$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: x86-64 PIE binary reads shellcode and jumps to it, but a seccomp allowlist restricts syscalls to getdents64/open/read/write/close/exit_group (no execve). Solution: shellcode open(\"/\")+getdents64 to discover the unknown flag filename (/s3cr3t_f1l3_w1th_fl0g), then open+read+write it; assembled locally with keystone-engine since host is arm64 macOS.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar