$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: NX/non-PIE x86-64 ELF that prints /proc/self/maps at startup (free libc leak) and has a 0x28 stack overflow in read(0,[rbp-0x20],0x100). Solution: parse libc base from the maps dump, ret2libc system('/bin/sh') with a ret for movaps alignment, then satisfy /bin/getflag's getppid()-cmdline check by running it from a `sh -c '<magic>'` parent faked via a PATH shim named x86_64.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar