攻防世界pwn新手区

攻防世界pwn新手区

简介

web学不下去了

wp

hello_pwn

ida打开附件,查看main函数

image-20210905221215647

如果if条件满足,可以执行函数得到flag

image-20210905221233918

栈溢出,通过read函数读unk变量覆盖dword变量

image-20210905221314044

所以脚本如下,四个字节是unk覆盖是p64,decode是为了不报错

image-20210905221122958

执行结果

image-20210905221135736

得到flag

image-20210905221153138

Level0

  • Copyright: Copyright is owned by the author. For commercial reprints, please contact the author for authorization. For non-commercial reprints, please indicate the source.
  • Copyrights © 2021 Sung
  • Visitors: | Views:

请我喝杯咖啡吧~

支付宝
微信