$ cat writeup.md…
$ cat writeup.md…
spbctf
Task: forking x86-64 TCP pwn service with stack canary + NX + no PIE; handler reads an attacker-controlled length then read_n overflows a stack buffer at [rbp-0x90]. Solution: exploit fork() canary reuse to brute-force the 7 unknown canary bytes one at a time (using the 'Bye!' clean-return banner as an oracle), then ret2win into win_fcn (0x400b2a) which reads flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar