$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: non-PIE 'ALICE' chatbot with a format-string bug in add_advise that calls printf(buf) on raw read() input; a decoy get_flag option is a red herring. Solution: fmt leak of printf@GOT to resolve the Debian libc-2.31 base, then a single %hn/%hhn write overwrites printf@GOT with system, and the next add_advise sends /bin/sh for a shell.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar