์คํ ํ๋ ์ ๋ถ์ Return address (0x8) SFP (0x8) buf [rbp-0x40] (0x40) ๊ณต๊ฒฉ ๊ณํ ์ต์ข ๋ชฉํ: system("/bin/sh") ์ํํ ๊ฒ. * system() ์ฃผ์ ๊ตฌํ๊ธฐ = lib_base + system_offset ** lib_base ๊ตฌํ๊ธฐ = read() ์ฃผ์ - read_offset *** read() ์ฃผ์ ๊ตฌํ๊ธฐ ROP๋ฅผ ํตํด, write(1, read@got, ...) * "/bin/sh" ์ฃผ์ ๊ตฌํ๊ธฐ = lib_base + binsh_offset ** system_offset, read_offset, binsh_offset ๊ตฌํ๊ธฐ libc๋ฅผ ์ด์ฉ * Return address๋ฅผ system("/bin/sh")๋ก Overwrite ROP๋ฅผ ์ด์ฉ ex..