pwnhard
ponbaby
volgactf2026
Task: Heap exploitation on glibc 2.42 with 2-byte overflow, limited allocations (16), limited overflows (4), no UAF read, no output primitive. Solution: Corrupt tcache_perthread_struct via overlapping chunks to bypass safe-linking, partial overwrite stdout for leak (12-bit brute force), then House of Apple 2 for RCE.
$ ls tags/ techniques/
safe_linking_bypasstcache_metadata_corruptionstdout_file_structure_corruptionoverlapping_chunkshouse_of_apple_2partial_overwrite_brute_force
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub to get started.
$ssh [email protected]