pwnhard

Military System

tamuctf

Task: ARM64 binary with UAF in close_channel (pointer not zeroed after free). Solution: Leak heap/PIE via stale metadata, tcache poisoning with safe-linking bypass to overwrite global auth, read flag.

$ ls tags/ techniques/
arbitrary_writesafe_linking_bypassuaf_tcache_poisoningstale_pointer_leakauth_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]