$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: x86-64 ELF (No PIE, canary, NX) with two bugs in logic() — a format string on a global buffer and a 0x200-byte read into a 0x90-byte stack buffer, plus an unused win_fcn that prints flag.txt. Solution: leak the stack canary with %23$p, then overflow the buffer restoring the canary and overwriting the saved return address with win_fcn (ret2win).
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar