# Problem.
This problem is about the buffer overflow vulnerability.
# How To Solve.
First of all,
Download bof ( http://pwnable.kr/bin/bof ) & bof.c ( http://pwnable.kr/bin/bof.c)
and i look the bof.c, it looks as follows.
data:image/s3,"s3://crabby-images/2d9b5/2d9b526098051171af90846416bfe9076f97650a" alt=""
first, look at the main function, I notice that the 0xdeadbeef is calling the func() as a transfer factor. and then, look the func() function, I notice that if key == 0xcafebabe, system("/bin/sh") is excuted.
To change the key value 0xcafebabe, I analyzed the bof using the gdb.
data:image/s3,"s3://crabby-images/6aacf/6aacf7daff40aff633557a344fca62053a1af811" alt=""
and I disassemble <func>. It looks as follows.
data:image/s3,"s3://crabby-images/7bb47/7bb476055722180a661db54db175086382fa5ec7" alt=""
From <+29> to <+40>, It can be seen that the distance from buffer to ret is 52bytes. So, I can change the key value by filling the dummy value by 52 bytes and filling with 0xcafebabe.
Here is the payload and flag.
data:image/s3,"s3://crabby-images/a39f5/a39f5871a1436e10d5a1bbde39c347e60a23c819" alt=""
No comments:
Post a Comment