This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Daddy bought me a system command shell. | |
| but he put some filters to prevent me from playing with it without his permission... | |
| but I wanna play anytime I want! | |
| ssh cmd2@pwnable.kr -p2222 (pw:flag of cmd1) | |
| ------------------------------------------------------------------------------------------ | |
| mtrlpq3015w-lp130-01-70-30-167-203:~ dual5651$ ssh cmd2@pwnable.kr -p2222 | |
| cmd2@pwnable.kr's password: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Mommy! what is PATH environment in Linux? | |
| ssh cmd1@pwnable.kr -p2222 (pw:guest) | |
| ------------------------------------------------- | |
| mtrlpq3015w-lp130-01-70-30-167-203:~ dual5651$ ssh cmd1@pwnable.kr -p2222 | |
| cmd1@pwnable.kr's password: | |
| ____ __ __ ____ ____ ____ _ ___ __ _ ____ | |
| | \| |__| || \ / || \ | | / _] | |/ ]| \ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Mommy! I made a lotto program for my homework. | |
| do you want to play? | |
| ssh lotto@pwnable.kr -p2222 (pw:guest) | |
| ----------------------------------------------------- | |
| mtrlpq3015w-lp130-01-70-30-167-203:~ dual5651$ ssh lotto@pwnable.kr -p2222 | |
| lotto@pwnable.kr's password: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Hey! check out this C implementation of blackjack game! | |
| I found it online | |
| * http://cboard.cprogramming.com/c-programming/114023-simple-blackjack-program.html | |
| I like to give my flags to millionares. | |
| how much money you got? | |
| Running at : nc pwnable.kr 9009 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Mommy, I wanna play a game! | |
| (if your network response time is too slow, try nc 0 9007 inside pwnable.kr server) | |
| Running at : nc pwnable.kr 9007 | |
| ---------------------------------------------------------------------------------------- |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Mommy, there was a shocking news about bash. | |
| I bet you already know, but lets just make it sure :) | |
| ssh shellshock@pwnable.kr -p2222 (pw:guest) | |
| ---------------------------------------------------------------- | |
| mtrlpq3015w-lp130-01-70-30-167-203:~ dual5651$ ssh shellshock@pwnable.kr -p2222 | |
| shellshock@pwnable.kr's password: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| We all make mistakes, let's move on. | |
| (don't take this too seriously, no fancy hacking skill is required at all) | |
| This task is based on real event | |
| Thanks to dhmonkey | |
| hint : operator priority | |
| ssh mistake@pwnable.kr -p2222 (pw:guest) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Daddy told me I should study arm. | |
| But I prefer to study my leg! | |
| Download : http://pwnable.kr/bin/leg.c | |
| Download : http://pwnable.kr/bin/leg.asm | |
| ssh leg@pwnable.kr -p2222 (pw:guest) | |
| ------------------------------------------------------------------- |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Mom? how can I pass my input to a computer program? | |
| ssh input2@pwnable.kr -p2222 (pw:guest) | |
| ----------------------------------------------------------------- | |
| mtrlpq3015w-lp130-01-70-30-167-203:~ dual5651$ ssh input2@pwnable.kr -p2222 | |
| input2@pwnable.kr's password: | |
| ____ __ __ ____ ____ ____ _ ___ __ _ ____ | |
| | \| |__| || \ / || \ | | / _] | |/ ]| \ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Daddy, teach me how to use random value in programming! | |
| ssh random@pwnable.kr -p2222 (pw:guest) | |
| -------------------------------------------------------------------- | |
| mtrlpq3015w-lp130-01-70-30-167-203:~ dual5651$ ssh random@pwnable.kr -p2222 | |
| random@pwnable.kr's password: | |
| ____ __ __ ____ ____ ____ _ ___ __ _ ____ | |
| | \| |__| || \ / || \ | | / _] | |/ ]| \ |
NewerOlder