$ cat writeup.md…
$ cat writeup.md…
CACTF2026
Task: PIE ELF64 with no canary, an executable stack (GNU_STACK RWX), a %p leak of the input buffer, and an 80-byte read into a 64-byte stack buffer. Solution: leak the buffer address, ret2shellcode into the executable stack; discover a seccomp filter blocks execve, pivot to an open/read/write (ORW) shellcode to read flag.txt.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar