14 lines
230 B
Markdown
14 lines
230 B
Markdown
|
# Ret2libc
|
||
|
|
||
|
|
||
|
## Finding offsets
|
||
|
|
||
|
* On target find `sh` address inside libc
|
||
|
```sh
|
||
|
strings -a -t x /lib32/libc.so.6 | grep /bin/sh
|
||
|
```
|
||
|
* Sub from `system` address from inside libc
|
||
|
```sh
|
||
|
readelf -s /lib32/libc.so.6 | grep system
|
||
|
```
|