$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: 64-bit PIE ELF reads an 8-byte 'payload' and passes it directly to printf (format-string vuln); a random malloc'd secret on the stack must be guessed to unlock print_flag(). Solution: leak the secret via the compact positional read %11$s, then replay the leaked string at the Secret prompt so strncmp passes and print_flag() dumps /flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar