Solve¶
Solution script and a containerized solver environment for the "heap1" challenge.
Prerequisites¶
-
Build the solver image:
-
Ensure
../publish/challexists (for local solving) -- see../build/README.mdand../publish/README.md.
Running the solution¶
1. Local solve (inside container)¶
Runs the exploit against the binary directly inside the solver container.
We mount the current directory (for exploit.py) and ../publish (for chall and its libc/loader).
docker run --rm -it \
-v "$(pwd):/solve" \
-v "$(pwd)/../publish:/publish" \
-w /publish \
heap1-solver \
python3 /solve/exploit.py
2. Solve against a local deployment¶
Runs the exploit against the challenge service started via ../deploy/README.md (listening on localhost:31011).
[!NOTE] Linux:
--network hostlets the container reachlocalhoston the host directly. macOS/Windows: usehost.docker.internalinstead of127.0.0.1and drop--network host.
docker run --rm -it --network host \
-v "$(pwd):/solve" \
heap1-solver \
python3 /solve/exploit.py REMOTE HOST=127.0.0.1 PORT=31011