$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: shellcode runner with a libseccomp allow-list limited to read/write/open/close/exit_group that calls the stack buffer directly. Solution: 71-byte hand-assembled shellcode that does open('/flag') -> read -> write(stdout) -> exit_group, all inside the allow list.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar