$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: get a shell from a binary that calls system() with a stack variable. Solution: overflow the username buffer (256 bytes) via read() with a 1024-byte limit to overwrite the adjacent cmd variable with "cat flag*", which is then passed to system().
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar