$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: x86-64 pwn binary (no canary, NX, no PIE) with a classic stack overflow via read(0,buf,0x80) into a 64-byte buffer; the program prints /proc/$PPID/maps at startup, leaking libc base for free. Solution: ret2libc chain — empirically found RIP offset = 56 (not the naive 72) and added two alignment ret gadgets to satisfy glibc 2.31 system()'s movaps 16-byte alignment.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar