Leaking libc through an oversized mmap chunk, then a format-string bug redirects a writable libc GOT entry to system to get a shell.
niktay: CTF writeups and tutorials
Featured
House of Sice
A double free, a leaked system(), and a detour through fastbins to reach __free_hook.
- Chonk Shortage
- House of Sice
A double free, a leaked
system(), and a detour through fastbins to reach__free_hook. - BabyRE
Recognizing the per-8-byte bit shuffle as a matrix transpose and inverting it in Python to turn the comparison constant back into the flag.
- The Vault
Extracting PICO-8 code hidden in a cartridge PNG's color-channel LSBs, then reimplementing its Lua check in Python to recover the password.
- Epic Game
Abusing an snprintf return-value bug to wrap a write into the GOT and point
memsetatsystem, using the game's leaked luck stat as a libc address. - Freeless
With no
freeavailable, a top-chunk overflow forces sysmalloc to free memory, enabling a libc leak and tcache poisoning of__free_hook.
Show 27 earlier postsHide 27 earlier posts2017–2021
- masterc
Overwriting a thread's master canary in its TCB via an unbounded
gets, then ROP-ing to a shell after leaking a PIE address throughscanf. - crypto warmup
Mapping every three-character block to the number the provided encoder outputs, then reversing the lookup over the given numbers.
- babycrypto1
Forging an AES-CBC command block with the server's encryption oracle, encrypting the show command under the previous block as its IV.
- babycrypto2
Flipping bits in the IV that the server prepends to AES-CBC ciphertext, so the first block decrypts to
showinstead oftest. - PWNkemon
Decoding a Game Boy link-cable capture as SPI in Saleae Logic, then converting the bytes with a Pokémon character table to read the flag.
- i-wanna-find-the-flag
Extracting the GameMaker
data.winfrom the game executable and opening it in UndertaleModTool to read the flag from its winner room. - Skywriting
A read without a NUL terminator leaks stack values; a later overflow restores the canary and selects a libc one-gadget return target.
- Finches in a Pie
A format-string leak defeats the canary and PIE, then a buffer overflow redirects execution to a built-in flag-printing function.
- Got It
A scrambled GOT turns the binary's
scanfintoprintf, and the resulting format-string write redirects a GOT entry to a one-gadget shell. - pwnagotchi
A
getsoverflow with no canary leaksputsto fingerprint libc, then ROPs through the eat and zzz helpers to reach a one-gadget shell. - Captain Hook
A format-string bug leaks the stack canary and libc, then a buffer overflow in the edit handler drives a ROP chain to a one-gadget shell.
- give_away_1
A 32-bit buffer overflow and a leaked
systemaddress drive a ret2libc call that runs /bin/sh via a string found in the provided libc. - give_away_2
A PIE binary that leaks
mainto beat ASLR, then leaks libc viaprintf's GOT entry before ROP-ing into a one-gadget shell. - z3robotwaves
Modeling the many constraints of a
check_flagroutine as an SMT problem and solving them with Z3 to recover the password. - Honey, Help!
Mapping garbled terminal symbols back to letters with a chosen-plaintext attack to recover the flag.
- ProCTF
An SSH login that drops into a Prolog interpreter, where shell() spawns a shell to read the flag.
- Warmup
Using
curlto read the page served before its redirect, then base64-decoding its contents to recover the flag. - Zakukozh
Brute-forcing the keys of an affine cipher over all 256 byte values and keeping the decryption that produces a valid PNG of the flag.
- [PoP:Rev] Reverse Engineering x86 ELF: 0x1
How a function's prologue, return value, and epilogue look in disassembly, through a program that only returns 0.
- [PoP:Rev] Reverse Engineering x86 ELF: 0x2
How local variables and function calls look in disassembly, through a program that adds three integers from user input.
- [PoP:Rev] Reverse Engineering x86 ELF: 0x3
How conditionals look in disassembly, through a program that tells whether its input is more than, less than, or equal to 10.
- [PoP:Rev] Reverse Engineering x86 ELF: 0x4
How loops look in disassembly, through a program that prints the length of its input.
- [PoP:Rev] Reverse Engineering x86 ELF: 0x5
How structs look in disassembly, through a program that reads a name and age into a struct and prints them.
- rev_rev_rev
Reversing a 32-bit ELF that reverses its input, transforms it with bitwise operations, and NOTs it, then brute-forcing the flag one character at a time.
- 2017, Dating in Singapore
Reading a string of digits as twelve months of days and tracing them out on the 2017 calendar.
- Prime
Decompiling an APK whose prime check also accepts squares of primes, which makes the flag π(10¹⁶) + π(10⁸).
- Simple Transfer
Recovering a PDF sent over NFS from a packet capture, then converting it to HTML with pdftohtml to reveal the flag.