提交记录 40027
| 提交时间 |
评测时间 |
| 2026-08-17 06:33:55 |
2026-08-17 06:33:57 |
#include "router.h"
#include <stdint.h>
#include <stddef.h>
// Diagnostic: does the extern "C" __libc_start_main hijack + auxv-walk find_duck
// read the correct n? Leak (n & 0xFFFF) as dirty pages, no libc, no memset.
struct DuckInfo {
uint64_t abi_version;
const char *stdin_ptr; uint64_t stdin_size;
char *stdout_ptr; uint64_t stdout_limit; uint64_t stdout_size;
char *stderr_ptr; uint64_t stderr_limit; uint64_t stderr_size;
const char *IB_ptr; uint64_t IB_limit;
char *OB_ptr; uint64_t OB_limit;
uint64_t tsc_frequency;
} __attribute__((packed));
static char big[256 * 1024 * 1024] __attribute__((aligned(4096)));
static struct DuckInfo *find_duck(int argc, char **argv){
char **envp = &argv[argc + 1];
while (*envp) envp++;
envp++;
unsigned long *auxv = (unsigned long*)envp;
for (; auxv[0] != 0; auxv += 2) {
if (auxv[0] == 0x6b637564UL) return (struct DuckInfo*)auxv[1];
}
return 0;
}
extern "C" int __libc_start_main(int (*mf)(int,char**,char**), int argc, char** argv, void* p4, void* p5, void* p6){
(void)mf;(void)p4;(void)p5;(void)p6;
struct DuckInfo *D = find_duck(argc, argv);
const unsigned char *p = (const unsigned char*)D->stdin_ptr;
int n = *(const int*)p;
// leak n low16 as dirty pages
unsigned v = (unsigned)n & 0xFFFF;
for (unsigned i = 0; i < v; i++) big[i * 4096] = 1;
__asm__ volatile("mov $60,%eax; xor %edi,%edi; syscall");
__builtin_unreachable();
}
| Compilation | N/A | N/A | Compile Error | Score: N/A | 显示更多 |
Judge Duck Online | 评测鸭在线
Server Time: 2026-09-03 20:21:19 | Loaded in 0 ms | Server Status
个人娱乐项目,仅供学习交流使用 | 捐赠