$ cat writeup.md…
$ cat writeup.md…
HackTheBox
Task: 64-bit glibc-2.35 pwn giving one arbitrary signed-int32-relative single-byte write per round (from a chained-comparison bug) plus a deliberately useless maps leak, requiring a leakless exploit across 32 fresh-ASLR rounds. Solution: tcache metadata overlap via LSB partial overwrite to steer malloc into the loader region, forge an Elf64_Sym and hijack the libc link_map's l_info[DT_SYMTAB], then corrupt stdin's vtable so _IO_vtable_check -> _dl_addr resolves the fake symbol into a one-gadget execve, all at fixed offsets.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar