data:image/s3,"s3://crabby-images/d74a6/d74a6bd3767d124187ca81dc6063fec3d0fd3762" alt=""
Level11
Use the password “ what!@#$? ” to access level11 account and check the hint.
data:image/s3,"s3://crabby-images/8f463/8f463353c4bfc022bfc0eaaf4a3abe779653818c" alt=""
data:image/s3,"s3://crabby-images/8f463/8f463353c4bfc022bfc0eaaf4a3abe779653818c" alt=""
I think of it as the source code of attackme. Because the content of hint is only source code. This attack exists FSB and BOF vulnerability. I solve this problem using the BOF vulnerability. To try RTL ( Return To Libc ), I first check the ASLR of libc
data:image/s3,"s3://crabby-images/29bc2/29bc2950be556022ed3a8d4174dcc11dce5b54df" alt=""
data:image/s3,"s3://crabby-images/29bc2/29bc2950be556022ed3a8d4174dcc11dce5b54df" alt=""
When I check the ASLR using ldd command, This program does not apply ASLR.Next, I use gdb to figure out the stack.
data:image/s3,"s3://crabby-images/47827/47827eccf42c91718bd06331f94eef728ab9be9f" alt=""
After that, I find the address of the System function and the address where “/bin/sh” is located. and then, I create a separate file and find the address of the system function. Because I still do not have level12 permission.
data:image/s3,"s3://crabby-images/76c92/76c920299c095d1a57153a16b8b57686274783ed" alt=""
Then, create the following code to find the address where “/bin/sh” is located:
data:image/s3,"s3://crabby-images/0745b/0745b939f8040d04ac463df824ba851a5fe2e3cb" alt=""
data:image/s3,"s3://crabby-images/0745b/0745b939f8040d04ac463df824ba851a5fe2e3cb" alt=""
So, I acquire all the materials to try RTL. The attack method is as follows.
data:image/s3,"s3://crabby-images/c2b52/c2b52a7c9e830b183ae3ddf4602b45951d40c4fd" alt=""
The completed payload is as follows.. `perl -e ‘print “A”x268,”\xc0\xf2\x03\x42”,”AAAA”,”\xa4\x73\x12\x42”’When I type the payload, level12 shell is executed, and I get the password of level12.
data:image/s3,"s3://crabby-images/727fc/727fc8768a591750e6be0f01d069520954ddae66" alt=""
No comments:
Post a Comment