pwnhard
printfology
miptctf
Blind format string in snprintf with Full RELRO, PIE, seccomp. Solution: __printf_arginfo_table hijack with %*N$c relative addressing, _dl_make_stack_executable to bypass NX, ORW shellcode for flag.
$ ls tags/ techniques/
orw_shellcodeprintf_arginfo_table_hijackrbp_chain_writepositional_width_relative_writedl_make_stack_executableaslr_bruteforce
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]