pwnProeasy

ret

spbctf

Task: Classic ret2win challenge with 8-byte buffer. Solution: Overflow buffer and saved RBP (16 bytes total) to overwrite return address with win function at 0x401162.

$ ls tags/ techniques/
return_address_overwrite

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups

  • [pwn][Pro]rbp— spbctf
  • [pwn][Pro]fptr— spbctf
  • [pwn][Pro]sptr— spbctf
  • [pwn][Pro]stackgift— spbctf
  • [pwn][free]ipv8— umdctf