Pwnctf ret2src Writeup
ret2src
先看一下保護機制:
這題什麼保護機制都沒有w,所以作法應該蠻多種的,這裡 return 到 gets 的 plt,把 shellcode 寫到某個 bss 段,然後再跳上開 shell。
exploit.py:
1 | from pwn import * |
shellcode :
https://www.exploit-db.com/shellcodes/49770
Pwned !!!
- Title: Pwnctf ret2src Writeup
- Author: kazma
- Created at : 2024-01-09 18:30:32
- Updated at : 2024-01-09 19:23:32
- Link: https://kazma.tw/2024/01/09/Pwnctf-ret2src-Writeup/
- License: This work is licensed under CC BY-NC-SA 4.0.
Comments