$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: No-PIE x86-64 binary reads the flag file into a fixed-address global buffer, then passes attacker input straight to printf (classic format string). Solution: use a positional %N$s format specifier to dereference the known static address 0x4040a0 of the secret buffer and leak the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar