$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: 64-bit ELF using unbounded gets() into a 256-byte stack buffer guarded by a hand-rolled 0xcafebabe sentinel, with inverted logic that prints the flag only when the sentinel is corrupted. Solution: overflow 268 bytes to reach and change the sentinel so data != 0xcafebabe, triggering print_flag().
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar