$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: NON-PIE pwn where read_files() iterates an uninitialized stack pointer-array and sprintf/fopen's a path from each 'block'; option 'sort+read' first fills the overlapping stack region with attacker-controlled malloc'd buffers. Solution: exploit the stack-frame overlap (read_files[j] == sort_data[j+640]) to alias our buffers as file records, forging block[0]='pwned_folder' and block[0x100]='flag.txt' so fopen reads the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar