mrctf2020_easyoverflow
Ubuntu 16.04
0x01
checksec
1 | [*] '/home/zelas/Desktop/pwn/mrctf2020_easyoverflow/mrctf2020_easyoverflow' |
保护全开
IDA
main()
1 | int __cdecl main(int argc, const char **argv, const char **envp) |
check()
1 | __int64 __fastcall check(__int64 a1) |
0x02
思路
gets()的溢出可以使v4覆盖v5
v5 = fake_flag即可
0x03
exp
1 | from pwn import * |
评论
匿名评论隐私政策
✅ 你无需删除空行,直接评论以获取最佳展示效果