From 70d6f3836959760d0d79fe5dc15bc87da93d7f82 Mon Sep 17 00:00:00 2001 From: M4xW4n9 Date: Sun, 22 Apr 2018 09:46:58 +0800 Subject: [PATCH] unfinished --- XDCTF2015_pwn200/bof | Bin 0 -> 7612 bytes XDCTF2015_pwn200/bof.c | 19 +++++++++++++++++++ pwnable_critical_heap/critical_heap.tar.gz | Bin 0 -> 6578 bytes 3 files changed, 19 insertions(+) create mode 100755 XDCTF2015_pwn200/bof create mode 100644 XDCTF2015_pwn200/bof.c create mode 100644 pwnable_critical_heap/critical_heap.tar.gz diff --git a/XDCTF2015_pwn200/bof b/XDCTF2015_pwn200/bof new file mode 100755 index 0000000000000000000000000000000000000000..bf5d75569ef3d35d8b70ac7b4bc2c4cf009a9790 GIT binary patch literal 7612 zcmeHMeQZ*90hI~LP1g}o~61#Qm%zmb! zLv2$7ZDuS*9jhvJ+UV$3Y3bvQ3(nsbMv0D$$iPwqP( zTrZ}hiaN~(8jz=<4$a^}h*n_Dp93aShib_XW8|GF1exuHSLug6==*xbK{Q$iX1~-| zK%9gA9Q2Zj!PK)4auoKOgTQ31YdT{`4$lxm^X<@)wSE)yfS)1yNB5!`dgu7&p)WGq zLx?5uSo@NAGv9wV``z2# z{@YDI`Rl28-7Eck?kmCcA!B98rn2s*-+2EpswYsL1I?2IMC@z{fwNLzM$rW3XF1P9@iZFYxa3GqNG zW?N!y~zZKYN7DI0SIa85brEU7;L%&-fH^UO6vO3#mBhqy%;W!8CPF)W1&(M=_Y zd!-7pSeEDKE9^6r90Hz>j)o}_&>|%k(Fi3xpQD^5#6?O3ew4CWh-$Q-fq{4_G1wYP zEZS=*F*oxl(Q!+5q^kHEAw*x{#koS{vc*!VwCAurt(Zb(_E^={0;CY7L!8ahL5`JF zI*3k0l*O|{Xi_@Jr;Ad3_LRij6;W26JuER_NKyWreM#bZ#0K#JiHGsqIZ!&t0dx*5 z{b+mtpR&W}np&HST+@98FNT-T9{8YCYRYHVP;A;b^#UJ43d~Tkv&^e(0CZf)P z;?)R7-_c)TZRfwe5DxQ?-i+TxZ)Gn|-*I*BQ9c76`^vWdGue@vO{G)WW8RaW6#6gZ z-;mp{c$$MannU|G?SO9j&$KLh>&V55>_}yQ;mC*cUB7+%qFs}FVwC>gv1cK?O`A&Z zz*}zH=*e+^=%=N)1x9^^Rq%=CkGxKQB6CwN%TQo2v$G@Br9(bc7XNUmRDzG<3TRGb zY3Q2hueb_zeMdjMmQOYU>s-~IlbM-kgJ_VqzbtZ3T%^-??2ptFHpwxaJnKVkuEtm3 zc(NmQ@fe!+6`qBgTy}&y46Q2Pw!gWlI8%)QLydBY=R^CO?h{3~svVHS$v65cF=?f5 zj>6xTmQC4_UB#62*bI+@q1{`oc*kJq@npAU42JgEN#pLp&_J-hwP7%{e_8F)6@#It z9{SQOk#GCnt9Tyq8jqj;)1N$_%bpt_%x(;3*FR-I5TSf%cT+L1VPzBXeXious-}1Y z+DTt|>-;@i&29PcD3-}U+m_8O#nZ6qE4+e52|u~G&&VGtVzk8%FnjszFp7 Jy4n z=YoCX(o$Z&=J50-+qan9R@(nMZL)(dOwCs>W!}#otKPcZ+*Zi%5T9V%$i0=8eYCI- zZYI7nI%EESKM*kZC_dDTfhyu20Q>8mPrPf{g0ym z21pU`RPCv#yK-7E>wf5X0p5k+SUI-qF{bBe6RdWLwccqJ84^i&0odoT_;W<2Ww_~JYGGF^_q|93ZAtC|{yQYc^S{uO9DJGh{j6y(96t&EG5BTh2{4J@5Nqq}zh*29TJ5oL!dU5F z?ytRN*&F_9p~jpUXQRdH4rA37k$pX8Rar`CbOoJApe#`IhznBOtX)uQf3DBS{=5FoA} zl3QFQ<*Q>@Wk$SbAi3qNBR?9$oPD+KDBW@usCB0>R}H?=%5&r{uP!}jZt(@F=eHfn zEms!`1`+W!QW}O7z+B}*EHtD5<|-d2x0ox+p_Y}E;^Pt{p!;{Be|o4b@1+VnKle+I z1N(vXUZXw;%>L-th5lL~xvxkr?1~2=xj#v?-wVlaS&|F!_>n5gUyf(;_@0NRT1_kL z=ZM#Uo#S;h$3FhJbQ~4Bf9|^XfOR}wi02=Hb^p}=1z67?ckMI|zyO0>i0@qB1DH=P z$vGJR&5i+bcE3IeZ*X7(`WUc*_;HENsqlzj5K{p%5bcM7n-HG{VEW$;tmn@Q{f)qS z{msGp%Kt|P7EB*}Zyo34FVbAB|oq#4{ z-z2;Ocn#vie4XPDIrMx7z71Y%;0NTz`Y6EvP=U zFyC*_!Jh3Oao8KE+wZXF^BtI^zXO=(0%;E4>K!RNZD%?={T;aMxwF36Y+T>cYMNsF zLddkc%?@4(;jYJwB+agPvOOF(BX%;CHp7`-(UI)#iCeZ6@vmI5YW37cyrYVl;Z!QT z)3g$HYNzN-g}W^?lIiZ=i6#zY!qT2#+MZOyYiJH^2$`XcL5xogR+lF|>F=^^v!}zfqnX70{`Ow6BNI;u(~5-cF#7w9MWh$C&Kth* z-gt+H=|DquI|nfFs?Ln0lV&uWi0~S3@^vCF632bv4sh~~p;IX@51kc`$S}O>dUAq6 zXO9_ufc3bfoS-n<)9Lbn<;CQbH;N|iAoVo!a&qe1MSpr{w;gU5e%y;H8P%m&0vDM* z!kM-jwKTlfC*j7 ziql>ddg8Y5%P{y+^miozZL1f*T=K9<%Gvc>(efgXM&Lpt)l{u^)k2r=>wp=033taj zFoL8__o(4g@gs`DkA2sTy`(ntfAPz+jITGo5}g0L&`tHL?*>%hl_c%-{}>Ey1X+H4 zh@~iNJLWiK-xPL1)LlSc$9|dnkPVb^EJ&h1@V8>Iz8}ndlx5~t+iHJ& z2Ija~FzxEV1}e$Sk!i<_MceH|nPX)?d?%A{Kv@&*NRNTF9dkGGy;PKmF`?}fU~R{o zj!c~nN3t>ken%EbK{}yGrRw8A0W4TO0oo2`K5KZvMwe>~lmw@RT hRdUU +#include +#include + +void vuln() +{ + char buf[100]; + setbuf(stdin, buf); + read(0, buf, 256); +} +int main() +{ + char buf[100] = "Welcome to XDCTF2015~!\n"; + + setbuf(stdout, buf); + write(1, buf, strlen(buf)); + vuln(); + return 0; +} diff --git a/pwnable_critical_heap/critical_heap.tar.gz b/pwnable_critical_heap/critical_heap.tar.gz new file mode 100644 index 0000000000000000000000000000000000000000..ee7bc1bd0921e2695ab89457dcee4b2029be4dff GIT binary patch literal 6578 zcmV;j8BOLNiwFSPzGzqg1MFN2bW}x}uFeC(D`^BJ5*`-@BqHf_LI?qjbOM2n2QUKh z2{ui4hi>UdwsV^#4verNN^e9ngX7|JIIg?Oj>@d#I*4OB3~F%32c8ut$H6(QpxYq< zf*=NY^#1>?s@rv&+~Ay}p4~Gk=>Gru{zp~)^;g}x-F@Q-dSs8o?zOpH_Uc^ngA_BA znKNb}&6_#HEK*)b-gNWy{JiNir{@8lS76RJ6KTc|(;aOI)yVdsBoVuRjmx__P_L(V zCHeo;;?T^$?E4{dfX;uxcbfnFyqP%vh50l3=l{nj+WD_>+k>v}Jp=xh^`DP;-i*Bd z`TucBZ}YFgzK1rH`Jbsb{{;n_`7bDh`JY)>Fq25;@1gB0mcR4)zrSqJf+T}MttXM2 z2-cd1T9mql;g*uPjfE7ELGYeMMw0qSWx4IRVu zI5h|~RWkyMhORde4JAZU?Xa&>F++=2X=o4YM|Y~$E{WL{F}otB&uJ^`SZl)gQrK%b z^Shjli_`f`Z@!?9rQ!?OiM)9#t(&J>H1uPp_i=*Vtzb8ReD`8xbSZ03FD{2!|2gIJ zkn8oVE-c9PI&-`pf2b~}uBb4lu)tIkFy$+KGBVwTODYw89!H7wc_g7Zfbw_u-1OSP zBgYzSjZ+B7GyW=gjeyrEc#Vcv7QDv6tH?5R*KBKJR^IM^99DYggR#khnGXeT ze02TuPi`CYO3tVZ(~{z|g@=!vd$jJE^>3NpeR{~}ov%J>zQ|zdviRxsoyAYDZ<%s+ zVfNUE#zY=CnXWfa=Lye5ZCT95kyv)<;1B8GZ|UHl>fnFU!E1H!79G4p2Y*=yKd6IW zr-KjC!RP4U&*0_&6QBQU_m4FfTKS*|JKh^ZjF+j{aRbc%}}%KnMSw4*oM8 z{Ba%pS{?j=4*oo$f_A@?)W|`+%zy%U9!)iNg&|5cEw#egItlb!Zz1$q0I@?Xnv?gs|Of5Bjj; zsC5#%9Pkit01j5N2f7EA>sE&p=QsqL4M&Q73d%O09eZM1;|us1Vj~L|m6y)5<(sCP z3gW!V#j$)7JvS#^_AfRS|K`^T`C88)++7D7C^o|58HT&_HLN~T zsV5VO)kC9EKZ#6b7YyTEI^TE=7%fb1rhtzVa7nQ@KpjnO2FL$o+aSb0-hq^bpkG)do~LAAOYVZ;9~^5S-=Mi z_;vx$6!0AaF0RWL1pHb7|BZkf1bnxE4-xQI0Us*h`vrWMfFBTW@nYF7;Ntn`uz(u{ zJSyM=1-x6p(*(Rnz{d(W-@kB9#tXPvz^@i?YeQF>wJEi@KqA)0Ryj4gPXXUb+eb7d zHsjvu5{XUr!h6Pe3vgJkYW{nndB@AcAKhaOe{O9!+Fh}{ysh;&6D`Erw%4MNwjC2J zB)TRRi=C;;7!QZ%-QywPmDZe0Al8PSbZhvFby>TWh(nl%uZ*A|b{Ld5EAd^q52IRT z;`NqH#eUNX#lhZ7$>6{m?zZlY&b1oev3_((zFPG*gnP>v4}NI-8;einOR(JyuLQ%W zA3C=3oz%YqWH_y~6fqZL$L5kyYUehvQ=OecgV=$U9ru9^@{l2tHM}7j4jpZ(JZfz! zi(13)M3kHjT#CiQWfvMYTp;(4jGX@ogkU5<5nO1|Z!gATO=TCX+pSwGVv3pJK*nq2 z#=)TxiSRqH54^jNHD-2Nn^GocV|T)3J$bFxt!0N_$EC6-L&0dZqdee?m;PDi_G$lZw8&DeZX>askEypE=O@N&_jgc%%crqZ(B zrBzfq5TrQZN#L0d__GVKSo2DyyOCMg-g5v%%8`2lxmCzDBUg*u1IRs$+!i z?gxhr^VA~SdUj&3!!xcr$KvJfi@@9e0R>H6J;LUI2q21Kg3V1?f+Zq?adPRed+aYb6 zl&aNnz#2Ya-FrA07MVg)t+<^u;Y!bFoC1oGgX-*V`WDwqV+9zt>|m37{=AA|^-EL< z@748gLGR(TzFTioF2uCW>5x2>y96yY^d!l74L!;7vW6Z*D0GEp+M>l^-MRXTYHLw# z&K1@2V2|h=899RSUVILcn)dJNB>j_(-cTrcU8 zbxuf^#62!@PMwAGJ#^P<8Oo-h?%Vh_cF#G!-wnEd0PcGABO`+*L*q|_RRp(?XhRQf zyX}2X{pM%k4B5L@1=A|VEY8^cM;Or_WyQ`qAj{Tb+#NC+Z_zckFmu?oMos2pnxfaI zhE^jpX=qJDn~AE;>2G4OjTuWBePw~V7I2r{uNvL=HQ$ofe!~t8y?Llp z!aS$!P$;kOCZI?EqdFf8&N~Yt7coaW&Oo-}c|7_da>K6!>>zS@e;0iNxp9c?1+LT3 zeA$lj?iuj{By1tO&+rlKJj)Mg%6@S{-7kD+_9|a<#}sk@Klu9H%u0qxGlb2P{QC59I@<05?mu$wh7wVv~_8MJ@}u zRmcrj^#*EvOQ*#{R|Omyb|+j1sNVfCK7W`Z;j;Id%HG3EV=-JBGd8~h0=PV8G~!2J zk)KWB-v98GayZ+KhcisN_(j%;k*!x`O%@BxXQ)!J`=_sz>&t;X*~0NU`Y89d)tV_v zt>F)&MlRb^cU!?#Srf7*z|qFiIV!RRhkq4FJBLL64fz4UH+NhY>*abl`ksiciz*{i!N$)@<{~ zyE$H<+0hRI-tixp07`Y-DeWP;s+%98+u0$y{jx)JJ3U0VCmf>N=^?sZJVdwCLv*`% zh;FBc=yvfC-A)hD?ZP1%paPx^Jtr|6HeTu_8!nzyv%#1Rs_&n~D>-uekW;YNk*h#% z7jo6e{VQ_K$UTYNZsdNBTsv|Pp5z&_;iM)*9y=M&kWF0`IJx0BcSFY#?^oIy_g|vN zYB&WS0Co?47^U8)-F8wr9(SX_EDDNG^3=*!lWYu3Qn;~IIXU8cYQ}?`lJKaG6=?VE z*6S^B6Cdfx=G{DbLUE7nwq!ET9+=vQbUjyj?}XZe7Gj_(3qU2~HN|W*T;H;x5vX>v z>a|HYn5|glW1_uQ_Tv>Nu#;~ooy2z%%Anix91wJThIb5>>+wDps~=#sLhXyCm+tO4 zsp-qJ1~rl>eL%0Z_m6}7klI=cR;!dX*tlDXmL(IfOACa03*LXD(^H^~*Yz7keOv@_ z)9@##co@B2qxGuJV8d~?gs2EsQAa1Pw>ovWw;sQIxPLmK8E!;KoD{abK8^!A*oA!z zjTd6^?_CKEW_RAnZIhYpGidwx<+lDrTXW}FL3~T1Sc*K0p4I@~IgT#QyOAH!+_B&y zE>er~K3jP&xY)~rUDWm6ZfB--CEU*JJRZNDd8A7@U^Q$wq#REUsmGHKI{ESB)lNKZ z9J<2o41R0WyO!p5M!rkEm6=9wWkTNG&GCuGR`sp(DBdBK_O0`a^Gc+ZGv29V z{EYYKWBiQw*|AFpmrs?haIj*+2N?%3_C;T63TzkjUlA`4R}N@r2JEO=RTG4XD%rr z?8d}>xdTQwD;3Wv$SDc@1aKX-u-hu1f0o={a$89_R#I8Ae9_j)AB>hrrFCl#(q-l0 zv*qD~i?07d`Rse|#pLKWQOL>0Lu}+BYr{T+byjES7=AE* z_sWtLB`ZtrDY5Nqj(=WzdLR2Noqcp}VBZc&Lb2JznlxCftjIOxbmYZucO}X3- z403XFbChB-X=J&QN%L<-T&9R}SC}Y~OjJl^>k)&#Faj#;xoAa#N0TWoG9}7#<2|8v zD{MAft}0STFeS%iv+@5qbclnMZ!jfSFc=7umbn~^TkdvA_(d^xpoRv5`3FI$#ue;U;Ai8~2xuwySBGRt2BjL8Bj{41f;Bd} z#r53C>5}apuVRYS0=I?J&bI z4CTin)N7x5xE5!V%4KCs3B;I`Pk|l;U5-G|iAf=b3tC+}-lF*Xb_}IE$5J|K9HrYC zeT3v;rBO!DFiMzwD5IH-8nTk-;BOD{yZ=@H9gE@bJyv}li*-Z& zwj*$Phx$ICZlH6I#$sE5-UIXnpeKOt2U_?=EEdI2Nr9%p<-6|7SPXBTz65Fo`aB#H z+(6I4$z}`CgK(660q8Ao=-&_Y*Fd8{e+MTU{N#EBoNBUxzKwV1Kxcdf_CVLc31hwty3Dd#fehz@x`4A{cH$IRwZ`gn& zH+Z6QC%l${e7#0qtIF|2v@$R7jwUV|V{{=ESel<@;T6LMl{iYQ;4 z!sVMm?tx?SA&vh(tNxz@`DD1Sxlbbx#m5iw`$4`!BfmX9evrQb@}Zjk4OIJ=g1OqI zZ$Am-M?n6H#{MPMem=-UkjvE?`?c};2l?9|FG&{dZ%kIlk81{U-l_3#Q~f^&@~Nj| zvBxz2e;yw{$ajGJ$zJjYbMq+3r8BXZ3xU#f<0DC>>6s5Fm!(TvQ%cjbA4;{Rn;#fp zO)qK~xH#PsOfM=)HtC{JC2G><@p|gg+CN&E#Ve zNk1(0q}qW<`^KsyG|I=^qN6HXAxqmao5N}*}j^XJbu{~tR^OZ zKz5l*O3QO(`x;hT;}4luhdf?qj>k!qn%iFECMIXSzoyY5s2as+%nmtX##;*IMP*8u-)EdF;8XnjnAz9FHG&p-|o?BjoD zfYzl1{gj0Igamt;*~<)=bOrkYc%6l{%kBC8w4MJw1%~teN_@5s%T0vFfZOx^YYW?F zG8yI16>@vN-{AAj$$~xK4|lK)u`nTEiSb)P=w8I_`Tp|>+W<=w`k$0Q?x%e{ogl-u+D)-C>_403t=`1oZK|JxRd9lQRx*@iDZYfH%G^LJl@eKWIf zX7;a0RMn41v+)=(zVFgv3KN=;$7(22wd00J%BCqx%as{9{JwA zl#eg-`2(YWN%Sv?{&kB6d;ZVa_DSB6AIXB+`H;3}`}2a)m+S4TPI3GJW6z%dPc7R2 z&WZk<=;QZkd$#{SGx}}5j^g-t#-45e7e;^Q(=W(pah$zJ+q3PzY8CIpmS)@h9nJRa z@p-FwFS^v1@y91u)c;EQU+Q~A-@Bszw-)`b^)|l>=^t^}^7@wg@;-RRv|q+A|J*0` zjKkkyKL23!E%N?unO264YuNt(Nw{kKiT)#^f6e^U12Fo(Nc(KAqf$R)csA~&`d))h z^nYKVFVU3$DOrbTC2y$o9g*jM8eW|Lt>2fJ{BP2Z#PdJh2=3h#kGxPkLJ?T|UK^f5 z2khJzUAPg$wePpHVq+MPdZ2M{7=7HnygiQF1=|1B$axBrW6y`z*#`D;=`H?08jV>0 z@8SG^-2eZ3JTMkBP(0Yl`Ey-+Hkr;>=tna^dCqO)U=Hj!6CT41tn=Mt6y>1@Hrw~X zsTab`1;SZlDb8;r3215&yuq$iTH(!(wu?joVCI&**m)8}E*Ou804FD{QG!vh8#}q6 z1hv$_qQ$Mo_Q!)kUUOAZu0so9K&+yZ5Nnet%4Gbjc^+)<%~bGpM_i|gnBobw7>dqk z9l?#l>^MrEcD}id(gRFN6p`>lY3xjr>lnp*KEwwKYCxO$i%t~q)rBF(KeUVbu*RG(%Ew1cWJPNFPw zA|I7xPF&IXW@+V(xua4=3GUKxSNgo-j(z)aibz8{Ftx2EOsq6oCk}3VRMCm=1zu)3 z@fy*CiVnTpuD{#<{x-Vxl|lQzo3H64_7X{NbYYIEf~kgvUX>Gffn#vYnN zKCX99pUn3a7+MErjWi$Xhq}_I7){re?K9D~WU4Ct!C+it9xlvPej@Qnh$qQzc2X-v zaTKZuM-_qX`ELXawQ97R?0|1&QiZHn53pV zG@Q+*re+*Y_uhIPmU|ZNi>dTZ>%+d9E%VEQ1Fu>qztrZ3RxyIr;B6v*9l*4H?{tgr z8RW(_0R>r459zVs?9c5A!{@>oo k!NI}7!NI}7!NI}7!NI}7!NI}7!SQbR7yN~CvH*Ah02qKN761SM literal 0 HcmV?d00001