$ cat writeup.md…
$ cat writeup.md…
CACTF2026
Task: NO-PIE/NO-canary x86-64 ELF reads 0x60 bytes into a 0x20 stack buffer, a classic stack overflow. Solution: ret2win overflowing the saved return address into bell() which calls execl("/bin/sh"), prepending a bare ret gadget for 16-byte movaps stack alignment.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar