rizin reverse engineering c

agnusdei·2025년 6월 6일

CTF

목록 보기
12/185

apt update
apt install rizin

root㉿docker-desktop)-[/]
└─# ls
CVE-2024-9264                    bin   data  etc   lib    media  opt   root  sbin  sys       tmp  var
Compiled-1688545393558.Compiled  boot  dev   home  lib64  mnt    proc  run   srv   test.txt  usr  vpn

┌──(root㉿docker-desktop)-[/]
└─# rizin Compiled-1688545393558.Compiled 
 -- Use +,-,*,/ to change the size of the block
[0x00001080]> aaa
[x] Analyze all flags starting with sym. and entry0 (aa)
[x] Analyze function calls
[x] Analyze len bytes of instructions for references
[x] Check for classes
[x] Analyze local variables and arguments
[x] Type matching analysis for all functions
[x] Applied 0 FLIRT signatures via sigdb
[x] Propagate noreturn information
[x] Integrate dwarf function information.
[x] Resolve pointers to data sections
[x] Use -AA or aaaa to perform additional experimental analysis.
[0x00001080]> afl
0x00001000    3 23           sym._init
0x00001030    1 6            sym.imp.printf
0x00001040    1 6            sym.imp.strcmp
0x00001050    1 6            sym.imp.__isoc99_scanf
0x00001060    1 6            sym.imp.fwrite
0x00001070    1 6            sym.imp.__cxa_finalize
0x00001080    1 33           entry0
0x000010b0    4 41   -> 34   sym.deregister_tm_clones
0x000010e0    4 57   -> 51   sym.register_tm_clones
0x00001120    5 57   -> 54   sym.__do_global_dtors_aux
0x00001160    1 9            entry.init0
0x00001169    7 253          main
0x00001268    1 9            sym._fini
[0x00001080]> pdf @ main
            ; DATA XREF from entry0 @ 0x1094
┌ int main(int argc, char **argv, char **envp);
│           ; var int64_t var_48h @ stack - 0x48
│           ; var int64_t var_40h @ stack - 0x40
│           ; var int64_t var_38h @ stack - 0x38
│           ; var const char *s1 @ stack - 0x28
│           0x00001169      push  rbp
│           0x0000116a      mov   rbp, rsp
│           0x0000116d      sub   rsp, 0x40
│           0x00001171      movabs rax, 0x4973676e69727453             ; 'StringsI'
│           0x0000117b      movabs rdx, 0x626f6f4e726f4673             ; 'sForNoob'
│           0x00001185      mov   qword [var_48h], rax
│           0x00001189      mov   qword [var_40h], rdx
│           0x0000118d      mov   word [var_38h], 0x73                 ; 's'
│           0x00001193      mov   rax, qword [obj.stdout]              ; obj.__TMC_END
│                                                                      ; [0x4030:8]=0
│           0x0000119a      mov   rcx, rax                             ; FILE *stream
│           0x0000119d      mov   edx, 0xa                             ; size_t nitems
│           0x000011a2      mov   esi, 1                               ; size_t size
│           0x000011a7      lea   rax, str.Password:                   ; 0x2004 ; "Password: "
│           0x000011ae      mov   rdi, rax                             ; const void *ptr
│           0x000011b1      call  sym.imp.fwrite                       ; sym.imp.fwrite ; size_t fwrite(const void *ptr, size_t size, size_t nitems, FILE *stream)
│           0x000011b6      lea   rax, [s1]
│           0x000011ba      mov   rsi, rax
│           0x000011bd      lea   rax, str.DoYouEven_sCTF              ; 0x200f ; "DoYouEven%sCTF"
│           0x000011c4      mov   rdi, rax                             ; const char *format
│           0x000011c7      mov   eax, 0
│           0x000011cc      call  sym.imp.__isoc99_scanf               ; sym.imp.__isoc99_scanf ; int scanf(const char *format)
│           0x000011d1      lea   rax, [s1]
│           0x000011d5      lea   rdx, str.dso_handle                  ; 0x201e ; "__dso_handle"
│           0x000011dc      mov   rsi, rdx                             ; const char *s2
│           0x000011df      mov   rdi, rax                             ; const char *s1
│           0x000011e2      call  sym.imp.strcmp                       ; sym.imp.strcmp ; int strcmp(const char *s1, const char *s2)
│           0x000011e7      test  eax, eax
│       ┌─< 0x000011e9      js    0x1205
│       │   0x000011eb      lea   rax, [s1]
│       │   0x000011ef      lea   rdx, str.dso_handle                  ; 0x201e ; "__dso_handle"
│       │   0x000011f6      mov   rsi, rdx                             ; const char *s2
│       │   0x000011f9      mov   rdi, rax                             ; const char *s1
│       │   0x000011fc      call  sym.imp.strcmp                       ; sym.imp.strcmp ; int strcmp(const char *s1, const char *s2)
│       │   0x00001201      test  eax, eax
│      ┌──< 0x00001203      jle   0x124b
│      │└─> 0x00001205      lea   rax, [s1]
│      │    0x00001209      lea   rdx, str.init                        ; 0x202b ; "_init"
│      │    0x00001210      mov   rsi, rdx                             ; const char *s2
│      │    0x00001213      mov   rdi, rax                             ; const char *s1
│      │    0x00001216      call  sym.imp.strcmp                       ; sym.imp.strcmp ; int strcmp(const char *s1, const char *s2)
│      │    0x0000121b      test  eax, eax
│      │┌─< 0x0000121d      jne   0x1235
│      ││   0x0000121f      lea   rax, str.Correct                     ; 0x2031 ; "Correct!"
│      ││   0x00001226      mov   rdi, rax                             ; const char *format
│      ││   0x00001229      mov   eax, 0
│      ││   0x0000122e      call  sym.imp.printf                       ; sym.imp.printf ; int printf(const char *format)
│     ┌───< 0x00001233      jmp   0x125f
│     ││└─> 0x00001235      lea   rax, str.Try_again                   ; 0x203a ; "Try again!"
│     ││    0x0000123c      mov   rdi, rax                             ; const char *format
│     ││    0x0000123f      mov   eax, 0
│     ││    0x00001244      call  sym.imp.printf                       ; sym.imp.printf ; int printf(const char *format)
│     ││┌─< 0x00001249      jmp   0x125f
│     │└──> 0x0000124b      lea   rax, str.Try_again                   ; 0x203a ; "Try again!"
│     │ │   0x00001252      mov   rdi, rax                             ; const char *format
│     │ │   0x00001255      mov   eax, 0
│     │ │   0x0000125a      call  sym.imp.printf                       ; sym.imp.printf ; int printf(const char *format)
│     │ │   ; CODE XREFS from main @ 0x1233, 0x1249
│     └─└─> 0x0000125f      mov   eax, 0
│           0x00001264      leave
└           0x00001265      ret
[0x00001080]> 

0x4973676e69727453 이 값은 문자열을 16진수로 표현한 것입니다.
단, 리틀 엔디안(Little Endian) 방식으로 저장되어 있으므로 역순으로 읽어야 합니다.


🔍 분석

원래 값:

0x4973676e69727453

16진수를 바이트 단위로 나누면:

49 73 67 6e 69 72 74 53

이를 아스키(ASCII) 문자로 바꾸면:

0x49 = I  
0x73 = s  
0x67 = g  
0x6e = n  
0x69 = i  
0x72 = r  
0x74 = t  
0x53 = S

→ 즉, 바이트 순서대로 보면 "IsgnirtS"
하지만 이건 리틀엔디안으로 저장된 거라 역순으로 읽어야 합니다:

"Stringsi"

정확히는 "Stringsi" (마지막 i는 "sForNoob"와 결합되며 "StringsForNoobs"를 만들려는 의도일 가능성 높음)


🧠 결론

항목설명
값0x4973676e69727453
저장 방식리틀 엔디안 (낮은 바이트 먼저)
문자열 해석"Stringsi"

0개의 댓글