KAIST-IS521 / 2018s-gitctf-team5

1 stars 0 forks source link

exploit-bug2 #49

Closed sunnyeo closed 6 years ago

sunnyeo commented 6 years ago

-----BEGIN PGP MESSAGE----- Version: GnuPG v1

hQEMAy8nZUIPGP0nAQgAlDRPdlEfeTmuTGKnNq31G/gIqMVCncxyDma3REc9r+DS SNFXMvv1nkbSKWjwSiE74hU0uz/XDa5DwVGS9vgqdwhsLiM/BZS/knI4XzBM7gLC TKZx4Bg4qr9WD0YrMAyUDcsstF3WLsFhbq7lbLIdoKXYfPB/2K+oVFzbpsK9QNiI +Tx3pIBFd9dhnz4Dg2wdedA/+FrHJvyLuVcZfMSUapjdSykNUSuu13L2D64et/X2 E60BzfJEb10i/uJK2h3qG3qMZcK9kl9GovGqdjUsKC0mgrkmggkdJFfb3tx9ymQx sJOy1z2h453FaHw+7o9MFldcRLUsZjf7iTgArkI4y4UBjAPcMgCV6N35oQEMALom 5KWFaXc41ALfNCp/u4+ZOnm4A15cLj/sZ9q/b9erZr91qlgUz6oy0CAkM5l6oC9g fXBwliHwQ6wBbQ/TWAlCFrWxMGNqWCoOIy00EuCZf109FbcqWUeI06B2FOthMilX HFxoszQbBcYx6ZlcSC7hL5Mf1JmV4EHKgtdTeGDkw2FQJlH1xonlElhQl2x0aMbg EDX9lqhqGSnlT7CwKLm/bvu4mPn51m/pbcKjVTvRmy19UMXZ4X9QlIWzwSkpjoPm pkVexLCRuE1zLXW6aYLH6eZbb5/0Z/MI7QMnWwIzrsdFB585Ks+gelnOP5ac7I0h AqVRCOqLnj3TuTJB+2ezOE7LEQZ3P2nxWOzdeV218M69hrX1wTMLL3mmRLyU8Q1l y5i0dxVN82n+lrUDBkRYWK51KWwkhwZLihkFbdWToqJWWIQbz7z+a7WZrit8IToQ oLsAIEDxnyJ5VA9J/Uj20b/oYrk6Od2WS9RIiZ1XSfwvBFFL0MJQ7AHYdX+9LNLr AQdFzn5yRdOv9jLFq3wzfnqZUbUqZzmiUY0cjW69CBsKuFExUsJJtGABTpXKovgC db7XtBN54WzlfUxBa604SFr378hzKwVs6NHworUKepBX9PEUNGrOWRkLcmTxLsA1 y20Z+nVZlZisis8yfsSPYibxZ5ETjRqDb1DoLphnhTeeI7bgAzq/kfErYFvJ3jte 1xHfa8R4REEwAd3Nvt96mK2XaiWxptzEaIlbVJ0tidgVmmZXgVbg0gJymGfevf5x RX6OPERaA+iNx27eDsyGigY4eMyUEsRlvIlEGFqbhQ2ZAETmmQ+RFvwcp/begO5g 44MqO2Y+iT/NWG9sF4GZgvRWzVqUdMz6EBbztXxK/QVvrKpPKy0ydYzADNdZpZJP 9lSuUxJnBrw0H9Qw+dGUoGmTAhGFUNusMHFWEfb/8P7T8ZTBTO1x+6HRvrn0Cn3i l1T+nGD6WudO5mtK7aqlagOQRJoUJhy4WNAWdYhNwOf1V2gGbrzdxzY1o49uwcgG C9Qdr3pu+lScxVNVRn5DCx7APFV6nuVqn16RAZUYX2kmlxCzvQ0FjcJIZhizY0Qp D3+XrRCv6RUwKw9SJW/ga/cx9WU3Oi4HeajHpZ44oD3mB2NSszN8BnuPN8BWqkDA 2gvoVLkdUU6U0DluGEvHjJmMdVwqwu6V6sQ2w3lZKOrH9LoN7kChUoAFyvP0m64d l3EUqJYcXuRP0VNZkYOiWLGdFetPmdjQUJh3AFIYvAOD48d4avmMmCzc46iFsMCD akwtkB5jVWVHouoW+imhcmPgaz+HlcA1lGlpib+LaeiTd+voIF79JcoPwaAl3tT4 rKJeey0JduoLT15Vwsu8c/7CO4DyMsfzM4S0bi9x6FzDC5yHW+IzijfSqx2IgTcO I75Gxyx58AR7EIEBTUIeDcam5IvLwr+Yjfw1cbm5UqUCbnPUoOXSHKPL8Jsv7TUn vxdmPLaQ1+MxYktIoHIU8OCdXsLTPT3R44uWsjOwPA1xBydnfqUT/BPbu2HOyxL0 bUVWSgXtYemvsG3KYgfBsc3xXB2ythlJb+yzcfUpur8qlT6gUyGUJ+ncTe85hm8u h8/tax5VXgtECp0cV23Js9TadpyLjAgkoZPVAUCz99yObOk3TwLc/kE4AO7sYZcx kZB/qXUtiGyhz8XwxiyDB/uLHNEmKIumpEWDHafvkIdCjVf8nMvcPRgi/3gRP4pD 2AE0DKRLixkmsLlnAF9/C0KBsb5j+wGEAan6qQMdABhQwK0keJeo+vkIWW2GgoNE BFVnOCg/ghP4TJvrBsaHVgdIYUwcwE9gAk8zo18zttv7J0YW3uEhkMDPdh4Jp5Zp GBWQdoj68vrj9aHHANP8vlzGt1BnsIVx30h6byYE8KQatBRQDKh/R0PrgSWwtqDi NnaUEzfsiteKCZbDNAJBwiVoTbU9qT+A7DSxHA+jOTNRdivvtEm0ORa1GuI5H7Pe Z1o8jtj+fSXrNAnJwhYyS2qnQ1hegOlmfPYOLy3/jnhOOzl1EmOPXihPpoV/JWJ2 CCmZKeVVBcE/UUpOAZihvO1fCm+zh2pkbr9S03lGXQ9zR+HoM85hSZbgvzN9bZLc v8YAmq0EhvA0TvzwQKRYpTNy9x0I2nzSryHaEC5Mt9hmptr9k6qQCwBPhdu7ixZ5 70oTwwIw0vgUnZCWqeB8769MpbICZ8Vv8ZxVuXMF6hhBMdTmwAuT38xQ8Wvb9gWC azi/8eVl+Uk+VgCZ1D7HH4LMRxkBIzRpLRpkOCeGWmVypv15t1EvHCZu7GB4eXa7 /fQVeuJh7qmLlk4O7KGFODIvzaqKLtKUDMODjIIhzacRVTM34wx1QWZYhW/A9Ery ePNnsjSD1vEvqJlTU1r8j6PW41hmPgxqfYwq+Ljt1K9GsUzEDypj1Ya3xurD8CCy a16SZaWFXEy/niTn6Y3EWEB2bh0CZd0K5kCuzBZXN5ZxLYkLEWd8ik4ZIk1i6PDN E81c4EpK2Sej7F/bMbt0kUUcmc4QL+FrgBtMv5vMf2U1vvMzDan4qt1zOZC+OAtv BTfydlcfMm3tGvzBMi6cLkJuGGcStXTv7X/nwCkeTgR9l+eFVpdgxMdQRLXv3L4z JN3YSKxvKNhaLzsh8FXFWdh6+mIsN+8MYSd5GFuprSqAABrX7FaEadmYH514zBAH aYIGjKp0vMHYDvyejZcf45odAJle23TZS77nixERH3T/Eg45r4rHkVRtFusT130K 2bFZ9ItEc5hPm0j9Lq/9RwMEBP6QyurTfhoMKDQoDIMWRWPGy7YN4CteFFxvLkIn cR2NXUhTnLLuWXCvO5s0eiur9nfCl7ZaiO0c6P20XoV3RE7XQfqbwXwY2XLHb6bn GCtijoNKGxp/y2dztH0oRkw+IuujM14ZbloBILZc6gPz5K6HX9WGJ7NSNm7mt2dl oKGclNLFT/sQyhVW9hbeJ9OJ/tiJ8sEeIHdTzcSEXQMcQFCfzVadVhZs1UpLofSV ETkAcY0hJyrSJgPp1wRNyh1BniUTreqYvtQehL12WbhWjaZOGZufjnxjILZV34Kl dDytpOD//i7GoMjXC5KRI6G6qHXo7PuOuyYZ3ewNC3Ejn8kIgMa245VTDuI7t6x/ onca3Ed1BkfQZbdsVLq9b9J8kNPMASwWbWIYaX883ob8W1rof+SdAqPXpXDdufPO 9s/FjGFG/lMDu692wa7lugETfcoBopvf71j1P4bQ5ZTqvfYspy0NL83s+IKJXQyW M5DHvcWr4vupiszf6difOvbLH4KjRvHqcGrXQNBxV2TN4z2SUQrWOjSWxkQwVp7e c25LJ7yhX2g+bFm1WbLKPEg5+w1dhYQTxsOuPb88VZaNlFLspuWXLtWWDmtKcUBg