$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: NON-PIE x86-64 ELF with NX/no-canary, stack overflow in read() but NO leak helper and NO win function — only write/read/setvbuf in PLT. Solution: build the libc leak yourself with a ROP write@plt(1, write@got, 8), re-enter logic() for a second read, compute libc-2.31 base, then ret2libc system(\"/bin/sh\"); satisfy /bin/getflag via the getppid /proc/cmdline parent-spoof trick.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar