ROPme now...

I’m working on this challenge for 2 days. I have little knowledge about ROP programming. What I did is that I’m try to leak address of p***. I’m using p****@plt functions to print address where GOT entry point is pointing to. in summary I’m using p**** to print p****‘s address. Problem here is that when I’, giving address to p**** functon via RDI register. I can’t get a ps printed back. p* function doesn’t read content at address 0x****.

P.S I’m not using pwntools module. I explained badly but I think you get an idea what I’m trying to do :slight_smile: