$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: canary-protected stack overflow with printf(%s) on the same buffer; a win() function calling system('cat flag') already exists. Solution: clobber the canary's leading NUL with a non-null byte to make printf leak the remaining 7 canary bytes, then in the same connection (the read() sits in a loop) rebuild the canary and return into a ret-gadget for movaps alignment plus win().
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar