pwnPromedium

Древний замок мага (Ancient Magician Castle)

duckerz

Task: Binary with buffer overflow, NX enabled, no useful ROP gadgets. Solution: SROP (Sigreturn Oriented Programming) with stack pivot to control all registers and execute execve("/bin/sh").

$ ls tags/ techniques/
sropstack_pivotrax_control_via_read

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups