p ¿É¼ÇÀ» Ãß°¡ÇØ ÁÖ¾î¾ß ÇÏ´õ±º¿ä. 07-07-26 14:43
211.¢½.74.31
°Ô½Ã¹° 121°Ç
¹øÈ£ ºÐ·ù Á¦¸ñ
À̸§
³¯Â¥ ÀÐÀ½
59 ÀÏ¹Ý   ¼Ö¶ó¸®½º ½Ã½ºÅÛ ºÎÇÏ ÃøÁ¤ È£¼® 07-08-13 5643
68 ÀÏ¹Ý   ¸®´ª½º ·çÆ® ºñ¹Ð¹øÈ£ ºÐ½Ç½Ã ó¸® È£¼® 08-02-11 5642
4 ÀÏ¹Ý   bash ½© ½ºÅ©¸³Æ® »ç¿ë¹ý È£¼® 05-06-27 5635
49 ÀÏ¹Ý   /dev/null 2>&1 ¿¡ ´ëÇØ¼­ ¾Ë·ÁÁÖ¼¼¿ä È£¼® 07-03-03 5621
46 ÀÏ¹Ý   ÇѲ¨¹ø¿¡ È®ÀåÀÚ ¹Ù²Ù±â rename È£¼® 07-01-26 5620
43 ÀÏ¹Ý   ¸®´ª½º¿¡¼­ Çϵåµð½ºÅ© Ãß°¡ ¼³Ä¡Çϱâ HDD (1) È£¼® 06-12-14 5616
26 ÀÏ¹Ý   APM ¿¬µ¿ httpd-2.0.55 mysql-5.0.18 php-4.4.2 (2) È£¼® 06-03-24 5605
23 ÀÏ¹Ý   °í¼º´É ftp Ŭ¶óÀÌ¾ðÆ® sftp, http µî Áö¿ø È£¼® 06-03-17 5601
32 ÀÏ¹Ý   [apm¼³Ä¡]Apache, PHP, MySQL, LibXML Source Compile È£¼® 06-04-22 5594
17 ÀÏ¹Ý   Spamassassin ¼³Ä¡ ( spam ¸ÞÀÏ Â÷´Ü ) È£¼® 06-01-04 5584
16 ÀÏ¹Ý   umaskÀÇ »ç¿ë È£¼® 05-12-01 5519
89 ÀÏ¹Ý   ¼Ö¶ó¸®½º ¸í·É¾î ( ¼Ö¶ó¸®½º ¹öÁ¯ È®ÀÎ ) (1) È£¼® 09-03-23 5511
6 ÀÏ¹Ý   TCP-Wrapper »ç¿ëÇϱâ È£¼® 05-06-28 5510
51 ÀÏ¹Ý   vi ¿¡¼­ Çѱ۱úÁú°æ¿ì 󸮹æ¹ý È£¼® 07-05-10 5508
28 ÀÏ¹Ý   [¹æ¾î] prevent ÇÁ·Î±×·¥ ssh 5¹ø ÀÌ»ó½ÇÆÐ½Ã ÀÚµ¿µî·Ï (1) È£¼® 06-03-29 5507
óÀ½ÀÌÀü  [1] [2] 3 [4] [5] [6] [7] [8] [9]  ´ÙÀ½¸Ç³¡
 
Copyright © zenos.pe.kr. All rights reserved.