hUWtlbY4D58xFCWR2RYHX6RQBO7rSK+sE1dobRHmF3jAGx4n0TJRcDPR4wKcvuzU ZqLEOsdXecupi16hV9paKnDhHXujW9q/nhCzSy6nLyQVOmIAxcq4DgwOhCmyeRMU TdW8ip4+bN0XnXDGZAL6FBmBOp8zD0aV7+eMAYo/5Ts1FeCQsMgLPGDa2mr49e3Z XOE/wqClpLnmg1Ts8zsZ1ue8IWrgOgAY4CGFOKYMwwB8JjDuwYd9378IxhYCh81s C/5YCmVVCpBWejkV7945/BXMGmd4LsxNHqqFlfdTscRvpS8Sq2dFkZW35VzPYBQ4 OMwcWVnyP6ejN0bdhEQIsU/xArGSn/UMEg9nFDN6I7+NhmWRIdr7vRFswEKcngQm rp/WtQEcJLm5CpU4hN4aQ2y1vLLhjVvcCay6TGyt5WQdUjYAZ9EgdDipA5jylTMo HDGdHToe/KSr7NtV5a2FN2qG9CIToQpNDde8973YiQ+3BcpLNQvroflm4XHB2wYt JhZLqS693Vu4DgMmHHnP6TELk9An061vDrAGvTa4q9Nj4u9UEfHfx2RnKERQ0YfY +TqF5VWjj4XP8iYhQOiRIxNPJJa6mCQ97kAZXFCfWiszHgVAifEaLYYzxAR+2c6v 2xGTvWb7Jp6/5HJQTEVEQCtrUBphGoX9Z8LdXaEzemEEcCmjIqgUNVAoHiwvC20R 7VuAatmuZkKiHSf2KZfl7A+rJ41ByckjkezgjoLIPpgXI6ci8Cu8Is99z3AiPjHX v8k7AHQvzG+xspEwHAmKfHJptijFj/QKQwLbDE8iCHuMqRJLCwna2ciTcWBxJJA7 Fm8TqjFd6wIwaROa5wBZ5hpkkswzm1cqrR7Mu3GUV/1CBHTPzDuUdlRzRy8hrszA as4/xNBRYtfErlAOIegaF0lVCfot5bRK8aX4MktqOusC+V+kZU/K37pCagI8wsFE 56u96QtQ+GseIlLFfIYjTPFyH2yQ92YIaR1K26vzO3sWue16TmtpbwJjzw9yxMEV m2WA8AOCJtHA3cE94x+IBD1mrKqqgeCM9PR840uHAUuSeFQpU7JI69HAxagR6dPC JW0KV4YoO3NRcjZ4FlmMF+7BED94dTjQ2Iss+9GBs3JvGjeDTj1tnnDXYBd1Vp2K 0c6p6oArmyIhH4PmKSR4JjjtBR2ucJeFYBRyjOdhVyKCSZryAEX4VM6F3Zbw5Isz bOkW5lV+skTu7pHImWq20D7v3LofWm9FLi+QEAjk/XSNowDfhKaCUjETwHJV4fve BqAqUhP0aMptp+LpcdBet1Xks8ROEW6070g5P+wUwt536Z//VaHEu9w43YHcwr27 0p/5/5DHuk3GNeWRX1CryCt86BZpEDINm/d8sOg6uajQ8/EvBl9VirNKuvbfyuT/ f0T08QIWXTkvQykaXMCZE8oPPmO49aP5MNpbiYBPBK8/vYgicbuUWH0KtcDDYwVB +bvZfBP0P7UZtdwbpGNsDJcPSJIqM90c8uzzfDUb3pvy6ZqH08m8r3Xn0EWlPPfG zAPiVsJGjuEXPJ/0fRUh78SCPBbljX1dIq8jrtPl+xT4TgNVtbIznV7Z0RcyerdM PVN7HhuFN8lIWYxerSVXoAzNfPdIW/14+woEKibabe24l/oQL28NkMoxqkRy8dro 0UjAYKue0aRsgr4PNkBs71S/9IaWp/e7MmmW1qdiDwZSQgKXbXihOjujvsyZe/pZ h/3DgCcxtspWgitu2PMnCMZ3PU7e4dVuyjV3sh8GLId0mzZuWUwr3SC8u/0rM4c3 MKPjtX5CReg3CGLDBcmetKDy8EjimoRmjCzoKLpgEGmRSsvjUIRtJlvI4GX4MuFq c6hrEp6s5NdwsF7rmnMvA2hvb4lKS7uWQSoMe9dv0CxFOCrh9hQ6VIJv3BhOIJ4H OKXXuH26+3WEHah/W2VeUix4rcUZsBTJjxz3vJs= =rnwS -----END PGP MESSAGE-----

softsec-is521 commented 6 years ago
About exploit-bug2 (exploit-service branch)
[*] Starting service from 2018s-gitctf-team5 (branch '8a0b39b831e3bb1efdc845658089c0ae66a36fd7')
Sending build context to Docker daemon  2.193MB
Step 1/33 : FROM debian:latest
---> 8626492fecd3
Step 2/33 : MAINTAINER k1rh4 <k1rh4.lee@gmail.com>
---> Using cache
---> 8e9e3881ec66
Step 3/33 : RUN         sed -i 's/deb.debian.org/ftp.daumkakao.com/g' /etc/apt/sources.list
---> Using cache
---> d58cb6fc7f0d
Step 4/33 : RUN apt-get update
---> Using cache
---> f74c65dc9bfe
Step 5/33 : RUN apt-get install -y xinetd
---> Using cache
---> 845d6f85baa1
Step 6/33 : RUN apt-get install -y libsqlite3-dev
---> Using cache
---> ff66c0e5a29c
Step 7/33 : RUN apt-get install netcat -y
---> Using cache
---> df491e9bff6a
Step 8/33 : RUN apt-get install net-tools -y
---> Using cache
---> 93debded14f4
Step 9/33 : RUN apt-get install -y procps
---> Using cache
---> c472a4cdaf3f
Step 10/33 : RUN useradd -d /home/load load -s /bin/bash
---> Using cache
---> 88d6cfc64fa7
Step 11/33 : RUN mkdir /home/load
---> Using cache
---> 82e3bcea59ce
Step 12/33 : RUN chown -R root:load /home/load
---> Using cache
---> 5aa04924d1ab
Step 13/33 : RUN chmod 750 /home/load
---> Using cache
---> f51da5c3a761
Step 14/33 : ADD ./BUILD/prob /home/load/
---> Using cache
---> 5fa7dbc08b05
Step 15/33 : ADD ./BUILD/modify_usr /home/load/modify_usr
---> Using cache
---> 80d1f6379516
Step 16/33 : ADD ./BUILD/run.sh /home/load/run.sh
---> Using cache
---> 906323f975f1
Step 17/33 : ADD ./BUILD/usr.db /home/load/usr.db
---> Using cache
---> ba9251f94caa
Step 18/33 : RUN chown root:root /home/load/*
---> Using cache
---> bb326fbfe03f
Step 19/33 : RUN chmod 755 /home/load/run.sh
---> Using cache
---> 693348cb1317
Step 20/33 : RUN chmod 755 /home/load/modify_usr
---> Using cache
---> e9b9fc8366c5
Step 21/33 : RUN chmod 755 /home/load/prob
---> Using cache
---> 2b467833030a
Step 22/33 : RUN chmod 766 /home/load/usr.db
---> Using cache
---> e09ce7454b7a
Step 23/33 : RUN mkdir -p /var/ctf/
---> Using cache
---> 836e043d7be7
Step 24/33 : COPY ./flag    /var/ctf/flag
---> fda9515574b9
Step 25/33 : RUN chown root:load /var/ctf/flag
---> Running in 170b1ea1a6c6
Removing intermediate container 170b1ea1a6c6
---> 09d90710107e
Step 26/33 : RUN chmod 440 /var/ctf/flag
---> Running in 2fb2d9cd83a1
Removing intermediate container 2fb2d9cd83a1
---> d0886daba18d
Step 27/33 : ADD ./SRC/load.xinetd /etc/xinetd.d/load
---> 9f8753f9df1b
Step 28/33 : WORKDIR /home/load
Removing intermediate container 06a51dca1f24
---> d54d4468ad28
Step 29/33 : ADD ./SRC/start.sh /start.sh
---> 39bdc80d4f83
Step 30/33 : RUN chmod +x /start.sh
---> Running in 36f487f1d46f
Removing intermediate container 36f487f1d46f
---> f050f4b907c8
Step 31/33 : RUN su load
---> Running in 19e2942185b9
Removing intermediate container 19e2942185b9
---> 830eb6f12575
Step 32/33 : RUN /start.sh &
---> Running in 0ee4be18005b
Removing intermediate container 0ee4be18005b
---> 12612090faa7
Step 33/33 : ENTRYPOINT /start.sh
---> Running in e6d4a01326f8
Removing intermediate container e6d4a01326f8
---> 7e9686e35892
Successfully built 7e9686e35892
Successfully tagged 2018s-gitctf-team5-8a0b39b831e3bb1efdc845658089c0ae66a36fd7:latest
de7fd07bc4c14517d7e99b3304a2605a685a0ab506db1064d554b680a0e6f815
[*] Started service successfully
[*] Running exploit
Can not show your exploit log because it cannot decode the content of exploit
[*] Failed to run exploit

