$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: WinRAR SFX containing a stripped ELF64 ncurses note-taking app with fake 'NOP encryption' (plaintext storage); read_note() has a buffer overflow where password[79] overwrites an adjacent flag variable. Solution: send 80-char payload ending with '}' to trigger system('cat ' + password), inject shell commands via semicolons to search the filesystem for the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar