Here is how I captured the stripe.com CTF flag. A complete walkthrough.
github.com
github.com
Thanks a bunch
While this made my solution for the fun() level much cleaner (I didn't need a nop-slide, and I had no shell code: I overwrote a single address on the stack to short the program into a call to system(), return-to-libc-style), it apparently wasn't warranted to spend that time or effort: dividuum was able to metaphorically sprint through those levels while I was wasting time staring at the track. ;P
while ! echo 'cat /home/level05/.password' | /levels/level04 "$(printf %1036s)"$'\xd0\x23\x5b\xf7____\xee\xab\x6a\xf7' | grep -F ''; do true; done
(To be clear: I still had to brute force the ASLR; but even if you are doing the executable-stack+shell-code approach, you don't need the nop-sled as you can just calculate exactly where you intend to return to; that's what I meant by "totally reasonable" "guesswork": the nop-sled works and kept you from having to stare at the assembly.)
(Note: my original version only required a single address, but involved more messiness outside of the program; the command I pasted here is a revision I made after an e-mail exchange I had with a1k0n, who reminded me that "/bin/sh" was a string that already existed in libc, so I could run an actual shell rather than some random garbage.)
(edit: Awesome! It turns out mpetrov managed to make a 100% deterministic version, which makes the executable-stack+shell-code approach look a lot cleaner, as it drops away that irritating brute force step ;P. http://news.ycombinator.com/item?id=3630826)