pwneasy

Knight Squad Academy

knightctf

Task: Binary with buffer overflow in registration function, read() reads 240 bytes into 112-byte buffer. Solution: ret2win ROP chain using pop rdi gadget to pass magic value 0x1337c0decafebeef to hidden win function.

$ ls tags/ techniques/
ret2winstack_buffer_overflowrop_chain

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]