Closed bannsec closed 5 years ago
Those addresses are the emulated ld-linux.so.2. If you look further in the trace you will find stuff at 0x400000.
Unless you're using archr, you can't expect addresses from a trace to correspond to addresses in angr.
Running QEMURunner on a test binary from the recent UTCTF (Jendy's), I noticed that the base_address was off.