pwnhard

Garden

dicega

Task: Custom VM with mark-and-compact GC, off-heap objects, and limited stack operations. Solution: Exploit null-reference GC corruption to trigger cascading memmove that corrupts object headers, expand off-heap object size for OOB access, leak libc via unsorted bin, and achieve RCE via House of Apple 2 FSOP.

$ ls tags/ techniques/
gc_null_reference_corruptioncascading_memmove_exploitationoob_length_expansionunsorted_bin_libc_leakhouse_of_apple_2_fsop

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]