Fork me on GitHub

Pwn

通用技巧

Linux命令

readelf

  • ELF header: readelf -h
  • .dynamic section: readelf -d
  • .rel.plt;.rel.dyn section: readelf -r
  • .dynsym section: readelf -s

ROPgadget

  • ROPgadget --binary bin --string "/bin/sh"

GDB

peda

pwndbg

  • heap 命令不支持32位程序

dpkg –add-architecture i386
apt-get install libc6:i386
apt-get install libc6-dbg:i386

Pwntools

栈溢出