x86-64

12 posts

  1. Chonk Shortage

    CTF.SG CTF 2022 · pwn

    Leaking libc through an oversized mmap chunk, then a format-string bug redirects a writable libc GOT entry to system to get a shell.

  2. House of Sice

    HSCTF 8 · pwn

    A double free, a leaked system(), and a detour through fastbins to reach __free_hook.

  3. BabyRE

    zh3r0 CTF 2021 · reversing

    Recognizing the per-8-byte bit shuffle as a matrix transpose and inverting it in Python to turn the comparison constant back into the flag.

  4. Epic Game

    ICHSA CTF 2021 · pwn

    Abusing an snprintf return-value bug to wrap a write into the GOT and point memset at system, using the game's leaked luck stat as a libc address.

  5. Freeless

    SECCON Beginners 2021 · pwn

    With no free available, a top-chunk overflow forces sysmalloc to free memory, enabling a libc leak and tcache poisoning of __free_hook.

  6. masterc

    3kCTF 2021 · pwn

    Overwriting a thread's master canary in its TCB via an unbounded gets, then ROP-ing to a shell after leaking a PIE address through scanf.

  7. Skywriting

    redpwnCTF 2020 · pwn

    A read without a NUL terminator leaks stack values; a later overflow restores the canary and selects a libc one-gadget return target.

  8. Got It

    HSCTF 7 · pwn

    A scrambled GOT turns the binary's scanf into printf, and the resulting format-string write redirects a GOT entry to a one-gadget shell.

  9. pwnagotchi

    HSCTF 7 · pwn

    A gets overflow with no canary leaks puts to fingerprint libc, then ROPs through the eat and zzz helpers to reach a one-gadget shell.

  10. Captain Hook

    Sharky CTF 2020 · pwn

    A format-string bug leaks the stack canary and libc, then a buffer overflow in the edit handler drives a ROP chain to a one-gadget shell.

  11. give_away_2

    Sharky CTF 2020 · pwn

    A PIE binary that leaks main to beat ASLR, then leaks libc via printf's GOT entry before ROP-ing into a one-gadget shell.

  12. z3robotwaves

    Sharky CTF 2020 · reversing

    Modeling the many constraints of a check_flag routine as an SMT problem and solving them with Z3 to recover the password.