pwnmedium

Meep

tamuctf

Task: MIPS32 big-endian binary with format string and buffer overflow vulnerabilities. Solution: Leak libc via format string in greet(), then ROP chain via buffer overflow in diagnostics() using MIPS delay slot gadget to call system('/bin/sh').

$ ls tags/ techniques/
got_leakformat_string_leakmips_rop_chaindelay_slot_exploitationlibc_address_calculation

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]