pwnmedium
Meep
tamuctf
Task: MIPS32 big-endian binary with format string and buffer overflow vulnerabilities. Solution: Leak libc via format string in greet(), then ROP chain via buffer overflow in diagnostics() using MIPS delay slot gadget to call system('/bin/sh').
$ ls tags/ techniques/
got_leakformat_string_leakmips_rop_chaindelay_slot_exploitationlibc_address_calculation
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]