pwnhard
Garden
dicega
Task: Custom VM with mark-and-compact GC, off-heap objects, and limited stack operations. Solution: Exploit null-reference GC corruption to trigger cascading memmove that corrupts object headers, expand off-heap object size for OOB access, leak libc via unsorted bin, and achieve RCE via House of Apple 2 FSOP.
$ ls tags/ techniques/
heap_exploitationcustom_vmglibc_2.39oob_writegc_corruptionmemmove_cascadehouse_of_apple_2fsopvm_escape
gc_null_reference_corruptioncascading_memmove_exploitationoob_length_expansionunsorted_bin_libc_leakhouse_of_apple_2_fsop
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub to get started.
$ssh [email protected]