$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: x86-64 pwn binary (No PIE, No canary) reads 0x200 bytes into a 0x108 stack buffer, causing a classic stack overflow; a read_flag routine gates flag printing behind an impossible pointer-equality check. Solution: ret2win overwriting saved RIP to jump PAST the check into the flag-printing body, plus a bare ret gadget to fix 16-byte stack alignment for glibc movaps.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar