pwnhard
Military System
tamuctf
Task: ARM64 binary with UAF in close_channel (pointer not zeroed after free). Solution: Leak heap/PIE via stale metadata, tcache poisoning with safe-linking bypass to overwrite global auth, read flag.
$ ls tags/ techniques/
arbitrary_writesafe_linking_bypassuaf_tcache_poisoningstale_pointer_leakauth_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]