2025西湖论剑
type
status
date
slug
summary
tags
category
icon
password
AI summary
Vpwn
漏洞点在push函数,可以一次4字节往栈里写入数据
data:image/s3,"s3://crabby-images/f1536/f1536c8b26b31949f774600c499697c605013a8e" alt="notion image"
注意覆盖count时控制好大小,之后可以通过show函数泄露count大小个4字节为单位的内存空间,得pie和libc
然后pop掉,重新覆盖一次count,再通过push函数写ret2syscall
最后exit触发
data:image/s3,"s3://crabby-images/4f913/4f9135492615e8c61ba08f663d52156ab047ec6b" alt="notion image"
Heaven's door
程序可以执行用户写的shellcode,在执行前会检查系统调用,只允许2次系统调用
思路是第一次open后通过mmap映射在内存里,重新执行一次程序,write出来
data:image/s3,"s3://crabby-images/7dac3/7dac3daf66b932f8c6c36c2a87fa180fa2bf91d9" alt="notion image"
sharkp
wireshark过滤http流,在8191流里发现接口
data:image/s3,"s3://crabby-images/6f719/6f719280ca6e17576a3e178582c65dd44d0b5ddb" alt="notion image"
在9494流看到elf文件,dump出来
data:image/s3,"s3://crabby-images/46404/46404aa92b932127862610c2fca3229e40eb04c6" alt="notion image"
elf放在安恒云沙箱里跑,得ip地址
data:image/s3,"s3://crabby-images/e77c9/e77c95ae5ea4aa687318c3c937bebb0e32f5a971" alt="notion image"