๐Ÿš”Vip_at_libc (Pwnme 2023)

Integer Overflow + Ret2PLT

Challenge:

checksec:

Pseudocode:

Sau mแป™t hแป“i tรฌm kiแบฟm, tรดi biแบฟt ฤ‘ฦฐแปฃc lแป— hแป•ng Buffer OverFlow nแบฑm แปŸ hร m access_lounge nhฦฐng cรณ 1 ฤ‘iแปu lร  khi menu in ra thรฌ nรณ khรดng hแป xuแบฅt hiแป‡n case thแปฉ 4 nhฦฐ แปŸ hร m menu:

Mร  cรกi nร y cแบงn cรณ 1 ฤ‘iแปu kiแป‡n ฤ‘แปƒ nรณ ฤ‘ฦฐแปฃc in ra. ฤรณ lร : money._4_1 != '\0'.Nรณ tฦฐฦกng ฤ‘ฦฐฦกng vแป›i:

ฤoแบกn nร y chรญnh lร  ฤ‘iแปu kiแป‡n ฤ‘แปƒ in ra case thแปฉ 4:

Set breakpoint tแบกi ฤ‘รขy.

Lร m lแบกi

Thแปฑc ra sau mแป™t hแป“i thรฌ mรฌnh phรกt hiแป‡n hฦฐแป›ng ฤ‘i ban ฤ‘แบงu cแปงa mรฌnh hฦกi cแป‘ chแบฅp khi khรดng phรขn tรญch nhแปฏng hร m khรกc trong khi lแป—i ฤ‘รณ nhแป xรญu nแบฑm trong hร m nร y:

Vร  tรดi ฤ‘รฃ chรบ รฝ vร o nhแปฏng phแบงn nร y:

Ban ฤ‘แบงu tรดi nghฤฉ lร  lแป—i nแบฑm แปŸ game [4] nhฦฐng khรดng khi tรดi thแปญ thรฌ thแบฅy nรณ แปŸ phแบงn cost. Vร  bแบกn ฤ‘oรกn ฤ‘ฦฐแปฃc lแป—i ฤ‘รณ lร  gรฌ khรดng. ฤรณ lร  Integer OverFlow. Hmmm cรณ khรก nhiแปu lรญ do ฤ‘แปƒ tรดi thay ฤ‘แป•i hฦฐแป›ng nhฦฐ vแบญy. Bแบกn hรฃy trแบฃi nghiแป‡m rแป“i nhแบญn ra ฤ‘iแปu ฤ‘รณ.

Vร  bรขy giแป case 4 nรณ sแบฝ hiแป‡n ra khi mua vรฉ VIP:

Chแปn option 4 thรฌ ta sแบฝ cรณ 1 lแป—i nแปฏa lร  Buffer Overflow:

Nhฦฐ vแบญy tแบฅt cแบฃ mแปi thแปฉ gแบงn nhฦฐ xong. Phแบงn cรฒn lแบกi lร  leak ra address of libc thรดng qua ret2plt. Rแป“i sau ฤ‘รณ chiแบฟm shell cแปงa server.

Payload

Last updated