==========================
[*] Exploit returned : None
[*] Solution flag : kdfTUTcaZY
[*] Exploit returned a wrong flag string

[*] The exploit did not work.

seongil-wi commented 6 years ago
timer: 0
        timer: 1
                timer: 2
                        timer: 3
                                timer: 4
                                        timer: 5
                                                timer: 6
                                                        timer: 7
                                                                timer: 8
                                                                        timer: 9

                                                                                ⳩mer: 10
    timer: 11

             ṣ8
               timer: 12
                        timer: 13
                                 timer: 14
                                          timer: 15
                                                   timer: 16
                                                                k
                                                                 timer: 17
                                                                          timer: 18
                                                                                   timer: 19
        timer: 20
                 timer: 21
                            kv
                                  timer: 22
                                           timer: 23
                                                    timer: 24
                                                             timer: 25
                                                                      timer: 26
                                                                                kv`
                                                                                   timer: 27
        timer: 28
                    kv`(
                            canary: 0x00e338096b766028
                                                      time: 0:00:29.054054
                                                                          timer: 29
                                                                                   timer: 30
        timer: 31
                 timer: 32
                          timer: 33
                                   timer: 34
                                            timer: 35
                                                     timer: 36
                                                              timer: 37
                                                                       timer: 38
                                                                                timer: 39
     timer: 40
              timer: 41
                       timer: 42
                                timer: 43
                                         timer: 44
                                                  timer: 45
                                                           timer: 46
                                                                    timer: 47
                                                                             timer: 48
  timer: 49
           timer: 50
                    timer: 51
                             timer: 52
                                      timer: 53
                                               timer: 54
                                                        timer: 55
                                                                 timer: 56
                                                                          timer: 57
                                                                                   timer: 58
        [*] Failed to run exploit