Black Watch PWN(栈迁移)
# 1. 程序分析
32 位程序,开启 NX
源程序:
main:
cint __cdecl main(int argc, const char **argv, const char **envp){ vul_function(); puts("GoodBye!"); return 0;}vul_function:
cssize_t vul_function(){ size_t v0; // eax size_t v1; // eax char buf[24];
more...