You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

格式字符串漏洞演示:无法读取栈中密码值的技术求助

格式字符串漏洞利用问题:无法通过脚本读取目标密码

我正在准备一场网络安全演示,计划利用格式字符串漏洞做一个简单的黑客攻击案例,编写了以下演示代码(分为两个文件):

演示代码

main.c

#include <stdio.h>
#include "secret.h"

void testPassword() {
  char password[64];
  char input[128];

  readPass(password); // 将秘密密码写入password

  printf("Password: ");
  scanf("%127s", input);

  printf("\nYou typed:\n");
  printf(input); // 存在格式字符串漏洞

  if (strcmp(password, input) == 0) {
    printf("\n...Senha correta!\n");
  } else {
    printf("\n...Voce errou :(\n");
  }
}

int main() {
  testPassword();
}

secret.h

#include <string.h>

#define pass "bcc_unesp_2024"

void readPass(char buff[64]) {
  strcpy_s(buff, 64*sizeof(char), pass);
}

利用脚本

我打算展示漏洞利用的基础原理,并用以下Python脚本查找密码及其他关键值:

import pwn

pwn.context.log_level = "critical"

programa = pwn.ELF("./a.out")

for i in range(0, 256):

    payload = b"".join([
        b"%" + str(i).encode("utf-8") + b"$s"
    ])

    pty = pwn.process.PTY
    p = programa.process(stdin=pty, stdout=pty)

    p.recvuntil(b"senha: ")
    response = p.recvall().decode("latin-1")
    print(response)

环境与问题现象

运行脚本后,能看到大量环境变量、乱码字符串甚至段错误,但始终找不到目标密码。我使用WSL2编写代码,在Ubuntu 20.04.6 LTS虚拟机中测试结果一致,编译使用GCC 11.4.0,未添加任何编译标志,仅执行gcc main.c。

已尝试的操作

  • 将所有代码合并到单个文件
  • 在函数作用域内直接声明并定义password
  • 在Python脚本中使用%p搜索指针、%x搜索十六进制值
  • 通过GDB调试查看栈指针$sp后的内容,能找到目标密码,但无法用脚本复现

恳请提供相关帮助或建议,若有信息缺失可随时询问,提前感谢!

内容的提问来源于stack exchange,提问作者arg_arthur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 22:02:14