$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: NON-PIE x86-64 menu pwn exposing arbitrary 1-byte write and arbitrary read, with a get_flag gate that calls strstr(user_ptr, \"root\"). Solution: skip the write primitive entirely — point the strstr haystack at the constant string \"root\" already in .rodata (0x402077), so strstr matches and print_flag() dumps /flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar