$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: x86-64 PIE C++ shellcode-golf pwn — read only 63 bytes of shellcode into an RX page under strict seccomp, with the flag hidden in one of 100 mmap'd linked-list nodes reachable via head=[rbp-8]. Solution: instead of byte-budget-heavy string comparison, dump every node's 32 data bytes to stdout with a 36-byte list-walk loop (push/pop syscall setup) and grep the flag client-side.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar