$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: a stripped non-PIE ELF64 maze game asks for a name, but the real bug is an early stack overflow before the maze matters. Solution: leak __libc_start_main with write@plt, identify musl from the remote leak, read 'cat flag.txt' into .bss, and call system() with a second-stage ROP chain.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar