2021 Hecheng cup pwn part wp

littleof ret2libc is given for nothing. The first output divulges canary, and the second output divulges the base address of libc. By the way, control the return address, and then return to input, and then get shell (stall) #!/usr/bin/env python #coding=utf-8 from pwn import* sh = remote("182.116.62.85", 27056) #sh = process('./littleof') el ...

Posted by JD^ on Sat, 09 Oct 2021 10:51:06 -0700

Tips for writing exp

Tips for writing exp 1. Code alignment When filling in the address in exp, pay attention to the filling of code length 2. Fill to specified length 3. Link the remote server or link the local file # long-range r = remote('objective IP Or target URL',Destination port number) # local r = process('./file name') 4. Format conversion The ...

Posted by Johnain on Mon, 20 Sep 2021 16:52:57 -0700