一題ROP - 資安
By Annie
at 2018-12-09T18:04
at 2018-12-09T18:04
Table of Contents
最近再看inndy的rop2可是看了writeup還是不懂為何這樣寫
題目是rop2
http://www.carlstar.club/2018/10/24/hackme.inndy.tw-pwn/
關鍵payload是這樣
payload = fit({0xc +
0x4:[p32(addr_sys),p32(addr_gadget),p32(3),p32(0),p32(addr_bss),p32(30)]})
想請問為何syscall後面可以擺一個rop gadget??
我看syscall不都是用register來當參數,為何stack這樣擺可以work??
感謝各位!
--
題目是rop2
http://www.carlstar.club/2018/10/24/hackme.inndy.tw-pwn/
關鍵payload是這樣
payload = fit({0xc +
0x4:[p32(addr_sys),p32(addr_gadget),p32(3),p32(0),p32(addr_bss),p32(30)]})
想請問為何syscall後面可以擺一個rop gadget??
我看syscall不都是用register來當參數,為何stack這樣擺可以work??
感謝各位!
--
Tags:
資安
All Comments
By Heather
at 2018-12-14T08:17
at 2018-12-14T08:17
By Jacob
at 2018-12-18T22:30
at 2018-12-18T22:30
Related Posts
學校網路被鎖
By Barb Cronin
at 2018-12-04T22:42
at 2018-12-04T22:42
萬豪酒店坦承遇駭 5億客戶個資外洩含信
By Mason
at 2018-12-01T02:17
at 2018-12-01T02:17
萬豪酒店坦承遇駭 5億客戶個資外洩含信
By James
at 2018-12-01T02:17
at 2018-12-01T02:17
[email protected] exploited
By Andrew
at 2018-11-27T10:07
at 2018-11-27T10:07
ISDA 我的黑帽女友之WIFI入門
By Aaliyah
at 2018-11-23T23:15
at 2018-11-23T23:15