$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: menu-driven heap pwn where free() leaves a dangling global EXECUTOR pointer (UAF). Solution: re-allocate a same-size namesayer struct that reuses the freed chunk, overwrite command[] via scanf into firstName, then execute_command runs system() on the attacker string; spaces bypassed with input redirection cat<flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar