
apt update
apt install rizin
root㉿docker-desktop)-[/]
└─# ls
CVE-2024-9264 bin data etc lib media opt root sbin sys tmp var
Compiled-1688545393558.Compiled boot dev home lib64 mnt proc run srv test.txt usr vpn
┌──(root㉿docker-desktop)-[/]
└─# rizin Compiled-1688545393558.Compiled
-- Use +,-,*,/ to change the size of the block
[0x00001080]> aaa
[x] Analyze all flags starting with sym. and entry0 (aa)
[x] Analyze function calls
[x] Analyze len bytes of instructions for references
[x] Check for classes
[x] Analyze local variables and arguments
[x] Type matching analysis for all functions
[x] Applied 0 FLIRT signatures via sigdb
[x] Propagate noreturn information
[x] Integrate dwarf function information.
[x] Resolve pointers to data sections
[x] Use -AA or aaaa to perform additional experimental analysis.
[0x00001080]> afl
0x00001000 3 23 sym._init
0x00001030 1 6 sym.imp.printf
0x00001040 1 6 sym.imp.strcmp
0x00001050 1 6 sym.imp.__isoc99_scanf
0x00001060 1 6 sym.imp.fwrite
0x00001070 1 6 sym.imp.__cxa_finalize
0x00001080 1 33 entry0
0x000010b0 4 41 -> 34 sym.deregister_tm_clones
0x000010e0 4 57 -> 51 sym.register_tm_clones
0x00001120 5 57 -> 54 sym.__do_global_dtors_aux
0x00001160 1 9 entry.init0
0x00001169 7 253 main
0x00001268 1 9 sym._fini
[0x00001080]> pdf @ main
; DATA XREF from entry0 @ 0x1094
┌ int main(int argc, char **argv, char **envp);
│ ; var int64_t var_48h @ stack - 0x48
│ ; var int64_t var_40h @ stack - 0x40
│ ; var int64_t var_38h @ stack - 0x38
│ ; var const char *s1 @ stack - 0x28
│ 0x00001169 push rbp
│ 0x0000116a mov rbp, rsp
│ 0x0000116d sub rsp, 0x40
│ 0x00001171 movabs rax, 0x4973676e69727453 ; 'StringsI'
│ 0x0000117b movabs rdx, 0x626f6f4e726f4673 ; 'sForNoob'
│ 0x00001185 mov qword [var_48h], rax
│ 0x00001189 mov qword [var_40h], rdx
│ 0x0000118d mov word [var_38h], 0x73 ; 's'
│ 0x00001193 mov rax, qword [obj.stdout] ; obj.__TMC_END
│ ; [0x4030:8]=0
│ 0x0000119a mov rcx, rax ; FILE *stream
│ 0x0000119d mov edx, 0xa ; size_t nitems
│ 0x000011a2 mov esi, 1 ; size_t size
│ 0x000011a7 lea rax, str.Password: ; 0x2004 ; "Password: "
│ 0x000011ae mov rdi, rax ; const void *ptr
│ 0x000011b1 call sym.imp.fwrite ; sym.imp.fwrite ; size_t fwrite(const void *ptr, size_t size, size_t nitems, FILE *stream)
│ 0x000011b6 lea rax, [s1]
│ 0x000011ba mov rsi, rax
│ 0x000011bd lea rax, str.DoYouEven_sCTF ; 0x200f ; "DoYouEven%sCTF"
│ 0x000011c4 mov rdi, rax ; const char *format
│ 0x000011c7 mov eax, 0
│ 0x000011cc call sym.imp.__isoc99_scanf ; sym.imp.__isoc99_scanf ; int scanf(const char *format)
│ 0x000011d1 lea rax, [s1]
│ 0x000011d5 lea rdx, str.dso_handle ; 0x201e ; "__dso_handle"
│ 0x000011dc mov rsi, rdx ; const char *s2
│ 0x000011df mov rdi, rax ; const char *s1
│ 0x000011e2 call sym.imp.strcmp ; sym.imp.strcmp ; int strcmp(const char *s1, const char *s2)
│ 0x000011e7 test eax, eax
│ ┌─< 0x000011e9 js 0x1205
│ │ 0x000011eb lea rax, [s1]
│ │ 0x000011ef lea rdx, str.dso_handle ; 0x201e ; "__dso_handle"
│ │ 0x000011f6 mov rsi, rdx ; const char *s2
│ │ 0x000011f9 mov rdi, rax ; const char *s1
│ │ 0x000011fc call sym.imp.strcmp ; sym.imp.strcmp ; int strcmp(const char *s1, const char *s2)
│ │ 0x00001201 test eax, eax
│ ┌──< 0x00001203 jle 0x124b
│ │└─> 0x00001205 lea rax, [s1]
│ │ 0x00001209 lea rdx, str.init ; 0x202b ; "_init"
│ │ 0x00001210 mov rsi, rdx ; const char *s2
│ │ 0x00001213 mov rdi, rax ; const char *s1
│ │ 0x00001216 call sym.imp.strcmp ; sym.imp.strcmp ; int strcmp(const char *s1, const char *s2)
│ │ 0x0000121b test eax, eax
│ │┌─< 0x0000121d jne 0x1235
│ ││ 0x0000121f lea rax, str.Correct ; 0x2031 ; "Correct!"
│ ││ 0x00001226 mov rdi, rax ; const char *format
│ ││ 0x00001229 mov eax, 0
│ ││ 0x0000122e call sym.imp.printf ; sym.imp.printf ; int printf(const char *format)
│ ┌───< 0x00001233 jmp 0x125f
│ ││└─> 0x00001235 lea rax, str.Try_again ; 0x203a ; "Try again!"
│ ││ 0x0000123c mov rdi, rax ; const char *format
│ ││ 0x0000123f mov eax, 0
│ ││ 0x00001244 call sym.imp.printf ; sym.imp.printf ; int printf(const char *format)
│ ││┌─< 0x00001249 jmp 0x125f
│ │└──> 0x0000124b lea rax, str.Try_again ; 0x203a ; "Try again!"
│ │ │ 0x00001252 mov rdi, rax ; const char *format
│ │ │ 0x00001255 mov eax, 0
│ │ │ 0x0000125a call sym.imp.printf ; sym.imp.printf ; int printf(const char *format)
│ │ │ ; CODE XREFS from main @ 0x1233, 0x1249
│ └─└─> 0x0000125f mov eax, 0
│ 0x00001264 leave
└ 0x00001265 ret
[0x00001080]>
0x4973676e69727453 이 값은 문자열을 16진수로 표현한 것입니다.
단, 리틀 엔디안(Little Endian) 방식으로 저장되어 있으므로 역순으로 읽어야 합니다.
원래 값:
0x4973676e69727453
16진수를 바이트 단위로 나누면:
49 73 67 6e 69 72 74 53
이를 아스키(ASCII) 문자로 바꾸면:
0x49 = I
0x73 = s
0x67 = g
0x6e = n
0x69 = i
0x72 = r
0x74 = t
0x53 = S
→ 즉, 바이트 순서대로 보면 "IsgnirtS"
하지만 이건 리틀엔디안으로 저장된 거라 역순으로 읽어야 합니다:
"Stringsi"
정확히는
"Stringsi"(마지막i는"sForNoob"와 결합되며"StringsForNoobs"를 만들려는 의도일 가능성 높음)
| 항목 | 설명 |
|---|---|
| 값 | 0x4973676e69727453 |
| 저장 방식 | 리틀 엔디안 (낮은 바이트 먼저) |
| 문자열 해석 | "Stringsi" |