$ cat writeup.md…
$ cat writeup.md…
volgactf2026
Task: bootable custom x86_64 OS image running under QEMU+KVM with a tiny syscall ABI for untrusted ring-3 code. Solution: abuse setregs to control SYSRETQ state, trigger a ring-0 #GP with non-canonical RCX, and redirect the #GP exception-name pointer to the kernel flag string so puts() prints it.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar