$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: NON-PIE x86-64 binary reads input with unbounded gets() into a 0x20 stack buffer; a give_shell() function calling system(\"/bin/sh\") already exists. Solution: classic ret2win — overflow 0x28 bytes (buf + saved rbp) and overwrite the saved return address with the address of give_shell to spawn a shell and read /flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar