$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: x86-64 pwn binary with a stack buffer overflow guarded by a homemade rand()-based canary, which is leaked verbatim by a format string. Solution: parse the leaked canary from the banner, overflow the buffer while restoring the canary at rbp-0x4 so the equality check passes, and overwrite the return address with print_flag (ret2win).
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar