-
Notifications
You must be signed in to change notification settings - Fork 19
chapters/exploitation-techniques: Handle 07-challenge-shellcode-on-st… #56
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
catalinamanolache
wants to merge
3
commits into
open-education-hub:main
Choose a base branch
from
catalinamanolache:fix-shellcode-on-stack-challenge
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from 1 commit
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
8d2398a
chapters/exploitation-techniques: Handle 07-challenge-shellcode-on-st…
catalinamanolache 516d911
exploitation-techniques: Add Dockerfile 07-challenge-shellcode-on-stack
catalinamanolache c3975a1
exploitation-techniques: Add Makefile and README.md
catalinamanolache File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
12 changes: 12 additions & 0 deletions
12
...tion-techniques/shellcodes/drills/07-challenge-shellcode-on-stack/sol/README.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,12 @@ | ||
| ### Building and running | ||
|
|
||
| **Running challenge** | ||
| Make sure you are in the `sol` directory and run the following command: | ||
|
|
||
| ```bash | ||
| ./run.sh | ||
| ``` | ||
| This will build the `challenge07` docker and run it. Afterwards, the `vuln` | ||
| executable will be copied to the `sol` directory and the `exploit.py` script | ||
| will be executed. | ||
| Cleanup will be done automatically after the script is finished. | ||
19 changes: 19 additions & 0 deletions
19
...ters/exploitation-techniques/shellcodes/drills/07-challenge-shellcode-on-stack/sol/run.sh
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,19 @@ | ||
| #!/bin/bash | ||
| # Build the Docker image from the correct directory | ||
| cd .. | ||
| docker build -f src/Dockerfile -t challenge07 . | ||
|
|
||
| # Run container in background | ||
| docker run -d --name challenge07 -p 31345:31345 challenge07 | ||
|
|
||
| # Copy the binary from the container for local analysis | ||
| docker cp challenge07:/app/vuln sol/vuln | ||
|
|
||
| # Navigate to the sol directory and run the exploit | ||
| cd sol | ||
| python3 exploit.py | ||
|
|
||
| # Cleanup: Remove the local copy of the binary and stop the container | ||
| rm -f vuln | ||
| docker stop challenge07 | ||
| docker rm -f challenge07 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Add ending newline. |
||
28 changes: 28 additions & 0 deletions
28
.../exploitation-techniques/shellcodes/drills/07-challenge-shellcode-on-stack/src/Dockerfile
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,28 @@ | ||
| # Build Stage | ||
| FROM gcc AS builder | ||
| WORKDIR /build | ||
|
|
||
| # Copy only the content from the src directory | ||
| COPY src/ . | ||
|
|
||
| RUN make | ||
|
|
||
| # Runtime Stage | ||
| FROM python:3.9-slim | ||
| WORKDIR /app | ||
|
|
||
| RUN apt-get update && \ | ||
| apt-get install -y --no-install-recommends binutils cpp && \ | ||
| rm -rf /var/lib/apt/lists/* && \ | ||
| pip install --no-cache-dir pwntools | ||
|
|
||
| ENV TERM=xterm | ||
|
|
||
| COPY --from=builder /build/vuln /app/vuln | ||
| COPY sol/exploit.py /app/exploit.py | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Why do you copy the exploit? |
||
|
|
||
| # Expose port 31345 | ||
| EXPOSE 31345 | ||
|
|
||
| # Run the vulnerable binary | ||
| CMD ["/app/vuln"] | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.