pwnmedium-hard
Warriors (Chronos Arena)
caplag
Task: Chronos Arena binary with custom heap allocator using XOR-encrypted free-list. Solution: UAF via Time Rewind snapshot restore, leak SECRET_COOKIE via OOB read, poison free-list via OOB write, allocate chunk at g_bridge to overwrite dispatch function pointer with win function address.
$ ls tags/ techniques/
heappwnuse-after-freecustom-allocatorxor-encrypted-freelistfree-list-poisoningarbitrary-allocfunction-pointer-overwriteoob-readoob-writeno-pieno-relro
function_pointer_overwriteuaf_via_state_restorefree_list_poisoningxor_cookie_leakoob_read_leakoob_write_poisonarbitrary_allocation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]