$ cat writeup.md…
$ cat writeup.md…
pwn_spbctf
Task: amd64 PIE/Partial-RELRO heap pwn; printf leaks heap pointers and PIE base, and an 8-byte strcpy buffer overflows into the destination pointer of a second strcpy. Solution: overflow buf_a to point the second strcpy at puts@GOT, write winner()'s address there, and let the trailing puts() jump to system(\"cat flag.txt\").
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar