$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: menu-driven heap allocator (glibc 2.31) with UAF (delete doesn't clear slot) and heap overflow in allocate() where user-controlled name_len can exceed the chunk size. Solution: unsorted-bin leak to get libc, then tcache poisoning by overflowing an in-use chunk into a tcache-linked neighbour's fd to return __free_hook, write system, free('/bin/sh').
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar