$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: non-PIE x86-64 'mic check' pwn exposing a raw write-what-where primitive (*(qword*)addr = value, both attacker-controlled) where a secret global gates the /flag print. Solution: overwrite the fixed secret global at 0x40408c with 0x10203040, minding the scanf formats (%10d signed decimal for value, %8x hex for address).
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar