Challenge #26 "Hashcalc2" was very similar to Hashcalc1.
Again, a good write-up is already available on sleepya's blog. He made an exploit bypassing any ASLR/NX using ROP.
Again since NX was not enabled, I used a similar exploitation with a few adjustements.
Showing posts with label format string. Show all posts
Showing posts with label format string. Show all posts
Tuesday, April 26, 2011
pCTF 2011 #22 Hashcalc1
Challenge #22 "Hashcalc 1" was binary exploitation over the network.
A good write-up is already available on sleepya's blog. He made an exploit bypassing any ASLR/NX using ROP.
However, NX was not enabled on the wargame machine... Organizers thought they did, but it was not effective :( Good for us it means only ASLR, and the binary was not even PIE. One could exploit it quickly by writing a shellcode in the GOT, let's see that.
A good write-up is already available on sleepya's blog. He made an exploit bypassing any ASLR/NX using ROP.
However, NX was not enabled on the wargame machine... Organizers thought they did, but it was not effective :( Good for us it means only ASLR, and the binary was not even PIE. One could exploit it quickly by writing a shellcode in the GOT, let's see that.
Subscribe to:
Posts (Atom)