pwnmedium-hard

Warriors (Chronos Arena)

caplag

Task: Chronos Arena binary with custom heap allocator using XOR-encrypted free-list. Solution: UAF via Time Rewind snapshot restore, leak SECRET_COOKIE via OOB read, poison free-list via OOB write, allocate chunk at g_bridge to overwrite dispatch function pointer with win function address.

$ ls tags/ techniques/
function_pointer_overwriteuaf_via_state_restorefree_list_poisoningxor_cookie_leakoob_read_leakoob_write_poisonarbitrary_allocation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]